Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
boatnet.arm.elf

Overview

General Information

Sample name:boatnet.arm.elf
Analysis ID:1588204
MD5:9ddae3ed15851a6660a6de94dda637ae
SHA1:ced5e67201d2d06c3c29889ef81cabc9d96cb7c2
SHA256:eb6da8c6eebe8470b6a107910c74ecc6ec5f2a9fd1f0fd313948c20fe92295cf
Tags:user-elfdigest
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Sample is packed with UPX
Sends malformed DNS queries
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Sample contains only a LOAD segment without any section mappings
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1588204
Start date and time:2025-01-10 22:38:08 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 28s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:boatnet.arm.elf
Detection:MAL
Classification:mal56.troj.evad.linELF@0/0@29/0
  • VT rate limit hit for: chinklabs.dyn
Command:/tmp/boatnet.arm.elf
PID:5485
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
The Peoples Bank of China.
Standard Error:
  • system is lnxubuntu20
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: boatnet.arm.elfVirustotal: Detection: 14%Perma Link
Source: boatnet.arm.elfReversingLabs: Detection: 23%

Networking

barindex
Source: global trafficDNS traffic detected: malformed DNS query: netfags.geek. [malformed]
Source: global trafficDNS traffic detected: malformed DNS query: yellowchink.pirate. [malformed]
Source: global trafficDNS traffic detected: malformed DNS query: dogeatingchink.parody. [malformed]
Source: global trafficDNS traffic detected: malformed DNS query: hiakamai.dyn. [malformed]
Source: global trafficDNS traffic detected: malformed DNS query: himrresearcher.dyn. [malformed]
Source: global trafficDNS traffic detected: malformed DNS query: w3d0ntlikebot5.parody. [malformed]
Source: global trafficDNS traffic detected: malformed DNS query: infectedslurs.geek. [malformed]
Source: global trafficDNS traffic detected: malformed DNS query: chinklabs.dyn. [malformed]
Source: global trafficDNS traffic detected: malformed DNS query: burnthe.libre. [malformed]
Source: global trafficDNS traffic detected: malformed DNS query: freethemonkeys.pirate. [malformed]
Source: global trafficTCP traffic: 192.168.2.14:38924 -> 193.143.1.54:25596
Source: /tmp/boatnet.arm.elf (PID: 5485)Socket: 127.0.0.1:39148Jump to behavior
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 95.216.99.249
Source: unknownUDP traffic detected without corresponding DNS query: 5.161.109.23
Source: unknownUDP traffic detected without corresponding DNS query: 51.254.162.59
Source: unknownUDP traffic detected without corresponding DNS query: 185.232.68.212
Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
Source: unknownUDP traffic detected without corresponding DNS query: 5.161.109.23
Source: unknownUDP traffic detected without corresponding DNS query: 5.161.109.23
Source: unknownUDP traffic detected without corresponding DNS query: 152.53.15.127
Source: unknownUDP traffic detected without corresponding DNS query: 95.216.99.249
Source: unknownUDP traffic detected without corresponding DNS query: 65.21.1.106
Source: unknownUDP traffic detected without corresponding DNS query: 95.216.99.249
Source: unknownUDP traffic detected without corresponding DNS query: 152.53.15.127
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 152.53.15.127
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 65.21.1.106
Source: unknownUDP traffic detected without corresponding DNS query: 64.176.6.48
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
Source: unknownUDP traffic detected without corresponding DNS query: 185.232.68.212
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 152.53.15.127
Source: unknownUDP traffic detected without corresponding DNS query: 152.53.15.127
Source: unknownUDP traffic detected without corresponding DNS query: 5.161.109.23
Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
Source: global trafficDNS traffic detected: DNS query: chinklabs.dyn
Source: global trafficDNS traffic detected: DNS query: freethewind.parody
Source: global trafficDNS traffic detected: DNS query: netfags.geek. [malformed]
Source: global trafficDNS traffic detected: DNS query: dogeatingchink.parody
Source: global trafficDNS traffic detected: DNS query: yellowchink.pirate. [malformed]
Source: global trafficDNS traffic detected: DNS query: dogeatingchink.parody. [malformed]
Source: global trafficDNS traffic detected: DNS query: hiakamai.dyn. [malformed]
Source: global trafficDNS traffic detected: DNS query: himrresearcher.dyn. [malformed]
Source: global trafficDNS traffic detected: DNS query: w3d0ntlikebot5.parody. [malformed]
Source: global trafficDNS traffic detected: DNS query: infectedslurs.geek. [malformed]
Source: global trafficDNS traffic detected: DNS query: chinklabs.dyn. [malformed]
Source: global trafficDNS traffic detected: DNS query: infectedchink.pirate
Source: global trafficDNS traffic detected: DNS query: burnthe.libre. [malformed]
Source: global trafficDNS traffic detected: DNS query: freethemonkeys.pirate. [malformed]
Source: boatnet.arm.elfString found in binary or memory: http://upx.sf.net
Source: LOAD without section mappingsProgram segment: 0x8000
Source: classification engineClassification label: mal56.troj.evad.linELF@0/0@29/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
Source: boatnet.arm.elfSubmission file: segment LOAD with 7.7034 entropy (max. 8.0)
Source: /tmp/boatnet.arm.elf (PID: 5485)Queries kernel information via 'uname': Jump to behavior
Source: boatnet.arm.elf, 5485.1.0000557b596d5000.0000557b598c3000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: boatnet.arm.elf, 5485.1.00007ffd4445c000.00007ffd4447d000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: boatnet.arm.elf, 5485.1.0000557b596d5000.0000557b598c3000.rw-.sdmpBinary or memory string: nY{U!/etc/qemu-binfmt/arm
Source: boatnet.arm.elf, 5485.1.00007ffd4445c000.00007ffd4447d000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/boatnet.arm.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/boatnet.arm.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1588204 Sample: boatnet.arm.elf Startdate: 10/01/2025 Architecture: LINUX Score: 56 14 yellowchink.pirate. [malformed] 2->14 16 w3d0ntlikebot5.parody. [malformed] 2->16 18 12 other IPs or domains 2->18 20 Multi AV Scanner detection for submitted file 2->20 22 Sample is packed with UPX 2->22 8 boatnet.arm.elf 2->8         started        signatures3 24 Sends malformed DNS queries 16->24 process4 process5 10 boatnet.arm.elf 8->10         started        process6 12 boatnet.arm.elf 10->12         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
boatnet.arm.elf15%VirustotalBrowse
boatnet.arm.elf24%ReversingLabsLinux.Trojan.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
chinklabs.dyn
193.143.1.54
truetrue
    unknown
    infectedchink.pirate
    unknown
    unknownfalse
      unknown
      himrresearcher.dyn. [malformed]
      unknown
      unknowntrue
        unknown
        chinklabs.dyn. [malformed]
        unknown
        unknowntrue
          unknown
          netfags.geek. [malformed]
          unknown
          unknowntrue
            unknown
            burnthe.libre. [malformed]
            unknown
            unknowntrue
              unknown
              dogeatingchink.parody. [malformed]
              unknown
              unknowntrue
                unknown
                infectedslurs.geek. [malformed]
                unknown
                unknowntrue
                  unknown
                  freethewind.parody
                  unknown
                  unknownfalse
                    unknown
                    w3d0ntlikebot5.parody. [malformed]
                    unknown
                    unknowntrue
                      unknown
                      freethemonkeys.pirate. [malformed]
                      unknown
                      unknowntrue
                        unknown
                        hiakamai.dyn. [malformed]
                        unknown
                        unknowntrue
                          unknown
                          yellowchink.pirate. [malformed]
                          unknown
                          unknowntrue
                            unknown
                            dogeatingchink.parody
                            unknown
                            unknowntrue
                              unknown
                              NameSourceMaliciousAntivirus DetectionReputation
                              http://upx.sf.netboatnet.arm.elffalse
                                high
                                • No. of IPs < 25%
                                • 25% < No. of IPs < 50%
                                • 50% < No. of IPs < 75%
                                • 75% < No. of IPs
                                IPDomainCountryFlagASNASN NameMalicious
                                193.143.1.54
                                chinklabs.dynunknown
                                57271BITWEB-ASRUtrue
                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                193.143.1.54https://www.lieferung-dhl-tracking.de/captcha/calcul_captcha.phpGet hashmaliciousUnknownBrowse
                                  https://www.deutschepost-gefolgt.com/Get hashmaliciousUnknownBrowse
                                    https://deutsche-post-infos.com/Get hashmaliciousUnknownBrowse
                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                      chinklabs.dynzerm68k.elfGet hashmaliciousUnknownBrowse
                                      • 185.150.24.67
                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                      BITWEB-ASRU133313712272908537.jsGet hashmaliciousStrela DownloaderBrowse
                                      • 193.143.1.205
                                      1667730710460316051.jsGet hashmaliciousStrela DownloaderBrowse
                                      • 193.143.1.205
                                      2609231882173488714.jsGet hashmaliciousStrela DownloaderBrowse
                                      • 193.143.1.205
                                      23614810137024152.jsGet hashmaliciousStrela DownloaderBrowse
                                      • 193.143.1.205
                                      20394193042959831455.jsGet hashmaliciousStrela DownloaderBrowse
                                      • 193.143.1.205
                                      11057252552282120022.jsGet hashmaliciousStrela DownloaderBrowse
                                      • 193.143.1.205
                                      3039412363370818030.jsGet hashmaliciousStrela DownloaderBrowse
                                      • 193.143.1.205
                                      160370701202011504.jsGet hashmaliciousStrela DownloaderBrowse
                                      • 193.143.1.205
                                      206038195771531175.jsGet hashmaliciousStrela DownloaderBrowse
                                      • 193.143.1.205
                                      273371081152046820.jsGet hashmaliciousStrela DownloaderBrowse
                                      • 193.143.1.205
                                      No context
                                      No context
                                      No created / dropped files found
                                      File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, no section header
                                      Entropy (8bit):7.695762425558059
                                      TrID:
                                      • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                      File name:boatnet.arm.elf
                                      File size:15'656 bytes
                                      MD5:9ddae3ed15851a6660a6de94dda637ae
                                      SHA1:ced5e67201d2d06c3c29889ef81cabc9d96cb7c2
                                      SHA256:eb6da8c6eebe8470b6a107910c74ecc6ec5f2a9fd1f0fd313948c20fe92295cf
                                      SHA512:37d34b86a6e45df056c74521127f320cad4ab9891618a99ec5e21b699bd95bee6e1be0fee3734bdba78d0c72c246a7268fed65e9c37de2d404e795cc33c1999a
                                      SSDEEP:384:wNPZ3wEWnWFfrZbu45kXYRKvkOP1ryYlmhTp/ftBb:OZ3p6WLbu45dKvk2j0dRb
                                      TLSH:8662D1E86A21AD87F1E00D73488D25CDD1A6202863ADE8657DC01F54E11F90ABA4EDDC
                                      File Content Preview:.ELF...a..........(.........4...........4. ...(.....................3<..3<...............d...d...d..................Q.td............................}.{mUPX!X.......\d..\d......V.........ELF.ra....(........4...b.... ...w.......... a.../..$a..#hu...C...Q.t.

                                      ELF header

                                      Class:ELF32
                                      Data:2's complement, little endian
                                      Version:1 (current)
                                      Machine:ARM
                                      Version Number:0x1
                                      Type:EXEC (Executable file)
                                      OS/ABI:ARM - ABI
                                      ABI Version:0
                                      Entry Point Address:0xb2f8
                                      Flags:0x202
                                      ELF Header Size:52
                                      Program Header Offset:52
                                      Program Header Size:32
                                      Number of Program Headers:3
                                      Section Header Offset:0
                                      Section Header Size:40
                                      Number of Section Headers:0
                                      Header String Table Index:0
                                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                      LOAD0x00x80000x80000x3c330x3c337.70340x5R E0x8000
                                      LOAD0x64040x164040x164040x00x00.00000x6RW 0x8000
                                      GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                      TimestampSource PortDest PortSource IPDest IP
                                      Jan 10, 2025 22:38:54.328224897 CET3892425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:38:54.333235979 CET2559638924193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:38:54.333308935 CET3892425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:38:54.345977068 CET3892425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:38:54.351069927 CET2559638924193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:38:54.351102114 CET3892425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:38:54.356147051 CET2559638924193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:38:56.059988976 CET2559638924193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:38:56.060503960 CET3892425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:38:56.065239906 CET2559638924193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:38:57.492364883 CET3892625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:38:57.497296095 CET2559638926193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:38:57.497431040 CET3892625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:38:57.498425007 CET3892625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:38:57.503153086 CET2559638926193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:38:57.503207922 CET3892625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:38:57.508018970 CET2559638926193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:38:59.280508995 CET2559638926193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:38:59.280898094 CET3892625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:38:59.285765886 CET2559638926193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:05.288923979 CET3892825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:05.293879986 CET2559638928193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:05.293991089 CET3892825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:05.294965982 CET3892825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:05.307387114 CET2559638928193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:05.307596922 CET3892825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:05.312712908 CET2559638928193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:07.089544058 CET2559638928193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:07.089943886 CET3892825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:07.094782114 CET2559638928193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:13.099606991 CET3893025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:13.104516983 CET2559638930193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:13.104609966 CET3893025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:13.105838060 CET3893025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:13.111183882 CET2559638930193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:13.111255884 CET3893025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:13.116331100 CET2559638930193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:14.843761921 CET2559638930193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:14.844126940 CET3893025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:14.849023104 CET2559638930193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:15.865374088 CET3893225596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:15.870254040 CET2559638932193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:15.870546103 CET3893225596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:15.871459961 CET3893225596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:15.876254082 CET2559638932193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:15.876348019 CET3893225596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:15.881107092 CET2559638932193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:17.629755974 CET2559638932193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:17.630116940 CET3893225596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:17.636167049 CET2559638932193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:23.638180017 CET3893425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:23.643172979 CET2559638934193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:23.643251896 CET3893425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:23.644265890 CET3893425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:23.649111032 CET2559638934193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:23.649177074 CET3893425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:23.654022932 CET2559638934193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:25.444031954 CET2559638934193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:25.444356918 CET3893425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:25.449167967 CET2559638934193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:31.448988914 CET3893625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:31.453910112 CET2559638936193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:31.454022884 CET3893625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:31.455214977 CET3893625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:31.460109949 CET2559638936193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:31.460176945 CET3893625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:31.464963913 CET2559638936193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:33.222588062 CET2559638936193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:33.222948074 CET3893625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:33.227813959 CET2559638936193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:39.231281042 CET3893825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:39.236223936 CET2559638938193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:39.236287117 CET3893825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:39.237287045 CET3893825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:39.242119074 CET2559638938193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:39.242191076 CET3893825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:39.247051954 CET2559638938193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:40.988214016 CET2559638938193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:40.988430023 CET3893825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:40.993387938 CET2559638938193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:42.008059025 CET3894025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:42.012921095 CET2559638940193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:42.013042927 CET3894025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:42.013590097 CET3894025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:42.018369913 CET2559638940193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:42.018445015 CET3894025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:42.023283958 CET2559638940193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:43.790716887 CET2559638940193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:43.791013956 CET3894025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:43.795821905 CET2559638940193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:44.820385933 CET3894225596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:44.825239897 CET2559638942193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:44.825301886 CET3894225596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:44.826246023 CET3894225596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:44.830977917 CET2559638942193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:44.831051111 CET3894225596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:44.835858107 CET2559638942193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:46.588001013 CET2559638942193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:46.588248968 CET3894225596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:46.593189001 CET2559638942193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:47.618014097 CET3894425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:47.622961998 CET2559638944193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:47.623024940 CET3894425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:47.623832941 CET3894425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:47.628716946 CET2559638944193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:47.628767967 CET3894425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:47.633591890 CET2559638944193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:49.395503044 CET2559638944193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:49.395589113 CET3894425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:49.400541067 CET2559638944193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:50.425786018 CET3894625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:50.430718899 CET2559638946193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:50.430844069 CET3894625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:50.432348013 CET3894625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:50.437243938 CET2559638946193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:50.437305927 CET3894625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:50.442105055 CET2559638946193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:52.242284060 CET2559638946193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:52.242535114 CET3894625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:52.247456074 CET2559638946193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:53.264159918 CET3894825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:53.269537926 CET2559638948193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:53.269627094 CET3894825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:53.270950079 CET3894825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:53.276392937 CET2559638948193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:53.276475906 CET3894825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:53.282102108 CET2559638948193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:55.063174009 CET2559638948193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:55.063453913 CET3894825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:55.068276882 CET2559638948193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:56.083940983 CET3895025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:56.088782072 CET2559638950193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:56.088852882 CET3895025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:56.089905024 CET3895025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:56.095499992 CET2559638950193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:56.095545053 CET3895025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:56.101236105 CET2559638950193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:57.852133989 CET2559638950193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:57.852595091 CET3895025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:57.857572079 CET2559638950193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:58.874306917 CET3895225596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:58.879115105 CET2559638952193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:58.879260063 CET3895225596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:58.880295992 CET3895225596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:58.885171890 CET2559638952193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:39:58.885260105 CET3895225596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:39:58.890106916 CET2559638952193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:00.648186922 CET2559638952193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:00.648346901 CET3895225596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:00.653214931 CET2559638952193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:01.669091940 CET3895425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:01.674048901 CET2559638954193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:01.674159050 CET3895425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:01.675498962 CET3895425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:01.680354118 CET2559638954193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:01.680428028 CET3895425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:01.685252905 CET2559638954193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:03.495528936 CET2559638954193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:03.495670080 CET3895425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:03.500454903 CET2559638954193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:04.515263081 CET3895625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:04.520296097 CET2559638956193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:04.520355940 CET3895625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:04.521418095 CET3895625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:04.526300907 CET2559638956193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:04.526361942 CET3895625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:04.531397104 CET2559638956193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:06.294950008 CET2559638956193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:06.295176983 CET3895625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:06.300066948 CET2559638956193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:07.326318979 CET3895825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:07.331502914 CET2559638958193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:07.331660032 CET3895825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:07.332607985 CET3895825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:07.337503910 CET2559638958193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:07.337560892 CET3895825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:07.342436075 CET2559638958193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:09.126251936 CET2559638958193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:09.126491070 CET3895825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:09.131308079 CET2559638958193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:10.145282030 CET3896025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:10.150137901 CET2559638960193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:10.150208950 CET3896025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:10.150934935 CET3896025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:10.155754089 CET2559638960193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:10.155805111 CET3896025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:10.160610914 CET2559638960193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:11.912132978 CET2559638960193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:11.912430048 CET3896025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:11.917426109 CET2559638960193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:12.944109917 CET3896225596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:12.949103117 CET2559638962193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:12.949183941 CET3896225596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:12.950388908 CET3896225596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:12.955228090 CET2559638962193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:12.955321074 CET3896225596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:12.960216045 CET2559638962193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:14.855901957 CET2559638962193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:14.856118917 CET3896225596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:14.861023903 CET2559638962193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:20.865269899 CET3896425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:20.870394945 CET2559638964193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:20.870593071 CET3896425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:20.871407986 CET3896425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:20.876224041 CET2559638964193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:20.876343012 CET3896425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:20.881449938 CET2559638964193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:22.648525953 CET2559638964193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:22.648904085 CET3896425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:22.653934002 CET2559638964193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:23.667766094 CET3896625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:23.672663927 CET2559638966193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:23.672715902 CET3896625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:23.673296928 CET3896625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:23.678116083 CET2559638966193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:23.678154945 CET3896625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:23.682980061 CET2559638966193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:25.447256088 CET2559638966193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:25.447376013 CET3896625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:25.452281952 CET2559638966193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:31.452493906 CET3896825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:31.457585096 CET2559638968193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:31.457700014 CET3896825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:31.458580017 CET3896825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:31.463349104 CET2559638968193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:31.463426113 CET3896825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:31.468399048 CET2559638968193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:33.194490910 CET2559638968193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:33.194688082 CET3896825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:33.203567028 CET2559638968193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:34.214818001 CET3897025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:34.220164061 CET2559638970193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:34.220256090 CET3897025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:34.221029043 CET3897025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:34.226237059 CET2559638970193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:34.226301908 CET3897025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:34.232085943 CET2559638970193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:35.971221924 CET2559638970193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:35.971467018 CET3897025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:35.976457119 CET2559638970193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:37.001326084 CET3897225596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:37.006108999 CET2559638972193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:37.006640911 CET3897225596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:37.006777048 CET3897225596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:37.011543989 CET2559638972193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:37.011590004 CET3897225596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:37.016347885 CET2559638972193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:38.788809061 CET2559638972193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:38.789140940 CET3897225596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:38.794126987 CET2559638972193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:39.809478045 CET3897425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:39.814372063 CET2559638974193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:39.814517021 CET3897425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:39.815289974 CET3897425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:39.820099115 CET2559638974193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:39.820147038 CET3897425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:39.825035095 CET2559638974193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:41.570080996 CET2559638974193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:41.570425987 CET3897425596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:41.575262070 CET2559638974193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:42.590853930 CET3897625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:42.595714092 CET2559638976193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:42.595767975 CET3897625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:42.599957943 CET3897625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:42.604736090 CET2559638976193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:42.604819059 CET3897625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:42.609579086 CET2559638976193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:44.331492901 CET2559638976193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:44.331654072 CET3897625596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:44.336528063 CET2559638976193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:50.340646029 CET3897825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:50.345489979 CET2559638978193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:50.345597982 CET3897825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:50.346427917 CET3897825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:50.351191998 CET2559638978193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:50.351269007 CET3897825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:50.356071949 CET2559638978193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:52.123835087 CET2559638978193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:52.124094963 CET3897825596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:52.128892899 CET2559638978193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:58.133230925 CET3898025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:58.138071060 CET2559638980193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:58.138138056 CET3898025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:58.139250040 CET3898025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:58.144197941 CET2559638980193.143.1.54192.168.2.14
                                      Jan 10, 2025 22:40:58.144251108 CET3898025596192.168.2.14193.143.1.54
                                      Jan 10, 2025 22:40:58.149147034 CET2559638980193.143.1.54192.168.2.14
                                      TimestampSource PortDest PortSource IPDest IP
                                      Jan 10, 2025 22:38:54.302695036 CET5655353192.168.2.1451.158.108.203
                                      Jan 10, 2025 22:38:54.318474054 CET535655351.158.108.203192.168.2.14
                                      Jan 10, 2025 22:38:57.062472105 CET4843553192.168.2.1495.216.99.249
                                      Jan 10, 2025 22:38:57.491147995 CET534843595.216.99.249192.168.2.14
                                      Jan 10, 2025 22:39:00.283268929 CET4526753192.168.2.145.161.109.23
                                      Jan 10, 2025 22:39:08.093811989 CET3970953192.168.2.1451.254.162.59
                                      Jan 10, 2025 22:39:15.847039938 CET3485053192.168.2.14185.232.68.212
                                      Jan 10, 2025 22:39:15.864573002 CET5334850185.232.68.212192.168.2.14
                                      Jan 10, 2025 22:39:18.632392883 CET4191853192.168.2.14178.254.22.166
                                      Jan 10, 2025 22:39:26.446069002 CET4937853192.168.2.145.161.109.23
                                      Jan 10, 2025 22:39:34.225750923 CET5867953192.168.2.145.161.109.23
                                      Jan 10, 2025 22:39:41.990223885 CET5567753192.168.2.14152.53.15.127
                                      Jan 10, 2025 22:39:42.007707119 CET5355677152.53.15.127192.168.2.14
                                      Jan 10, 2025 22:39:44.793905973 CET6088153192.168.2.1495.216.99.249
                                      Jan 10, 2025 22:39:44.819984913 CET536088195.216.99.249192.168.2.14
                                      Jan 10, 2025 22:39:47.590783119 CET4459053192.168.2.1465.21.1.106
                                      Jan 10, 2025 22:39:47.617487907 CET534459065.21.1.106192.168.2.14
                                      Jan 10, 2025 22:39:50.397377014 CET5360453192.168.2.1495.216.99.249
                                      Jan 10, 2025 22:39:50.424557924 CET535360495.216.99.249192.168.2.14
                                      Jan 10, 2025 22:39:53.245532990 CET5033853192.168.2.14152.53.15.127
                                      Jan 10, 2025 22:39:53.263148069 CET5350338152.53.15.127192.168.2.14
                                      Jan 10, 2025 22:39:56.066260099 CET5461353192.168.2.14194.36.144.87
                                      Jan 10, 2025 22:39:56.083542109 CET5354613194.36.144.87192.168.2.14
                                      Jan 10, 2025 22:39:58.855969906 CET3473153192.168.2.14152.53.15.127
                                      Jan 10, 2025 22:39:58.873368025 CET5334731152.53.15.127192.168.2.14
                                      Jan 10, 2025 22:40:01.651282072 CET5895053192.168.2.14194.36.144.87
                                      Jan 10, 2025 22:40:01.668395996 CET5358950194.36.144.87192.168.2.14
                                      Jan 10, 2025 22:40:04.498683929 CET3448053192.168.2.1451.158.108.203
                                      Jan 10, 2025 22:40:04.514589071 CET533448051.158.108.203192.168.2.14
                                      Jan 10, 2025 22:40:07.298350096 CET4338653192.168.2.1481.169.136.222
                                      Jan 10, 2025 22:40:07.325578928 CET534338681.169.136.222192.168.2.14
                                      Jan 10, 2025 22:40:10.129331112 CET5771753192.168.2.1451.158.108.203
                                      Jan 10, 2025 22:40:10.144819021 CET535771751.158.108.203192.168.2.14
                                      Jan 10, 2025 22:40:12.916194916 CET5233253192.168.2.1465.21.1.106
                                      Jan 10, 2025 22:40:12.943078995 CET535233265.21.1.106192.168.2.14
                                      Jan 10, 2025 22:40:15.859687090 CET4307553192.168.2.1464.176.6.48
                                      Jan 10, 2025 22:40:23.650955915 CET5759753192.168.2.1451.158.108.203
                                      Jan 10, 2025 22:40:23.667349100 CET535759751.158.108.203192.168.2.14
                                      Jan 10, 2025 22:40:26.449614048 CET3316253192.168.2.14178.254.22.166
                                      Jan 10, 2025 22:40:34.197341919 CET3568653192.168.2.14185.232.68.212
                                      Jan 10, 2025 22:40:34.214267015 CET5335686185.232.68.212192.168.2.14
                                      Jan 10, 2025 22:40:36.973750114 CET3524353192.168.2.1481.169.136.222
                                      Jan 10, 2025 22:40:37.000643969 CET533524381.169.136.222192.168.2.14
                                      Jan 10, 2025 22:40:39.791505098 CET5502353192.168.2.14152.53.15.127
                                      Jan 10, 2025 22:40:39.808602095 CET5355023152.53.15.127192.168.2.14
                                      Jan 10, 2025 22:40:42.573023081 CET5241453192.168.2.14152.53.15.127
                                      Jan 10, 2025 22:40:42.590312004 CET5352414152.53.15.127192.168.2.14
                                      Jan 10, 2025 22:40:45.334912062 CET3465053192.168.2.145.161.109.23
                                      Jan 10, 2025 22:40:53.127437115 CET4172753192.168.2.14178.254.22.166
                                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                      Jan 10, 2025 22:38:54.302695036 CET192.168.2.1451.158.108.2030x9a8eStandard query (0)chinklabs.dynA (IP address)IN (0x0001)false
                                      Jan 10, 2025 22:38:57.062472105 CET192.168.2.1495.216.99.2490xc5d2Standard query (0)freethewind.parodyA (IP address)IN (0x0001)false
                                      Jan 10, 2025 22:39:00.283268929 CET192.168.2.145.161.109.230x8576Standard query (0)freethewind.parodyA (IP address)IN (0x0001)false
                                      Jan 10, 2025 22:39:08.093811989 CET192.168.2.1451.254.162.590x2080Standard query (0)netfags.geek. [malformed]256385false
                                      Jan 10, 2025 22:39:15.847039938 CET192.168.2.14185.232.68.2120xfdd3Standard query (0)freethewind.parodyA (IP address)IN (0x0001)false
                                      Jan 10, 2025 22:39:18.632392883 CET192.168.2.14178.254.22.1660x11f9Standard query (0)dogeatingchink.parodyA (IP address)IN (0x0001)false
                                      Jan 10, 2025 22:39:26.446069002 CET192.168.2.145.161.109.230x819bStandard query (0)yellowchink.pirate. [malformed]256403false
                                      Jan 10, 2025 22:39:34.225750923 CET192.168.2.145.161.109.230xfc8Standard query (0)dogeatingchink.parody. [malformed]256411false
                                      Jan 10, 2025 22:39:41.990223885 CET192.168.2.14152.53.15.1270xff1bStandard query (0)hiakamai.dyn. [malformed]256414false
                                      Jan 10, 2025 22:39:44.793905973 CET192.168.2.1495.216.99.2490x776eStandard query (0)hiakamai.dyn. [malformed]256416false
                                      Jan 10, 2025 22:39:47.590783119 CET192.168.2.1465.21.1.1060xfee8Standard query (0)himrresearcher.dyn. [malformed]256419false
                                      Jan 10, 2025 22:39:50.397377014 CET192.168.2.1495.216.99.2490x47a8Standard query (0)w3d0ntlikebot5.parody. [malformed]256422false
                                      Jan 10, 2025 22:39:53.245532990 CET192.168.2.14152.53.15.1270x3cdfStandard query (0)infectedslurs.geek. [malformed]256425false
                                      Jan 10, 2025 22:39:56.066260099 CET192.168.2.14194.36.144.870xe065Standard query (0)chinklabs.dyn. [malformed]256428false
                                      Jan 10, 2025 22:39:58.855969906 CET192.168.2.14152.53.15.1270x67caStandard query (0)infectedchink.pirateA (IP address)IN (0x0001)false
                                      Jan 10, 2025 22:40:01.651282072 CET192.168.2.14194.36.144.870x8b37Standard query (0)burnthe.libre. [malformed]256433false
                                      Jan 10, 2025 22:40:04.498683929 CET192.168.2.1451.158.108.2030xa5a0Standard query (0)infectedslurs.geek. [malformed]256436false
                                      Jan 10, 2025 22:40:07.298350096 CET192.168.2.1481.169.136.2220x4a0dStandard query (0)chinklabs.dyn. [malformed]256439false
                                      Jan 10, 2025 22:40:10.129331112 CET192.168.2.1451.158.108.2030x9beeStandard query (0)hiakamai.dyn. [malformed]256442false
                                      Jan 10, 2025 22:40:12.916194916 CET192.168.2.1465.21.1.1060x5239Standard query (0)hiakamai.dyn. [malformed]256444false
                                      Jan 10, 2025 22:40:15.859687090 CET192.168.2.1464.176.6.480xe446Standard query (0)chinklabs.dynA (IP address)IN (0x0001)false
                                      Jan 10, 2025 22:40:23.650955915 CET192.168.2.1451.158.108.2030x9fb1Standard query (0)dogeatingchink.parody. [malformed]256455false
                                      Jan 10, 2025 22:40:26.449614048 CET192.168.2.14178.254.22.1660xb194Standard query (0)infectedslurs.geek. [malformed]256463false
                                      Jan 10, 2025 22:40:34.197341919 CET192.168.2.14185.232.68.2120xda18Standard query (0)dogeatingchink.parody. [malformed]256466false
                                      Jan 10, 2025 22:40:36.973750114 CET192.168.2.1481.169.136.2220x7e5fStandard query (0)burnthe.libre. [malformed]256469false
                                      Jan 10, 2025 22:40:39.791505098 CET192.168.2.14152.53.15.1270x8b65Standard query (0)chinklabs.dyn. [malformed]256471false
                                      Jan 10, 2025 22:40:42.573023081 CET192.168.2.14152.53.15.1270x4e5Standard query (0)freethemonkeys.pirate. [malformed]256474false
                                      Jan 10, 2025 22:40:45.334912062 CET192.168.2.145.161.109.230x7026Standard query (0)w3d0ntlikebot5.parody. [malformed]256482false
                                      Jan 10, 2025 22:40:53.127437115 CET192.168.2.14178.254.22.1660x571dStandard query (0)hiakamai.dyn. [malformed]256490false
                                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                      Jan 10, 2025 22:38:54.318474054 CET51.158.108.203192.168.2.140x9a8eNo error (0)chinklabs.dyn193.143.1.54A (IP address)IN (0x0001)false
                                      Jan 10, 2025 22:38:57.491147995 CET95.216.99.249192.168.2.140xc5d2Name error (3)freethewind.parodynonenoneA (IP address)IN (0x0001)false
                                      Jan 10, 2025 22:39:15.864573002 CET185.232.68.212192.168.2.140xfdd3Refused (5)freethewind.parodynonenoneA (IP address)IN (0x0001)false
                                      Jan 10, 2025 22:39:42.007707119 CET152.53.15.127192.168.2.140xff1bFormat error (1)hiakamai.dyn. [malformed]nonenone256414false
                                      Jan 10, 2025 22:39:44.819984913 CET95.216.99.249192.168.2.140x776eFormat error (1)hiakamai.dyn. [malformed]nonenone256416false
                                      Jan 10, 2025 22:39:47.617487907 CET65.21.1.106192.168.2.140xfee8Format error (1)himrresearcher.dyn. [malformed]nonenone256419false
                                      Jan 10, 2025 22:39:50.424557924 CET95.216.99.249192.168.2.140x47a8Format error (1)w3d0ntlikebot5.parody. [malformed]nonenone256422false
                                      Jan 10, 2025 22:39:53.263148069 CET152.53.15.127192.168.2.140x3cdfFormat error (1)infectedslurs.geek. [malformed]nonenone256425false
                                      Jan 10, 2025 22:39:56.083542109 CET194.36.144.87192.168.2.140xe065Format error (1)chinklabs.dyn. [malformed]nonenone256428false
                                      Jan 10, 2025 22:39:58.873368025 CET152.53.15.127192.168.2.140x67caName error (3)infectedchink.piratenonenoneA (IP address)IN (0x0001)false
                                      Jan 10, 2025 22:40:01.668395996 CET194.36.144.87192.168.2.140x8b37Format error (1)burnthe.libre. [malformed]nonenone256433false
                                      Jan 10, 2025 22:40:04.514589071 CET51.158.108.203192.168.2.140xa5a0Format error (1)infectedslurs.geek. [malformed]nonenone256436false
                                      Jan 10, 2025 22:40:10.144819021 CET51.158.108.203192.168.2.140x9beeFormat error (1)hiakamai.dyn. [malformed]nonenone256442false
                                      Jan 10, 2025 22:40:12.943078995 CET65.21.1.106192.168.2.140x5239Format error (1)hiakamai.dyn. [malformed]nonenone256444false
                                      Jan 10, 2025 22:40:23.667349100 CET51.158.108.203192.168.2.140x9fb1Format error (1)dogeatingchink.parody. [malformed]nonenone256455false
                                      Jan 10, 2025 22:40:39.808602095 CET152.53.15.127192.168.2.140x8b65Format error (1)chinklabs.dyn. [malformed]nonenone256471false
                                      Jan 10, 2025 22:40:42.590312004 CET152.53.15.127192.168.2.140x4e5Format error (1)freethemonkeys.pirate. [malformed]nonenone256474false

                                      System Behavior

                                      Start time (UTC):21:38:53
                                      Start date (UTC):10/01/2025
                                      Path:/tmp/boatnet.arm.elf
                                      Arguments:/tmp/boatnet.arm.elf
                                      File size:4956856 bytes
                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                      Start time (UTC):21:38:53
                                      Start date (UTC):10/01/2025
                                      Path:/tmp/boatnet.arm.elf
                                      Arguments:-
                                      File size:4956856 bytes
                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                      Start time (UTC):21:38:53
                                      Start date (UTC):10/01/2025
                                      Path:/tmp/boatnet.arm.elf
                                      Arguments:-
                                      File size:4956856 bytes
                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1