Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
spc.elf

Overview

General Information

Sample name:spc.elf
Analysis ID:1588723
MD5:eacda0ea070ca1b3168fa1d059f84db0
SHA1:3dea1fd0c1dcaab392b888ce37afd4c9bd5d0e11
SHA256:367446efb00c75a510a0ed29913041e0d0b0928b6e5511b19a3195b760d4590a
Tags:elfuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1588723
Start date and time:2025-01-11 04:40:40 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 40s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:spc.elf
Detection:MAL
Classification:mal56.linELF@0/0@0/0
Command:/tmp/spc.elf
PID:6256
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
wormbot
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6229, Parent: 4331)
  • rm (PID: 6229, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.Kx15Y4ZrSy /tmp/tmp.zG9UODFNcX /tmp/tmp.s3tk65Vanm
  • dash New Fork (PID: 6230, Parent: 4331)
  • rm (PID: 6230, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.Kx15Y4ZrSy /tmp/tmp.zG9UODFNcX /tmp/tmp.s3tk65Vanm
  • spc.elf (PID: 6256, Parent: 6157, MD5: 7dc1c0e23cd5e102bb12e5c29403410e) Arguments: /tmp/spc.elf
    • spc.elf New Fork (PID: 6258, Parent: 6256)
  • cleanup
SourceRuleDescriptionAuthorStrings
spc.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xe6a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe6b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe6c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe6dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe6f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe704:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe718:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe72c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe740:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe754:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe768:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe77c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe790:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe7a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe7b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe7cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe7e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe7f4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe808:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe81c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe830:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
SourceRuleDescriptionAuthorStrings
6256.1.00007fb404011000.00007fb404021000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xe6a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe6b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe6c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe6dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe6f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe704:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe718:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe72c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe740:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe754:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe768:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe77c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe790:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe7a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe7b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe7cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe7e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe7f4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe808:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe81c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe830:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: spc.elf PID: 6256Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x454e:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4562:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4576:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x458a:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x459e:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x45b2:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x45c6:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x45da:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x45ee:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4602:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4616:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x462a:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x463e:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4652:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4666:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x467a:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x468e:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x46a2:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x46b6:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x46ca:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x46de:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: spc.elfVirustotal: Detection: 31%Perma Link
Source: spc.elfReversingLabs: Detection: 31%
Source: global trafficTCP traffic: 192.168.2.23:39354 -> 85.239.34.134:999
Source: /tmp/spc.elf (PID: 6256)Socket: 127.0.0.1:7567Jump to behavior
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: spc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6256.1.00007fb404011000.00007fb404021000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: spc.elf PID: 6256, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: ELF static info symbol of initial sample.symtab present: no
Source: spc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6256.1.00007fb404011000.00007fb404021000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: spc.elf PID: 6256, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal56.linELF@0/0@0/0
Source: /usr/bin/dash (PID: 6229)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.Kx15Y4ZrSy /tmp/tmp.zG9UODFNcX /tmp/tmp.s3tk65VanmJump to behavior
Source: /usr/bin/dash (PID: 6230)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.Kx15Y4ZrSy /tmp/tmp.zG9UODFNcX /tmp/tmp.s3tk65VanmJump to behavior
Source: /tmp/spc.elf (PID: 6256)Queries kernel information via 'uname': Jump to behavior
Source: spc.elf, 6256.1.0000564aa5ee6000.0000564aa5f4b000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sparc
Source: spc.elf, 6256.1.00007ffdd66d5000.00007ffdd66f6000.rw-.sdmpBinary or memory string: Ux86_64/usr/bin/qemu-sparc/tmp/spc.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/spc.elf
Source: spc.elf, 6256.1.0000564aa5ee6000.0000564aa5f4b000.rw-.sdmpBinary or memory string: JV!/etc/qemu-binfmt/sparc
Source: spc.elf, 6256.1.00007ffdd66d5000.00007ffdd66f6000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sparc
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
SourceDetectionScannerLabelLink
spc.elf32%VirustotalBrowse
spc.elf32%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
85.239.34.134
unknownRussian Federation
134121RAINBOW-HKRainbownetworklimitedHKfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
85.239.34.134x86.elfGet hashmaliciousUnknownBrowse
    arm.elfGet hashmaliciousUnknownBrowse
      arm7.elfGet hashmaliciousMiraiBrowse
        arm.elfGet hashmaliciousUnknownBrowse
          arm7.elfGet hashmaliciousUnknownBrowse
            x86.elfGet hashmaliciousUnknownBrowse
              154.216.17.162-arm-2025-01-09T02_53_12.elfGet hashmaliciousUnknownBrowse
                ppc.elfGet hashmaliciousUnknownBrowse
                  x86.elfGet hashmaliciousUnknownBrowse
                    mpsl.elfGet hashmaliciousUnknownBrowse
                      109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                      • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                      91.189.91.43sse.elfGet hashmaliciousGafgytBrowse
                        ssp.elfGet hashmaliciousGafgytBrowse
                          2.elfGet hashmaliciousUnknownBrowse
                            12.elfGet hashmaliciousUnknownBrowse
                              Space.arm.elfGet hashmaliciousMiraiBrowse
                                arm.elfGet hashmaliciousUnknownBrowse
                                  ss.elfGet hashmaliciousGafgytBrowse
                                    boatnet.x86.elfGet hashmaliciousUnknownBrowse
                                      Space.arm5.elfGet hashmaliciousUnknownBrowse
                                        ssd.elfGet hashmaliciousGafgytBrowse
                                          91.189.91.42sse.elfGet hashmaliciousGafgytBrowse
                                            ssp.elfGet hashmaliciousGafgytBrowse
                                              2.elfGet hashmaliciousUnknownBrowse
                                                12.elfGet hashmaliciousUnknownBrowse
                                                  Space.arm.elfGet hashmaliciousMiraiBrowse
                                                    arm.elfGet hashmaliciousUnknownBrowse
                                                      ss.elfGet hashmaliciousGafgytBrowse
                                                        boatnet.x86.elfGet hashmaliciousUnknownBrowse
                                                          Space.arm5.elfGet hashmaliciousUnknownBrowse
                                                            ssd.elfGet hashmaliciousGafgytBrowse
                                                              No context
                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                              RAINBOW-HKRainbownetworklimitedHKx86.elfGet hashmaliciousUnknownBrowse
                                                              • 85.239.34.134
                                                              arm.elfGet hashmaliciousUnknownBrowse
                                                              • 85.239.34.134
                                                              arm7.elfGet hashmaliciousMiraiBrowse
                                                              • 85.239.34.134
                                                              arm.elfGet hashmaliciousUnknownBrowse
                                                              • 85.239.34.134
                                                              arm7.elfGet hashmaliciousUnknownBrowse
                                                              • 85.239.34.134
                                                              x86.elfGet hashmaliciousUnknownBrowse
                                                              • 85.239.34.134
                                                              154.216.17.162-arm-2025-01-09T02_53_12.elfGet hashmaliciousUnknownBrowse
                                                              • 85.239.34.134
                                                              ppc.elfGet hashmaliciousUnknownBrowse
                                                              • 85.239.34.134
                                                              x86.elfGet hashmaliciousUnknownBrowse
                                                              • 85.239.34.134
                                                              mpsl.elfGet hashmaliciousUnknownBrowse
                                                              • 85.239.34.134
                                                              CANONICAL-ASGBsse.elfGet hashmaliciousGafgytBrowse
                                                              • 91.189.91.42
                                                              ssp.elfGet hashmaliciousGafgytBrowse
                                                              • 91.189.91.42
                                                              2.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              12.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              Space.arm.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              arm.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              ss.elfGet hashmaliciousGafgytBrowse
                                                              • 91.189.91.42
                                                              boatnet.arm7.elfGet hashmaliciousUnknownBrowse
                                                              • 185.125.190.26
                                                              boatnet.x86.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              Space.arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              CANONICAL-ASGBsse.elfGet hashmaliciousGafgytBrowse
                                                              • 91.189.91.42
                                                              ssp.elfGet hashmaliciousGafgytBrowse
                                                              • 91.189.91.42
                                                              2.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              12.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              Space.arm.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              arm.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              ss.elfGet hashmaliciousGafgytBrowse
                                                              • 91.189.91.42
                                                              boatnet.arm7.elfGet hashmaliciousUnknownBrowse
                                                              • 185.125.190.26
                                                              boatnet.x86.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              Space.arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              INIT7CHsse.elfGet hashmaliciousGafgytBrowse
                                                              • 109.202.202.202
                                                              ssp.elfGet hashmaliciousGafgytBrowse
                                                              • 109.202.202.202
                                                              2.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              12.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              Space.arm.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              arm.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              ss.elfGet hashmaliciousGafgytBrowse
                                                              • 109.202.202.202
                                                              boatnet.x86.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              Space.arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              ssd.elfGet hashmaliciousGafgytBrowse
                                                              • 109.202.202.202
                                                              No context
                                                              No context
                                                              No created / dropped files found
                                                              File type:ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, stripped
                                                              Entropy (8bit):5.96159032224557
                                                              TrID:
                                                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                              File name:spc.elf
                                                              File size:64'016 bytes
                                                              MD5:eacda0ea070ca1b3168fa1d059f84db0
                                                              SHA1:3dea1fd0c1dcaab392b888ce37afd4c9bd5d0e11
                                                              SHA256:367446efb00c75a510a0ed29913041e0d0b0928b6e5511b19a3195b760d4590a
                                                              SHA512:9c599c74c8160ca7418fb53b75ea27afc695a80f6e6642e7f5706b13fb6b68bae433506169b0a2f166db92af550a784b75413922487902880d6679853649fabc
                                                              SSDEEP:1536:yGN5CY0SlWw/kMNq+12odX62ZkoUIdHrN:ytzsNq6NdfkErN
                                                              TLSH:74531B627A7A0B27C4E1643850E7575EB3FA4BCD2564C20B7EB10D4DBFA89613053AF8
                                                              File Content Preview:.ELF...........................4.........4. ...(.......................x...x...............x...x...x......4`........................................dt.Q................................@..(....@.9%................#.....c...`.....!.....#...@.....".........`

                                                              ELF header

                                                              Class:ELF32
                                                              Data:2's complement, big endian
                                                              Version:1 (current)
                                                              Machine:Sparc
                                                              Version Number:0x1
                                                              Type:EXEC (Executable file)
                                                              OS/ABI:UNIX - System V
                                                              ABI Version:0
                                                              Entry Point Address:0x101c4
                                                              Flags:0x0
                                                              ELF Header Size:52
                                                              Program Header Offset:52
                                                              Program Header Size:32
                                                              Number of Program Headers:4
                                                              Section Header Offset:63456
                                                              Section Header Size:40
                                                              Number of Section Headers:14
                                                              Header String Table Index:13
                                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                              NULL0x00x00x00x00x0000
                                                              .initPROGBITS0x100b40xb40x1c0x00x6AX004
                                                              .textPROGBITS0x100d00xd00xe4cc0x00x6AX004
                                                              .finiPROGBITS0x1e59c0xe59c0x140x00x6AX004
                                                              .rodataPROGBITS0x1e5b00xe5b00xcc80x00x2A008
                                                              .eh_framePROGBITS0x202780xf2780x480x00x3WA004
                                                              .tbssNOBITS0x202c00xf2c00x80x00x403WAT004
                                                              .ctorsPROGBITS0x202c00xf2c00x80x00x3WA004
                                                              .dtorsPROGBITS0x202c80xf2c80x80x00x3WA004
                                                              .jcrPROGBITS0x202d00xf2d00x40x00x3WA004
                                                              .gotPROGBITS0x202d40xf2d40x10c0x40x3WA004
                                                              .dataPROGBITS0x203e00xf3e00x3a80x00x3WA008
                                                              .bssNOBITS0x207880xf7880x2f500x00x3WA008
                                                              .shstrtabSTRTAB0x00xf7880x580x00x0001
                                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                              LOAD0x00x100000x100000xf2780xf2785.97140x5R E0x1000.init .text .fini .rodata
                                                              LOAD0xf2780x202780x202780x5100x34605.02760x6RW 0x1000.eh_frame .tbss .ctors .dtors .jcr .got .data .bss
                                                              TLS0xf2c00x202c00x202c00x00x80.00000x4R 0x4.tbss
                                                              GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Jan 11, 2025 04:41:28.517568111 CET39354999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:28.522469997 CET9993935485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:28.522535086 CET39354999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:28.522840023 CET39354999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:28.528114080 CET9993935485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:28.528153896 CET39354999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:28.533677101 CET9993935485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:28.823833942 CET43928443192.168.2.2391.189.91.42
                                                              Jan 11, 2025 04:41:30.277235031 CET9993935485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:30.277968884 CET39354999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:30.282777071 CET9993935485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:31.279681921 CET39356999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:31.284540892 CET9993935685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:31.284606934 CET39356999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:31.284630060 CET39356999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:31.289474964 CET9993935685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:31.289525032 CET39356999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:31.294337034 CET9993935685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:33.041728973 CET9993935685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:33.042023897 CET39356999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:33.046892881 CET9993935685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:34.043629885 CET39358999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:34.053392887 CET9993935885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:34.053471088 CET39358999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:34.053492069 CET39358999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:34.058442116 CET9993935885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:34.058501959 CET39358999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:34.063277006 CET9993935885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:34.198977947 CET42836443192.168.2.2391.189.91.43
                                                              Jan 11, 2025 04:41:35.478807926 CET4251680192.168.2.23109.202.202.202
                                                              Jan 11, 2025 04:41:35.806557894 CET9993935885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:35.806840897 CET39358999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:35.811748028 CET9993935885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:36.809161901 CET39360999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:36.814111948 CET9993936085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:36.814258099 CET39360999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:36.814316988 CET39360999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:36.819130898 CET9993936085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:36.819195986 CET39360999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:36.824027061 CET9993936085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:38.608887911 CET9993936085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:38.609083891 CET39360999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:38.614023924 CET9993936085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:39.610965967 CET39362999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:39.615731001 CET9993936285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:39.615808964 CET39362999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:39.615839958 CET39362999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:39.620618105 CET9993936285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:39.620686054 CET39362999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:39.625492096 CET9993936285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:41.388557911 CET9993936285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:41.388988018 CET39362999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:41.393913031 CET9993936285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:42.391252041 CET39364999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:42.396030903 CET9993936485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:42.396090984 CET39364999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:42.396111012 CET39364999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:42.400893927 CET9993936485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:42.400940895 CET39364999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:42.405786037 CET9993936485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:44.136274099 CET9993936485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:44.136473894 CET39364999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:44.141329050 CET9993936485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:45.138561964 CET39366999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:45.143491983 CET9993936685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:45.143552065 CET39366999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:45.143572092 CET39366999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:45.148369074 CET9993936685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:45.148417950 CET39366999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:45.153253078 CET9993936685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:46.904357910 CET9993936685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:46.904624939 CET39366999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:46.909544945 CET9993936685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:47.906691074 CET39368999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:47.911474943 CET9993936885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:47.911549091 CET39368999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:47.911587000 CET39368999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:47.916342020 CET9993936885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:47.916402102 CET39368999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:47.921201944 CET9993936885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:49.300795078 CET43928443192.168.2.2391.189.91.42
                                                              Jan 11, 2025 04:41:49.665713072 CET9993936885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:49.666111946 CET39368999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:49.670878887 CET9993936885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:50.668104887 CET39370999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:50.673022985 CET9993937085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:50.673094034 CET39370999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:50.673142910 CET39370999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:50.678009033 CET9993937085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:50.678054094 CET39370999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:50.682791948 CET9993937085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:52.431338072 CET9993937085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:52.431590080 CET39370999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:52.436521053 CET9993937085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:53.433665991 CET39372999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:53.438674927 CET9993937285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:53.438779116 CET39372999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:53.438779116 CET39372999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:53.443700075 CET9993937285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:53.443778992 CET39372999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:53.448626041 CET9993937285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:55.212837934 CET9993937285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:55.213120937 CET39372999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:55.217947006 CET9993937285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:56.215307951 CET39374999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:56.220256090 CET9993937485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:56.220366001 CET39374999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:56.220433950 CET39374999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:56.225316048 CET9993937485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:56.225394964 CET39374999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:56.230262995 CET9993937485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:57.977930069 CET9993937485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:57.978317976 CET39374999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:57.983156919 CET9993937485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:58.980400085 CET39376999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:58.985312939 CET9993937685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:58.985394001 CET39376999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:58.985440969 CET39376999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:58.990250111 CET9993937685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:41:58.990303993 CET39376999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:41:58.995054960 CET9993937685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:00.728425026 CET9993937685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:00.728872061 CET39376999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:00.733747959 CET9993937685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:01.586916924 CET42836443192.168.2.2391.189.91.43
                                                              Jan 11, 2025 04:42:01.730880976 CET39378999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:01.735766888 CET9993937885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:01.735879898 CET39378999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:01.735925913 CET39378999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:01.740705967 CET9993937885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:01.740776062 CET39378999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:01.745549917 CET9993937885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:03.511779070 CET9993937885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:03.512176037 CET39378999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:03.517055035 CET9993937885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:04.514647961 CET39380999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:04.519510031 CET9993938085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:04.519603968 CET39380999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:04.519659042 CET39380999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:04.524498940 CET9993938085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:04.524573088 CET39380999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:04.529386997 CET9993938085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:05.682290077 CET4251680192.168.2.23109.202.202.202
                                                              Jan 11, 2025 04:42:06.277482986 CET9993938085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:06.277853012 CET39380999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:06.283077002 CET9993938085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:07.279660940 CET39382999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:07.284555912 CET9993938285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:07.284651995 CET39382999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:07.284676075 CET39382999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:07.289504051 CET9993938285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:07.289578915 CET39382999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:07.294365883 CET9993938285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:09.040960073 CET9993938285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:09.041268110 CET39382999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:09.046065092 CET9993938285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:10.043541908 CET39384999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:10.048413992 CET9993938485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:10.048496008 CET39384999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:10.048571110 CET39384999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:10.053385973 CET9993938485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:10.053533077 CET39384999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:10.058327913 CET9993938485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:11.807435989 CET9993938485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:11.807665110 CET39384999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:11.812856913 CET9993938485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:12.809387922 CET39386999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:12.814405918 CET9993938685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:12.814490080 CET39386999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:12.814507008 CET39386999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:12.819391966 CET9993938685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:12.819472075 CET39386999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:12.824299097 CET9993938685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:14.571729898 CET9993938685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:14.572024107 CET39386999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:14.576883078 CET9993938685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:15.574521065 CET39388999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:15.579369068 CET9993938885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:15.579480886 CET39388999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:15.579536915 CET39388999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:15.584350109 CET9993938885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:15.584427118 CET39388999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:15.589262962 CET9993938885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:17.358370066 CET9993938885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:17.358743906 CET39388999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:17.363563061 CET9993938885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:18.361762047 CET39390999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:18.366693020 CET9993939085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:18.366787910 CET39390999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:18.366826057 CET39390999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:18.371674061 CET9993939085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:18.371747017 CET39390999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:18.376593113 CET9993939085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:20.103769064 CET9993939085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:20.104286909 CET39390999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:20.109241009 CET9993939085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:21.107913017 CET39392999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:21.112850904 CET9993939285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:21.112993956 CET39392999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:21.113035917 CET39392999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:21.117908001 CET9993939285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:21.118036985 CET39392999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:21.122971058 CET9993939285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:22.870405912 CET9993939285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:22.870640039 CET39392999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:22.876234055 CET9993939285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:23.872947931 CET39394999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:23.877871990 CET9993939485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:23.877969980 CET39394999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:23.878019094 CET39394999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:23.882863998 CET9993939485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:23.882971048 CET39394999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:23.887811899 CET9993939485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:25.635138988 CET9993939485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:25.635334015 CET39394999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:25.640218019 CET9993939485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:26.637636900 CET39396999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:26.642580986 CET9993939685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:26.642693996 CET39396999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:26.642755032 CET39396999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:26.647653103 CET9993939685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:26.647846937 CET39396999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:26.652611971 CET9993939685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:28.385087967 CET9993939685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:28.385379076 CET39396999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:28.390328884 CET9993939685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:29.387984037 CET39398999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:29.393208027 CET9993939885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:29.393295050 CET39398999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:29.393316984 CET39398999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:29.398248911 CET9993939885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:29.398319960 CET39398999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:29.403244972 CET9993939885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:30.254740953 CET43928443192.168.2.2391.189.91.42
                                                              Jan 11, 2025 04:42:31.151012897 CET9993939885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:31.151206017 CET39398999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:31.156167030 CET9993939885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:32.153373957 CET39400999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:32.158452034 CET9993940085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:32.158531904 CET39400999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:32.158548117 CET39400999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:32.163378954 CET9993940085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:32.163436890 CET39400999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:32.168325901 CET9993940085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:33.917900085 CET9993940085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:33.918118000 CET39400999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:33.918118000 CET39400999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:33.923036098 CET9993940085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:34.920384884 CET39402999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:34.925393105 CET9993940285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:34.925476074 CET39402999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:34.925493002 CET39402999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:34.930382013 CET9993940285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:34.930516958 CET39402999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:34.935374022 CET9993940285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:36.682384968 CET9993940285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:36.682682991 CET39402999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:36.687566996 CET9993940285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:37.686491013 CET39404999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:37.691615105 CET9993940485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:37.691777945 CET39404999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:37.691777945 CET39404999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:37.696701050 CET9993940485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:37.696796894 CET39404999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:37.701682091 CET9993940485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:39.432313919 CET9993940485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:39.432559967 CET39404999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:39.437568903 CET9993940485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:40.435340881 CET39406999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:40.440484047 CET9993940685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:40.440572023 CET39406999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:40.440634012 CET39406999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:40.445530891 CET9993940685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:40.445581913 CET39406999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:40.450426102 CET9993940685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:42.198194981 CET9993940685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:42.198394060 CET39406999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:42.203236103 CET9993940685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:43.201119900 CET39408999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:43.206167936 CET9993940885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:43.206242085 CET39408999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:43.206290007 CET39408999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:43.211076021 CET9993940885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:43.211157084 CET39408999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:43.216028929 CET9993940885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:44.965317011 CET9993940885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:44.965560913 CET39408999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:44.970501900 CET9993940885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:45.967705011 CET39410999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:45.972640991 CET9993941085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:45.972752094 CET39410999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:45.972807884 CET39410999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:45.977581024 CET9993941085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:45.977642059 CET39410999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:45.982465029 CET9993941085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:47.729090929 CET9993941085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:47.729473114 CET39410999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:47.734494925 CET9993941085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:48.732436895 CET39412999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:48.737765074 CET9993941285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:48.737880945 CET39412999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:48.737945080 CET39412999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:48.743221998 CET9993941285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:48.743289948 CET39412999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:48.748229027 CET9993941285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:50.496484041 CET9993941285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:50.496932030 CET39412999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:50.501878023 CET9993941285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:51.499340057 CET39414999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:51.504148960 CET9993941485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:51.504406929 CET39414999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:51.504406929 CET39414999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:51.509222984 CET9993941485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:51.509295940 CET39414999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:51.514139891 CET9993941485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:53.262217045 CET9993941485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:53.262438059 CET39414999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:53.269413948 CET9993941485.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:54.264514923 CET39416999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:54.269515991 CET9993941685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:54.269602060 CET39416999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:54.269648075 CET39416999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:54.274508953 CET9993941685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:54.274571896 CET39416999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:54.279470921 CET9993941685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:56.010278940 CET9993941685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:56.010601997 CET39416999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:56.015470982 CET9993941685.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:57.013098955 CET39418999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:57.017996073 CET9993941885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:57.018085957 CET39418999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:57.018132925 CET39418999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:57.022914886 CET9993941885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:57.022981882 CET39418999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:57.027755022 CET9993941885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:58.808917046 CET9993941885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:58.809232950 CET39418999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:58.814028978 CET9993941885.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:59.811059952 CET39420999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:59.815874100 CET9993942085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:59.815943956 CET39420999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:59.815968990 CET39420999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:59.820760012 CET9993942085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:42:59.820848942 CET39420999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:42:59.825704098 CET9993942085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:43:01.572520971 CET9993942085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:43:01.572841883 CET39420999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:43:01.577646971 CET9993942085.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:43:02.575114965 CET39422999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:43:02.580022097 CET9993942285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:43:02.580112934 CET39422999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:43:02.580162048 CET39422999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:43:02.584964991 CET9993942285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:43:02.585040092 CET39422999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:43:02.589874983 CET9993942285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:43:12.589292049 CET39422999192.168.2.2385.239.34.134
                                                              Jan 11, 2025 04:43:12.594149113 CET9993942285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:43:12.816725016 CET9993942285.239.34.134192.168.2.23
                                                              Jan 11, 2025 04:43:12.817023993 CET39422999192.168.2.2385.239.34.134

                                                              System Behavior

                                                              Start time (UTC):03:41:24
                                                              Start date (UTC):11/01/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):03:41:24
                                                              Start date (UTC):11/01/2025
                                                              Path:/usr/bin/rm
                                                              Arguments:rm -f /tmp/tmp.Kx15Y4ZrSy /tmp/tmp.zG9UODFNcX /tmp/tmp.s3tk65Vanm
                                                              File size:72056 bytes
                                                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                              Start time (UTC):03:41:24
                                                              Start date (UTC):11/01/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):03:41:24
                                                              Start date (UTC):11/01/2025
                                                              Path:/usr/bin/rm
                                                              Arguments:rm -f /tmp/tmp.Kx15Y4ZrSy /tmp/tmp.zG9UODFNcX /tmp/tmp.s3tk65Vanm
                                                              File size:72056 bytes
                                                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                              Start time (UTC):03:41:27
                                                              Start date (UTC):11/01/2025
                                                              Path:/tmp/spc.elf
                                                              Arguments:/tmp/spc.elf
                                                              File size:4379400 bytes
                                                              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                                                              Start time (UTC):03:41:27
                                                              Start date (UTC):11/01/2025
                                                              Path:/tmp/spc.elf
                                                              Arguments:-
                                                              File size:4379400 bytes
                                                              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e