Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
ppc.elf

Overview

General Information

Sample name:ppc.elf
Analysis ID:1588737
MD5:8c7b72161082b652c42c91091c479471
SHA1:ee7e836fa2474f220a90bfb1d744f2233f3616a4
SHA256:04ff0628b46e45010d4579d8a1ae4ae87b10782526e17fdbbd91f547aa24a06a
Tags:elfMiraiuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1588737
Start date and time:2025-01-11 04:51:18 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 30s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:ppc.elf
Detection:MAL
Classification:mal56.linELF@0/0@0/0
Command:/tmp/ppc.elf
PID:5432
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
wormbot
Standard Error:
  • system is lnxubuntu20
  • ppc.elf (PID: 5432, Parent: 5353, MD5: ae65271c943d3451b7f026d1fadccea6) Arguments: /tmp/ppc.elf
    • ppc.elf New Fork (PID: 5434, Parent: 5432)
  • cleanup
SourceRuleDescriptionAuthorStrings
ppc.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xc548:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc55c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc570:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc584:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc598:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc5ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc5c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc5d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc5e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc5fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc610:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc624:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc638:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc64c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc660:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc674:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc688:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc69c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc6b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc6c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc6d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
SourceRuleDescriptionAuthorStrings
5432.1.00007f0734001000.00007f073400f000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xc548:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc55c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc570:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc584:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc598:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc5ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc5c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc5d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc5e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc5fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc610:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc624:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc638:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc64c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc660:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc674:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc688:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc69c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc6b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc6c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc6d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: ppc.elf PID: 5432Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x106a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x106b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x106cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x106e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x106f4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10708:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1071c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10730:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10744:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10758:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1076c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10780:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10794:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x107a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x107bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x107d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x107e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x107f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1080c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10820:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10834:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: ppc.elfVirustotal: Detection: 29%Perma Link
Source: ppc.elfReversingLabs: Detection: 39%
Source: global trafficTCP traffic: 192.168.2.13:45928 -> 85.239.34.134:999
Source: /tmp/ppc.elf (PID: 5432)Socket: 127.0.0.1:7567Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134

System Summary

barindex
Source: ppc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5432.1.00007f0734001000.00007f073400f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: ppc.elf PID: 5432, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: ELF static info symbol of initial sample.symtab present: no
Source: ppc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5432.1.00007f0734001000.00007f073400f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: ppc.elf PID: 5432, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal56.linELF@0/0@0/0
Source: /tmp/ppc.elf (PID: 5432)Queries kernel information via 'uname': Jump to behavior
Source: ppc.elf, 5432.1.000056537831f000.00005653783d6000.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc11!hotpluggableq
Source: ppc.elf, 5432.1.00007ffc47579000.00007ffc4759a000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-ppc/tmp/ppc.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/ppc.elf
Source: ppc.elf, 5432.1.000056537831f000.00005653783d6000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/ppc
Source: ppc.elf, 5432.1.00007ffc47579000.00007ffc4759a000.rw-.sdmpBinary or memory string: /usr/bin/qemu-ppc
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
ppc.elf30%VirustotalBrowse
ppc.elf39%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
85.239.34.134
unknownRussian Federation
134121RAINBOW-HKRainbownetworklimitedHKfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
85.239.34.134arm6.elfGet hashmaliciousUnknownBrowse
    arm5.elfGet hashmaliciousUnknownBrowse
      m68k.elfGet hashmaliciousUnknownBrowse
        mpsl.elfGet hashmaliciousUnknownBrowse
          harm.elfGet hashmaliciousUnknownBrowse
            mips.elfGet hashmaliciousUnknownBrowse
              spc.elfGet hashmaliciousUnknownBrowse
                x86.elfGet hashmaliciousUnknownBrowse
                  arm.elfGet hashmaliciousUnknownBrowse
                    arm7.elfGet hashmaliciousMiraiBrowse
                      No context
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      RAINBOW-HKRainbownetworklimitedHKarm6.elfGet hashmaliciousUnknownBrowse
                      • 85.239.34.134
                      arm5.elfGet hashmaliciousUnknownBrowse
                      • 85.239.34.134
                      m68k.elfGet hashmaliciousUnknownBrowse
                      • 85.239.34.134
                      mpsl.elfGet hashmaliciousUnknownBrowse
                      • 85.239.34.134
                      harm.elfGet hashmaliciousUnknownBrowse
                      • 85.239.34.134
                      mips.elfGet hashmaliciousUnknownBrowse
                      • 85.239.34.134
                      spc.elfGet hashmaliciousUnknownBrowse
                      • 85.239.34.134
                      x86.elfGet hashmaliciousUnknownBrowse
                      • 85.239.34.134
                      arm.elfGet hashmaliciousUnknownBrowse
                      • 85.239.34.134
                      arm7.elfGet hashmaliciousMiraiBrowse
                      • 85.239.34.134
                      No context
                      No context
                      No created / dropped files found
                      File type:ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, stripped
                      Entropy (8bit):6.192781244144005
                      TrID:
                      • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                      File name:ppc.elf
                      File size:55'268 bytes
                      MD5:8c7b72161082b652c42c91091c479471
                      SHA1:ee7e836fa2474f220a90bfb1d744f2233f3616a4
                      SHA256:04ff0628b46e45010d4579d8a1ae4ae87b10782526e17fdbbd91f547aa24a06a
                      SHA512:b7d6d7bc3ab35f2169bba778586697cbb747ee294bc6e1b929abdfaaac6840617417325463ab9145fb6c6b86c7cf0e8b3d0d1f73c2ff1c82c9217160184883c8
                      SSDEEP:1536:grn8Zo0iS/XZG5uiwGCgptyTU+NhlF/0I:gLSo0FPGuZXg0t8I
                      TLSH:2B431A0272250E57E6934EB42A2F2BD0D7BB9DD026F0F6492A1F7B554D72E370483E89
                      File Content Preview:.ELF...........................4...d.....4. ...(..........................................................-................X...X...X................dt.Q.............................!..|......$H...H..9...$8!. |...N.. .!..|.......?..........p..../...@..`= .

                      ELF header

                      Class:ELF32
                      Data:2's complement, big endian
                      Version:1 (current)
                      Machine:PowerPC
                      Version Number:0x1
                      Type:EXEC (Executable file)
                      OS/ABI:UNIX - System V
                      ABI Version:0
                      Entry Point Address:0x10000218
                      Flags:0x0
                      ELF Header Size:52
                      Program Header Offset:52
                      Program Header Size:32
                      Number of Program Headers:4
                      Section Header Offset:54628
                      Section Header Size:40
                      Number of Section Headers:16
                      Header String Table Index:15
                      NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                      NULL0x00x00x00x00x0000
                      .initPROGBITS0x100000b40xb40x240x00x6AX004
                      .textPROGBITS0x100000d80xd80xbf900x00x6AX004
                      .finiPROGBITS0x1000c0680xc0680x200x00x6AX004
                      .rodataPROGBITS0x1000c0880xc0880x107c0x00x2A004
                      .eh_framePROGBITS0x1000e1040xd1040x540x00x3WA004
                      .tbssNOBITS0x1000e1580xd1580x80x00x403WAT004
                      .ctorsPROGBITS0x1000e1580xd1580x80x00x3WA004
                      .dtorsPROGBITS0x1000e1600xd1600x80x00x3WA004
                      .jcrPROGBITS0x1000e1680xd1680x40x00x3WA004
                      .dataPROGBITS0x1000e16c0xd16c0x3200x00x3WA004
                      .gotPROGBITS0x1000e48c0xd48c0x100x40x7WAX004
                      .sdataPROGBITS0x1000e49c0xd49c0x600x00x3WA004
                      .sbssNOBITS0x1000e4fc0xd4fc0x740x00x3WA004
                      .bssNOBITS0x1000e5700xd4fc0x29540x00x3WA004
                      .shstrtabSTRTAB0x00xd4fc0x650x00x0001
                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                      LOAD0x00x100000000x100000000xd1040xd1046.22320x5R E0x1000.init .text .fini .rodata
                      LOAD0xd1040x1000e1040x1000e1040x3f80x2dc04.97420x7RWE0x1000.eh_frame .tbss .ctors .dtors .jcr .data .got .sdata .sbss .bss
                      TLS0xd1580x1000e1580x1000e1580x00x80.00000x4R 0x4.tbss
                      GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                      TimestampSource PortDest PortSource IPDest IP
                      Jan 11, 2025 04:52:07.247275114 CET45928999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:07.252233028 CET9994592885.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:07.252307892 CET45928999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:07.252490997 CET45928999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:07.257232904 CET9994592885.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:07.257282019 CET45928999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:07.262150049 CET9994592885.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:09.021068096 CET9994592885.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:09.021600962 CET45928999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:09.026434898 CET9994592885.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:10.031507969 CET45930999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:10.036606073 CET9994593085.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:10.036674976 CET45930999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:10.036703110 CET45930999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:10.041547060 CET9994593085.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:10.041601896 CET45930999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:10.046374083 CET9994593085.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:11.802464008 CET9994593085.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:11.802830935 CET45930999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:11.807931900 CET9994593085.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:12.804836988 CET45932999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:12.809788942 CET9994593285.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:12.809853077 CET45932999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:12.809875011 CET45932999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:12.814687967 CET9994593285.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:12.814735889 CET45932999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:12.819570065 CET9994593285.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:14.585721970 CET9994593285.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:14.586015940 CET45932999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:14.591033936 CET9994593285.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:15.588970900 CET45934999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:15.594017982 CET9994593485.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:15.594110012 CET45934999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:15.594173908 CET45934999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:15.598932028 CET9994593485.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:15.599021912 CET45934999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:15.603837967 CET9994593485.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:17.346775055 CET9994593485.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:17.347090006 CET45934999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:17.352364063 CET9994593485.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:18.349437952 CET45936999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:18.354547024 CET9994593685.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:18.354656935 CET45936999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:18.354700089 CET45936999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:18.359509945 CET9994593685.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:18.359570026 CET45936999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:18.364384890 CET9994593685.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:20.111294031 CET9994593685.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:20.111762047 CET45936999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:20.116873980 CET9994593685.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:21.114216089 CET45938999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:21.119276047 CET9994593885.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:21.119410038 CET45938999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:21.119450092 CET45938999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:21.124313116 CET9994593885.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:21.124423027 CET45938999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:21.129216909 CET9994593885.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:22.865221977 CET9994593885.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:22.865612030 CET45938999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:22.870423079 CET9994593885.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:23.868109941 CET45940999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:23.873192072 CET9994594085.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:23.873341084 CET45940999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:23.873341084 CET45940999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:23.878225088 CET9994594085.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:23.878283024 CET45940999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:23.883372068 CET9994594085.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:25.630397081 CET9994594085.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:25.630899906 CET45940999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:25.635802031 CET9994594085.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:26.633521080 CET45942999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:26.639035940 CET9994594285.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:26.639138937 CET45942999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:26.639188051 CET45942999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:26.645087957 CET9994594285.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:26.645152092 CET45942999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:26.650757074 CET9994594285.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:28.412262917 CET9994594285.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:28.412493944 CET45942999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:28.417375088 CET9994594285.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:29.414639950 CET45944999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:29.419812918 CET9994594485.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:29.419892073 CET45944999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:29.419914007 CET45944999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:29.424747944 CET9994594485.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:29.424820900 CET45944999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:29.429686069 CET9994594485.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:31.193680048 CET9994594485.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:31.193964958 CET45944999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:31.199306965 CET9994594485.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:32.196806908 CET45946999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:32.201910019 CET9994594685.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:32.202023029 CET45946999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:32.202075005 CET45946999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:32.206944942 CET9994594685.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:32.207026958 CET45946999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:32.211880922 CET9994594685.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:33.941836119 CET9994594685.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:33.942426920 CET45946999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:33.947376013 CET9994594685.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:34.945194006 CET45948999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:34.951168060 CET9994594885.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:34.951278925 CET45948999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:34.951339006 CET45948999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:34.956156015 CET9994594885.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:34.956259966 CET45948999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:34.963795900 CET9994594885.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:36.705615044 CET9994594885.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:36.706193924 CET45948999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:36.711133957 CET9994594885.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:37.708830118 CET45950999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:37.713988066 CET9994595085.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:37.714080095 CET45950999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:37.714133024 CET45950999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:37.718919992 CET9994595085.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:37.718981981 CET45950999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:37.723793030 CET9994595085.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:39.474303961 CET9994595085.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:39.474741936 CET45950999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:39.474797010 CET45950999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:39.480532885 CET9994595085.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:40.477813005 CET45952999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:40.482925892 CET9994595285.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:40.483036995 CET45952999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:40.483081102 CET45952999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:40.487947941 CET9994595285.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:40.488064051 CET45952999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:40.492945910 CET9994595285.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:42.239780903 CET9994595285.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:42.240041971 CET45952999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:42.245976925 CET9994595285.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:43.242635965 CET45954999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:43.256593943 CET9994595485.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:43.256726980 CET45954999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:43.256901979 CET45954999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:43.261836052 CET9994595485.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:43.261920929 CET45954999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:43.266823053 CET9994595485.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:45.038701057 CET9994595485.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:45.039180994 CET45954999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:45.044017076 CET9994595485.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:46.041815042 CET45956999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:46.046849012 CET9994595685.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:46.046952963 CET45956999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:46.047022104 CET45956999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:46.051840067 CET9994595685.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:46.052309990 CET45956999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:46.057128906 CET9994595685.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:47.818799019 CET9994595685.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:47.819339991 CET45956999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:47.825496912 CET9994595685.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:48.821438074 CET45958999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:48.826695919 CET9994595885.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:48.826793909 CET45958999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:48.826793909 CET45958999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:48.831702948 CET9994595885.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:48.831774950 CET45958999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:48.836754084 CET9994595885.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:50.580432892 CET9994595885.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:50.580817938 CET45958999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:50.586395979 CET9994595885.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:51.583300114 CET45960999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:51.911591053 CET9994596085.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:51.911848068 CET45960999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:51.912025928 CET45960999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:51.916815996 CET9994596085.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:51.916902065 CET45960999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:51.921766043 CET9994596085.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:53.658966064 CET9994596085.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:53.659539938 CET45960999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:53.664588928 CET9994596085.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:54.662281990 CET45962999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:54.667382002 CET9994596285.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:54.667474031 CET45962999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:54.667511940 CET45962999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:54.672394037 CET9994596285.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:54.672461987 CET45962999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:54.677299023 CET9994596285.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:56.428244114 CET9994596285.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:56.428611994 CET45962999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:56.433547020 CET9994596285.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:57.431417942 CET45964999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:57.436465979 CET9994596485.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:57.436594963 CET45964999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:57.436642885 CET45964999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:57.441490889 CET9994596485.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:57.441606998 CET45964999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:57.446458101 CET9994596485.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:59.225119114 CET9994596485.239.34.134192.168.2.13
                      Jan 11, 2025 04:52:59.225475073 CET45964999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:52:59.230329990 CET9994596485.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:00.227761030 CET45966999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:00.234518051 CET9994596685.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:00.234621048 CET45966999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:00.234668016 CET45966999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:00.241060972 CET9994596685.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:00.241132021 CET45966999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:00.245973110 CET9994596685.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:02.230304956 CET9994596685.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:02.230541945 CET45966999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:02.235492945 CET9994596685.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:03.233222008 CET45968999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:03.238236904 CET9994596885.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:03.238359928 CET45968999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:03.238396883 CET45968999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:03.243252993 CET9994596885.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:03.243390083 CET45968999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:03.248297930 CET9994596885.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:04.986908913 CET9994596885.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:04.987252951 CET45968999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:04.992127895 CET9994596885.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:05.990380049 CET45970999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:05.997663975 CET9994597085.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:05.997776031 CET45970999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:05.997816086 CET45970999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:06.004179955 CET9994597085.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:06.004278898 CET45970999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:06.009640932 CET9994597085.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:07.787516117 CET9994597085.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:07.788119078 CET45970999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:07.793011904 CET9994597085.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:08.791835070 CET45972999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:08.796889067 CET9994597285.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:08.796969891 CET45972999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:08.797136068 CET45972999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:08.801987886 CET9994597285.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:08.802057028 CET45972999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:08.808101892 CET9994597285.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:10.550297976 CET9994597285.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:10.550776005 CET45972999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:10.555646896 CET9994597285.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:11.553873062 CET45974999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:11.558834076 CET9994597485.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:11.558969021 CET45974999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:11.559029102 CET45974999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:11.563847065 CET9994597485.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:11.563927889 CET45974999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:11.568834066 CET9994597485.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:13.314635992 CET9994597485.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:13.314958096 CET45974999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:13.319766998 CET9994597485.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:14.317934036 CET45976999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:14.322916985 CET9994597685.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:14.323020935 CET45976999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:14.323062897 CET45976999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:14.327887058 CET9994597685.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:14.327971935 CET45976999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:14.332886934 CET9994597685.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:16.118611097 CET9994597685.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:16.119070053 CET45976999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:16.124078035 CET9994597685.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:17.122232914 CET45978999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:17.127176046 CET9994597885.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:17.127286911 CET45978999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:17.127351999 CET45978999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:17.132112026 CET9994597885.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:17.132250071 CET45978999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:17.137080908 CET9994597885.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:18.877314091 CET9994597885.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:18.877877951 CET45978999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:18.882831097 CET9994597885.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:19.881072998 CET45980999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:19.886221886 CET9994598085.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:19.886293888 CET45980999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:19.886343002 CET45980999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:19.891289949 CET9994598085.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:19.891349077 CET45980999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:19.896400928 CET9994598085.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:21.664747000 CET9994598085.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:21.665326118 CET45980999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:21.670248032 CET9994598085.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:22.670339108 CET45982999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:22.675544024 CET9994598285.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:22.675817013 CET45982999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:22.676054001 CET45982999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:22.680902958 CET9994598285.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:22.681016922 CET45982999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:22.685846090 CET9994598285.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:24.442122936 CET9994598285.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:24.442380905 CET45982999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:24.447233915 CET9994598285.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:25.445856094 CET45984999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:25.451984882 CET9994598485.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:25.452100992 CET45984999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:25.452148914 CET45984999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:25.457020998 CET9994598485.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:25.457151890 CET45984999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:25.462025881 CET9994598485.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:27.228948116 CET9994598485.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:27.229302883 CET45984999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:27.234234095 CET9994598485.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:28.232661963 CET45986999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:28.237653971 CET9994598685.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:28.237768888 CET45986999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:28.237768888 CET45986999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:28.242666006 CET9994598685.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:28.242734909 CET45986999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:28.247632027 CET9994598685.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:30.006882906 CET9994598685.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:30.007359028 CET45986999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:30.012305021 CET9994598685.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:31.009689093 CET45988999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:31.014589071 CET9994598885.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:31.014709949 CET45988999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:31.014709949 CET45988999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:31.019519091 CET9994598885.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:31.019596100 CET45988999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:31.024401903 CET9994598885.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:32.804810047 CET9994598885.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:32.805195093 CET45988999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:32.810225010 CET9994598885.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:33.808185101 CET45990999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:33.813189983 CET9994599085.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:33.813294888 CET45990999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:33.813337088 CET45990999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:33.818160057 CET9994599085.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:33.818228960 CET45990999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:33.823076963 CET9994599085.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:35.567356110 CET9994599085.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:35.567681074 CET45990999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:35.572566032 CET9994599085.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:36.569814920 CET45992999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:36.574708939 CET9994599285.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:36.574796915 CET45992999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:36.574810028 CET45992999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:36.579540968 CET9994599285.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:36.579621077 CET45992999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:36.584341049 CET9994599285.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:38.334681034 CET9994599285.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:38.335057020 CET45992999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:38.339900970 CET9994599285.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:39.337256908 CET45994999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:39.342201948 CET9994599485.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:39.342286110 CET45994999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:39.342322111 CET45994999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:39.347129107 CET9994599485.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:39.347206116 CET45994999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:39.352005959 CET9994599485.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:41.098546982 CET9994599485.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:41.098975897 CET45994999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:41.103828907 CET9994599485.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:42.101193905 CET45996999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:42.106134892 CET9994599685.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:42.106298923 CET45996999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:42.106321096 CET45996999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:42.111145973 CET9994599685.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:42.111221075 CET45996999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:42.116012096 CET9994599685.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:43.863229036 CET9994599685.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:43.863543034 CET45996999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:43.868415117 CET9994599685.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:44.865689039 CET45998999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:44.870884895 CET9994599885.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:44.870990992 CET45998999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:44.871028900 CET45998999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:44.875900984 CET9994599885.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:44.875977039 CET45998999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:44.880829096 CET9994599885.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:46.614742041 CET9994599885.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:46.615360022 CET45998999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:46.622068882 CET9994599885.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:47.617424965 CET46000999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:47.622519016 CET9994600085.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:47.622586012 CET46000999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:47.622605085 CET46000999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:47.627453089 CET9994600085.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:47.627506971 CET46000999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:47.632462978 CET9994600085.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:49.378329039 CET9994600085.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:49.378504038 CET46000999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:49.383462906 CET9994600085.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:50.381067991 CET46002999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:50.386254072 CET9994600285.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:50.386332989 CET46002999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:50.386352062 CET46002999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:50.391303062 CET9994600285.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:50.391355038 CET46002999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:50.396528006 CET9994600285.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:52.146574020 CET9994600285.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:52.146930933 CET46002999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:52.151894093 CET9994600285.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:53.150162935 CET46004999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:53.155208111 CET9994600485.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:53.155354977 CET46004999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:53.155390024 CET46004999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:53.160203934 CET9994600485.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:53.160314083 CET46004999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:53.165234089 CET9994600485.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:54.930891037 CET9994600485.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:54.931231976 CET46004999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:54.936105013 CET9994600485.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:55.933859110 CET46006999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:55.939003944 CET9994600685.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:55.939095020 CET46006999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:55.939119101 CET46006999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:55.944061041 CET9994600685.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:55.944169044 CET46006999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:55.948997021 CET9994600685.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:57.739542007 CET9994600685.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:57.740147114 CET46006999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:57.745022058 CET9994600685.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:58.743180037 CET46008999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:58.748461008 CET9994600885.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:58.748620987 CET46008999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:58.748661041 CET46008999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:58.753525019 CET9994600885.239.34.134192.168.2.13
                      Jan 11, 2025 04:53:58.753601074 CET46008999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:53:58.758497000 CET9994600885.239.34.134192.168.2.13
                      Jan 11, 2025 04:54:00.523017883 CET9994600885.239.34.134192.168.2.13
                      Jan 11, 2025 04:54:00.523505926 CET46008999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:54:00.528546095 CET9994600885.239.34.134192.168.2.13
                      Jan 11, 2025 04:54:01.526032925 CET46010999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:54:01.531117916 CET9994601085.239.34.134192.168.2.13
                      Jan 11, 2025 04:54:01.531286955 CET46010999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:54:01.531287909 CET46010999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:54:01.536235094 CET9994601085.239.34.134192.168.2.13
                      Jan 11, 2025 04:54:01.536906004 CET46010999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:54:01.541748047 CET9994601085.239.34.134192.168.2.13
                      Jan 11, 2025 04:54:03.303550959 CET9994601085.239.34.134192.168.2.13
                      Jan 11, 2025 04:54:03.303836107 CET46010999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:54:03.308717012 CET9994601085.239.34.134192.168.2.13
                      Jan 11, 2025 04:54:04.306818008 CET46012999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:54:04.311806917 CET9994601285.239.34.134192.168.2.13
                      Jan 11, 2025 04:54:04.311975956 CET46012999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:54:04.311975956 CET46012999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:54:04.316864014 CET9994601285.239.34.134192.168.2.13
                      Jan 11, 2025 04:54:04.316992998 CET46012999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:54:04.321845055 CET9994601285.239.34.134192.168.2.13
                      Jan 11, 2025 04:54:06.065566063 CET9994601285.239.34.134192.168.2.13
                      Jan 11, 2025 04:54:06.066191912 CET46012999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:54:06.071135044 CET9994601285.239.34.134192.168.2.13
                      Jan 11, 2025 04:54:07.069605112 CET46014999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:54:07.074734926 CET9994601485.239.34.134192.168.2.13
                      Jan 11, 2025 04:54:07.074829102 CET46014999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:54:07.074873924 CET46014999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:54:07.079643011 CET9994601485.239.34.134192.168.2.13
                      Jan 11, 2025 04:54:07.079713106 CET46014999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:54:07.084592104 CET9994601485.239.34.134192.168.2.13
                      Jan 11, 2025 04:54:08.852899075 CET9994601485.239.34.134192.168.2.13
                      Jan 11, 2025 04:54:08.853287935 CET46014999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:54:08.858207941 CET9994601485.239.34.134192.168.2.13
                      Jan 11, 2025 04:54:09.855560064 CET46016999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:54:09.860596895 CET9994601685.239.34.134192.168.2.13
                      Jan 11, 2025 04:54:09.860692978 CET46016999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:54:09.860718012 CET46016999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:54:09.865583897 CET9994601685.239.34.134192.168.2.13
                      Jan 11, 2025 04:54:09.865643024 CET46016999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:54:09.870436907 CET9994601685.239.34.134192.168.2.13
                      Jan 11, 2025 04:54:11.634037018 CET9994601685.239.34.134192.168.2.13
                      Jan 11, 2025 04:54:11.634351015 CET46016999192.168.2.1385.239.34.134
                      Jan 11, 2025 04:54:11.639211893 CET9994601685.239.34.134192.168.2.13

                      System Behavior

                      Start time (UTC):03:52:06
                      Start date (UTC):11/01/2025
                      Path:/tmp/ppc.elf
                      Arguments:/tmp/ppc.elf
                      File size:5388968 bytes
                      MD5 hash:ae65271c943d3451b7f026d1fadccea6

                      Start time (UTC):03:52:06
                      Start date (UTC):11/01/2025
                      Path:/tmp/ppc.elf
                      Arguments:-
                      File size:5388968 bytes
                      MD5 hash:ae65271c943d3451b7f026d1fadccea6