Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
spc.elf

Overview

General Information

Sample name:spc.elf
Analysis ID:1589170
MD5:4f7f0dab1d24e937c23e6751ef51e43b
SHA1:fd8c1dcea98b5299c1a3a9cba82951f3503e5b92
SHA256:d5f3530e9847792931687d2d693fda27de9b6d32de5650d33f8aef6aa9c53af8
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai, Moobot
Score:100
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Detected Mirai
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Mirai
Yara detected Moobot
Connects to many ports of the same IP (likely port scanning)
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1589170
Start date and time:2025-01-11 14:45:02 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 8s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:spc.elf
Detection:MAL
Classification:mal100.troj.evad.linELF@0/0@74/0
  • VT rate limit hit for: update.byeux.com
Command:/tmp/spc.elf
PID:6265
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
done.
Standard Error:
  • system is lnxubuntu20
  • spc.elf (PID: 6265, Parent: 6189, MD5: 7dc1c0e23cd5e102bb12e5c29403410e) Arguments: /tmp/spc.elf
    • spc.elf New Fork (PID: 6267, Parent: 6265)
      • spc.elf New Fork (PID: 6269, Parent: 6267)
      • spc.elf New Fork (PID: 6270, Parent: 6267)
        • spc.elf New Fork (PID: 6273, Parent: 6270)
  • dash New Fork (PID: 6280, Parent: 4331)
  • rm (PID: 6280, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.lmaZ6NiHPq /tmp/tmp.Hdcvw0I1J0 /tmp/tmp.EKhH8LMmJS
  • dash New Fork (PID: 6281, Parent: 4331)
  • rm (PID: 6281, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.lmaZ6NiHPq /tmp/tmp.Hdcvw0I1J0 /tmp/tmp.EKhH8LMmJS
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
NameDescriptionAttributionBlogpost URLsLink
MooBotNo Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.moobot
SourceRuleDescriptionAuthorStrings
spc.elfJoeSecurity_MoobotYara detected MoobotJoe Security
    spc.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      spc.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0xc630:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc644:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc658:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc66c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc680:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc694:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc6a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc6bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc6d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc6e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc6f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc70c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc720:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc734:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc748:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc75c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc770:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc784:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc798:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc7ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc7c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      SourceRuleDescriptionAuthorStrings
      6265.1.00007fac90011000.00007fac9001f000.r-x.sdmpJoeSecurity_MoobotYara detected MoobotJoe Security
        6265.1.00007fac90011000.00007fac9001f000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          6265.1.00007fac90011000.00007fac9001f000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
          • 0xc630:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc644:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc658:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc66c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc680:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc694:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc6a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc6bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc6d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc6e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc6f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc70c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc720:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc734:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc748:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc75c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc770:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc784:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc798:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc7ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc7c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          Process Memory Space: spc.elf PID: 6265JoeSecurity_MoobotYara detected MoobotJoe Security
            Process Memory Space: spc.elf PID: 6265JoeSecurity_Mirai_8Yara detected MiraiJoe Security
              Click to see the 1 entries
              TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
              2025-01-11T14:46:20.765035+010020304911Malware Command and Control Activity Detected192.168.2.2360542107.189.4.20158431TCP
              2025-01-11T14:46:22.417059+010020304911Malware Command and Control Activity Detected192.168.2.2360544107.189.4.20158431TCP
              2025-01-11T14:46:24.181642+010020304911Malware Command and Control Activity Detected192.168.2.2360546107.189.4.20158431TCP
              2025-01-11T14:46:25.846831+010020304911Malware Command and Control Activity Detected192.168.2.2360548107.189.4.20158431TCP
              2025-01-11T14:46:27.645719+010020304911Malware Command and Control Activity Detected192.168.2.2360550107.189.4.20158431TCP
              2025-01-11T14:46:29.384069+010020304911Malware Command and Control Activity Detected192.168.2.2360552107.189.4.20158431TCP
              2025-01-11T14:46:31.370054+010020304911Malware Command and Control Activity Detected192.168.2.2360554107.189.4.20158431TCP
              2025-01-11T14:46:33.337002+010020304911Malware Command and Control Activity Detected192.168.2.2360556107.189.4.20158431TCP
              2025-01-11T14:46:35.006115+010020304911Malware Command and Control Activity Detected192.168.2.2360558107.189.4.20158431TCP
              2025-01-11T14:46:36.729349+010020304911Malware Command and Control Activity Detected192.168.2.2360560107.189.4.20158431TCP
              2025-01-11T14:46:38.380070+010020304911Malware Command and Control Activity Detected192.168.2.2360562107.189.4.20158431TCP
              2025-01-11T14:46:40.055199+010020304911Malware Command and Control Activity Detected192.168.2.2360564107.189.4.20158431TCP
              2025-01-11T14:46:41.742733+010020304911Malware Command and Control Activity Detected192.168.2.2360566107.189.4.20158431TCP
              2025-01-11T14:46:43.395293+010020304911Malware Command and Control Activity Detected192.168.2.2360568107.189.4.20158431TCP
              2025-01-11T14:46:45.055082+010020304911Malware Command and Control Activity Detected192.168.2.2360570107.189.4.20158431TCP
              2025-01-11T14:46:46.707600+010020304911Malware Command and Control Activity Detected192.168.2.2360572107.189.4.20158431TCP
              2025-01-11T14:46:48.378751+010020304911Malware Command and Control Activity Detected192.168.2.2360574107.189.4.20158431TCP
              2025-01-11T14:46:50.021590+010020304911Malware Command and Control Activity Detected192.168.2.2360576107.189.4.20158431TCP
              2025-01-11T14:46:51.681739+010020304911Malware Command and Control Activity Detected192.168.2.2360578107.189.4.20158431TCP
              2025-01-11T14:46:53.333534+010020304911Malware Command and Control Activity Detected192.168.2.2360580107.189.4.20158431TCP
              2025-01-11T14:46:55.022517+010020304911Malware Command and Control Activity Detected192.168.2.2360582107.189.4.20158431TCP
              2025-01-11T14:46:56.801030+010020304911Malware Command and Control Activity Detected192.168.2.2360584107.189.4.20158431TCP
              2025-01-11T14:46:58.461457+010020304911Malware Command and Control Activity Detected192.168.2.2360586107.189.4.20158431TCP
              2025-01-11T14:47:00.132101+010020304911Malware Command and Control Activity Detected192.168.2.2360588107.189.4.20158431TCP
              2025-01-11T14:47:01.930840+010020304911Malware Command and Control Activity Detected192.168.2.2360590107.189.4.20158431TCP
              2025-01-11T14:47:03.621060+010020304911Malware Command and Control Activity Detected192.168.2.2360592107.189.4.20158431TCP
              2025-01-11T14:47:05.289293+010020304911Malware Command and Control Activity Detected192.168.2.2360594107.189.4.20158431TCP
              2025-01-11T14:47:06.946604+010020304911Malware Command and Control Activity Detected192.168.2.2360596107.189.4.20158431TCP
              2025-01-11T14:47:08.599470+010020304911Malware Command and Control Activity Detected192.168.2.2360598107.189.4.20158431TCP
              2025-01-11T14:47:10.281030+010020304911Malware Command and Control Activity Detected192.168.2.2360600107.189.4.20158431TCP
              2025-01-11T14:47:11.947997+010020304911Malware Command and Control Activity Detected192.168.2.2360602107.189.4.20158431TCP
              2025-01-11T14:47:13.662891+010020304911Malware Command and Control Activity Detected192.168.2.2360604107.189.4.20158431TCP
              2025-01-11T14:47:15.303195+010020304911Malware Command and Control Activity Detected192.168.2.2360606107.189.4.20158431TCP
              2025-01-11T14:47:17.106759+010020304911Malware Command and Control Activity Detected192.168.2.2360608107.189.4.20158431TCP
              2025-01-11T14:47:18.756051+010020304911Malware Command and Control Activity Detected192.168.2.2360610107.189.4.20158431TCP
              2025-01-11T14:47:21.047177+010020304911Malware Command and Control Activity Detected192.168.2.2360612107.189.4.20158431TCP
              2025-01-11T14:47:22.712873+010020304911Malware Command and Control Activity Detected192.168.2.2360614107.189.4.20158431TCP
              2025-01-11T14:47:24.383104+010020304911Malware Command and Control Activity Detected192.168.2.2360616107.189.4.20158431TCP
              2025-01-11T14:47:26.040850+010020304911Malware Command and Control Activity Detected192.168.2.2360618107.189.4.20158431TCP
              2025-01-11T14:47:27.708947+010020304911Malware Command and Control Activity Detected192.168.2.2360620107.189.4.20158431TCP
              2025-01-11T14:47:29.351143+010020304911Malware Command and Control Activity Detected192.168.2.2360622107.189.4.20158431TCP
              2025-01-11T14:47:30.990277+010020304911Malware Command and Control Activity Detected192.168.2.2360624107.189.4.20158431TCP
              2025-01-11T14:47:32.652578+010020304911Malware Command and Control Activity Detected192.168.2.2360626107.189.4.20158431TCP
              2025-01-11T14:47:34.421577+010020304911Malware Command and Control Activity Detected192.168.2.2360628107.189.4.20158431TCP
              2025-01-11T14:47:36.088768+010020304911Malware Command and Control Activity Detected192.168.2.2360630107.189.4.20158431TCP
              2025-01-11T14:47:37.744539+010020304911Malware Command and Control Activity Detected192.168.2.2360632107.189.4.20158431TCP
              2025-01-11T14:47:39.416170+010020304911Malware Command and Control Activity Detected192.168.2.2360634107.189.4.20158431TCP
              2025-01-11T14:47:41.071612+010020304911Malware Command and Control Activity Detected192.168.2.2360636107.189.4.20158431TCP
              2025-01-11T14:47:42.730002+010020304911Malware Command and Control Activity Detected192.168.2.2360638107.189.4.20158431TCP
              2025-01-11T14:47:44.380677+010020304911Malware Command and Control Activity Detected192.168.2.2360640107.189.4.20158431TCP
              2025-01-11T14:47:46.069385+010020304911Malware Command and Control Activity Detected192.168.2.2360642107.189.4.20158431TCP
              2025-01-11T14:47:47.708788+010020304911Malware Command and Control Activity Detected192.168.2.2360644107.189.4.20158431TCP
              2025-01-11T14:47:49.366319+010020304911Malware Command and Control Activity Detected192.168.2.2360646107.189.4.20158431TCP
              2025-01-11T14:47:51.039289+010020304911Malware Command and Control Activity Detected192.168.2.2360648107.189.4.20158431TCP
              2025-01-11T14:47:52.862700+010020304911Malware Command and Control Activity Detected192.168.2.2360650107.189.4.20158431TCP
              2025-01-11T14:47:54.538393+010020304911Malware Command and Control Activity Detected192.168.2.2360652107.189.4.20158431TCP
              2025-01-11T14:47:56.178640+010020304911Malware Command and Control Activity Detected192.168.2.2360654107.189.4.20158431TCP
              2025-01-11T14:47:57.836945+010020304911Malware Command and Control Activity Detected192.168.2.2360656107.189.4.20158431TCP
              2025-01-11T14:47:59.490788+010020304911Malware Command and Control Activity Detected192.168.2.2360658107.189.4.20158431TCP
              2025-01-11T14:48:01.162041+010020304911Malware Command and Control Activity Detected192.168.2.2360660107.189.4.20158431TCP
              2025-01-11T14:48:02.821186+010020304911Malware Command and Control Activity Detected192.168.2.2360662107.189.4.20158431TCP
              2025-01-11T14:48:04.480279+010020304911Malware Command and Control Activity Detected192.168.2.2360664107.189.4.20158431TCP
              2025-01-11T14:48:06.149851+010020304911Malware Command and Control Activity Detected192.168.2.2360666107.189.4.20158431TCP
              2025-01-11T14:48:07.821260+010020304911Malware Command and Control Activity Detected192.168.2.2360668107.189.4.20158431TCP
              2025-01-11T14:48:09.488156+010020304911Malware Command and Control Activity Detected192.168.2.2360670107.189.4.20158431TCP
              2025-01-11T14:48:11.150747+010020304911Malware Command and Control Activity Detected192.168.2.2360672107.189.4.20158431TCP
              2025-01-11T14:48:12.804547+010020304911Malware Command and Control Activity Detected192.168.2.2360674107.189.4.20158431TCP
              2025-01-11T14:48:14.463271+010020304911Malware Command and Control Activity Detected192.168.2.2360676107.189.4.20158431TCP
              2025-01-11T14:48:16.147552+010020304911Malware Command and Control Activity Detected192.168.2.2360678107.189.4.20158431TCP
              2025-01-11T14:48:17.808063+010020304911Malware Command and Control Activity Detected192.168.2.2360680107.189.4.20158431TCP
              2025-01-11T14:48:19.488896+010020304911Malware Command and Control Activity Detected192.168.2.2360682107.189.4.20158431TCP
              2025-01-11T14:48:21.132399+010020304911Malware Command and Control Activity Detected192.168.2.2360684107.189.4.20158431TCP
              2025-01-11T14:48:22.809478+010020304911Malware Command and Control Activity Detected192.168.2.2360686107.189.4.20158431TCP
              2025-01-11T14:48:24.488996+010020304911Malware Command and Control Activity Detected192.168.2.2360688107.189.4.20158431TCP

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: spc.elfAvira: detected
              Source: spc.elfVirustotal: Detection: 65%Perma Link
              Source: spc.elfReversingLabs: Detection: 65%

              Networking

              barindex
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60554 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60546 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60578 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60576 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60562 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60560 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60574 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60566 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60584 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60572 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60550 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60558 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60638 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60544 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60564 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60598 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60654 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60596 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60606 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60570 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60580 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60582 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60610 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60548 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60614 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60668 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60648 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60594 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60590 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60650 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60642 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60658 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60556 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60600 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60656 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60588 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60634 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60552 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60660 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60664 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60670 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60682 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60542 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60674 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60586 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60568 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60636 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60632 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60608 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60652 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60622 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60676 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60680 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60640 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60602 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60644 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60686 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60620 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60672 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60618 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60688 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60662 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60666 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60592 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60628 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60646 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60678 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60612 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60684 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60630 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60604 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60616 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60624 -> 107.189.4.201:58431
              Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:60626 -> 107.189.4.201:58431
              Source: global trafficTCP traffic: 107.189.4.201 ports 58431,1,3,4,5,8
              Source: global trafficTCP traffic: 192.168.2.23:60542 -> 107.189.4.201:58431
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
              Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
              Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
              Source: global trafficDNS traffic detected: DNS query: update.byeux.com
              Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39256
              Source: unknownNetwork traffic detected: HTTP traffic on port 39256 -> 443

              System Summary

              barindex
              Source: spc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: 6265.1.00007fac90011000.00007fac9001f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: Process Memory Space: spc.elf PID: 6265, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: ELF static info symbol of initial sample.symtab present: no
              Source: spc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: 6265.1.00007fac90011000.00007fac9001f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: Process Memory Space: spc.elf PID: 6265, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: classification engineClassification label: mal100.troj.evad.linELF@0/0@74/0
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/1582/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/3088/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/230/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/110/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/231/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/111/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/232/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/1579/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/112/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/233/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/1699/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/113/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/234/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/1335/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/1698/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/114/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/235/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/1334/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/1576/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/2302/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/115/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/236/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/116/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/237/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/117/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/118/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/910/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/6227/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/119/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/912/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/10/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/2307/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/11/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/918/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/12/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/13/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/14/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/15/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/16/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/17/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/18/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/1594/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/120/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/121/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/1349/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/1/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/122/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/243/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/123/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/2/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/124/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/3/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/4/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/125/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/126/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/1344/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/1465/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/1586/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/127/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/6/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/248/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/128/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/249/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/1463/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/800/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/9/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/801/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/20/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/21/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/1900/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/22/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/23/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/24/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/25/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/26/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/27/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/28/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/29/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/491/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/250/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/130/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/251/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/6250/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/252/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/132/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/253/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/254/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/255/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/256/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/1599/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/257/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/1477/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/379/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/258/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/1476/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/259/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/1475/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/6249/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/936/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/4745/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/30/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/2208/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/35/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/1809/cmdlineJump to behavior
              Source: /tmp/spc.elf (PID: 6269)File opened: /proc/1494/cmdlineJump to behavior
              Source: /usr/bin/dash (PID: 6280)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.lmaZ6NiHPq /tmp/tmp.Hdcvw0I1J0 /tmp/tmp.EKhH8LMmJSJump to behavior
              Source: /usr/bin/dash (PID: 6281)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.lmaZ6NiHPq /tmp/tmp.Hdcvw0I1J0 /tmp/tmp.EKhH8LMmJSJump to behavior

              Hooking and other Techniques for Hiding and Protection

              barindex
              Source: /tmp/spc.elf (PID: 6265)File: /tmp/spc.elfJump to behavior
              Source: /tmp/spc.elf (PID: 6265)Queries kernel information via 'uname': Jump to behavior
              Source: spc.elf, 6265.1.0000563a70f90000.0000563a71015000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sparc
              Source: spc.elf, 6265.1.0000563a70f90000.0000563a71015000.rw-.sdmpBinary or memory string: p:V!/etc/qemu-binfmt/sparc
              Source: spc.elf, 6265.1.00007ffc3f9a6000.00007ffc3f9c7000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-sparc/tmp/spc.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/spc.elf
              Source: spc.elf, 6265.1.00007ffc3f9a6000.00007ffc3f9c7000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sparc

              Stealing of Sensitive Information

              barindex
              Source: Yara matchFile source: spc.elf, type: SAMPLE
              Source: Yara matchFile source: 6265.1.00007fac90011000.00007fac9001f000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: spc.elf PID: 6265, type: MEMORYSTR
              Source: Yara matchFile source: spc.elf, type: SAMPLE
              Source: Yara matchFile source: 6265.1.00007fac90011000.00007fac9001f000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: spc.elf PID: 6265, type: MEMORYSTR

              Remote Access Functionality

              barindex
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
              Source: Yara matchFile source: spc.elf, type: SAMPLE
              Source: Yara matchFile source: 6265.1.00007fac90011000.00007fac9001f000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: spc.elf PID: 6265, type: MEMORYSTR
              Source: Yara matchFile source: spc.elf, type: SAMPLE
              Source: Yara matchFile source: 6265.1.00007fac90011000.00007fac9001f000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: spc.elf PID: 6265, type: MEMORYSTR
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
              File Deletion
              1
              OS Credential Dumping
              11
              Security Software Discovery
              Remote ServicesData from Local System1
              Encrypted Channel
              Exfiltration Over Other Network MediumAbuse Accessibility Features
              CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
              Non-Standard Port
              Exfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
              Non-Application Layer Protocol
              Automated ExfiltrationData Encrypted for Impact
              Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
              Application Layer Protocol
              Traffic DuplicationData Destruction
              No configs have been found
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Number of created Files
              • Is malicious
              • Internet
              behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1589170 Sample: spc.elf Startdate: 11/01/2025 Architecture: LINUX Score: 100 24 update.byeux.com 107.189.4.201, 58431, 60542, 60544 PONYNETUS United States 2->24 26 109.202.202.202, 80 INIT7CH Switzerland 2->26 28 2 other IPs or domains 2->28 30 Suricata IDS alerts for network traffic 2->30 32 Malicious sample detected (through community Yara rule) 2->32 34 Antivirus / Scanner detection for submitted sample 2->34 36 5 other signatures 2->36 9 spc.elf 2->9         started        12 dash rm 2->12         started        14 dash rm 2->14         started        signatures3 process4 signatures5 38 Sample deletes itself 9->38 16 spc.elf 9->16         started        process6 process7 18 spc.elf 16->18         started        20 spc.elf 16->20         started        process8 22 spc.elf 18->22         started       
              SourceDetectionScannerLabelLink
              spc.elf65%VirustotalBrowse
              spc.elf66%ReversingLabsLinux.Trojan.Mirai
              spc.elf100%AviraEXP/ELF.Mirai.Z.A
              No Antivirus matches
              No Antivirus matches
              No Antivirus matches
              NameIPActiveMaliciousAntivirus DetectionReputation
              update.byeux.com
              107.189.4.201
              truetrue
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                107.189.4.201
                update.byeux.comUnited States
                53667PONYNETUStrue
                34.249.145.219
                unknownUnited States
                16509AMAZON-02USfalse
                109.202.202.202
                unknownSwitzerland
                13030INIT7CHfalse
                91.189.91.42
                unknownUnited Kingdom
                41231CANONICAL-ASGBfalse
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                107.189.4.201sh4.elfGet hashmaliciousMirai, MoobotBrowse
                  mpsl.elfGet hashmaliciousMirai, MoobotBrowse
                    x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                      x86.elfGet hashmaliciousMirai, MoobotBrowse
                        JVL2bXW1ch.elfGet hashmaliciousMirai, MoobotBrowse
                          arm7.elfGet hashmaliciousMirai, MoobotBrowse
                            mips.elfGet hashmaliciousMirai, MoobotBrowse
                              34.249.145.219sh4.elfGet hashmaliciousMirai, MoobotBrowse
                                Space.mips.elfGet hashmaliciousUnknownBrowse
                                  boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                    la.bot.arm7.elfGet hashmaliciousMiraiBrowse
                                      mpsl.elfGet hashmaliciousMiraiBrowse
                                        la.bot.arm5.elfGet hashmaliciousMiraiBrowse
                                          main_arm.elfGet hashmaliciousMiraiBrowse
                                            main_m68k.elfGet hashmaliciousMiraiBrowse
                                              i586.elfGet hashmaliciousUnknownBrowse
                                                ppc.elfGet hashmaliciousUnknownBrowse
                                                  109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                                                  • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                                                  91.189.91.42sh4.elfGet hashmaliciousMirai, MoobotBrowse
                                                    spc.elfGet hashmaliciousMirai, MoobotBrowse
                                                      arm5.elfGet hashmaliciousUnknownBrowse
                                                        mpsl.elfGet hashmaliciousMirai, MoobotBrowse
                                                          ARMV6L.elfGet hashmaliciousUnknownBrowse
                                                            I586.elfGet hashmaliciousUnknownBrowse
                                                              POWERPC.elfGet hashmaliciousUnknownBrowse
                                                                SH4.elfGet hashmaliciousUnknownBrowse
                                                                  sss.elfGet hashmaliciousGafgytBrowse
                                                                    ARMV5L.elfGet hashmaliciousUnknownBrowse
                                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                      update.byeux.comsh4.elfGet hashmaliciousMirai, MoobotBrowse
                                                                      • 107.189.4.201
                                                                      mpsl.elfGet hashmaliciousMirai, MoobotBrowse
                                                                      • 107.189.4.201
                                                                      x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                                                                      • 107.189.4.201
                                                                      x86.elfGet hashmaliciousMirai, MoobotBrowse
                                                                      • 107.189.4.201
                                                                      JVL2bXW1ch.elfGet hashmaliciousMirai, MoobotBrowse
                                                                      • 107.189.4.201
                                                                      arm7.elfGet hashmaliciousMirai, MoobotBrowse
                                                                      • 107.189.4.201
                                                                      mips.elfGet hashmaliciousMirai, MoobotBrowse
                                                                      • 107.189.4.201
                                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                      CANONICAL-ASGBsh4.elfGet hashmaliciousMirai, MoobotBrowse
                                                                      • 91.189.91.42
                                                                      spc.elfGet hashmaliciousMirai, MoobotBrowse
                                                                      • 91.189.91.42
                                                                      arm5.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      mpsl.elfGet hashmaliciousMirai, MoobotBrowse
                                                                      • 91.189.91.42
                                                                      ARMV6L.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      I586.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      POWERPC.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      SH4.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      sst.elfGet hashmaliciousGafgytBrowse
                                                                      • 185.125.190.26
                                                                      sss.elfGet hashmaliciousGafgytBrowse
                                                                      • 91.189.91.42
                                                                      INIT7CHsh4.elfGet hashmaliciousMirai, MoobotBrowse
                                                                      • 109.202.202.202
                                                                      spc.elfGet hashmaliciousMirai, MoobotBrowse
                                                                      • 109.202.202.202
                                                                      arm5.elfGet hashmaliciousUnknownBrowse
                                                                      • 109.202.202.202
                                                                      mpsl.elfGet hashmaliciousMirai, MoobotBrowse
                                                                      • 109.202.202.202
                                                                      ARMV6L.elfGet hashmaliciousUnknownBrowse
                                                                      • 109.202.202.202
                                                                      I586.elfGet hashmaliciousUnknownBrowse
                                                                      • 109.202.202.202
                                                                      POWERPC.elfGet hashmaliciousUnknownBrowse
                                                                      • 109.202.202.202
                                                                      SH4.elfGet hashmaliciousUnknownBrowse
                                                                      • 109.202.202.202
                                                                      sss.elfGet hashmaliciousGafgytBrowse
                                                                      • 109.202.202.202
                                                                      ARMV5L.elfGet hashmaliciousUnknownBrowse
                                                                      • 109.202.202.202
                                                                      AMAZON-02USsh4.elfGet hashmaliciousMirai, MoobotBrowse
                                                                      • 34.249.145.219
                                                                      res.x86.elfGet hashmaliciousUnknownBrowse
                                                                      • 18.134.184.155
                                                                      Space.mips.elfGet hashmaliciousUnknownBrowse
                                                                      • 34.249.145.219
                                                                      QsBdpe1gK5.exeGet hashmaliciousFormBook, PureLog StealerBrowse
                                                                      • 54.67.42.145
                                                                      HN1GiQ5tF7.exeGet hashmaliciousFormBookBrowse
                                                                      • 13.248.169.48
                                                                      qbSIgCrCgw.exeGet hashmaliciousFormBookBrowse
                                                                      • 13.248.169.48
                                                                      8L6MBxaJ2m.exeGet hashmaliciousFormBookBrowse
                                                                      • 13.248.169.48
                                                                      6.elfGet hashmaliciousUnknownBrowse
                                                                      • 54.122.159.233
                                                                      SH4.elfGet hashmaliciousUnknownBrowse
                                                                      • 54.171.230.55
                                                                      3.elfGet hashmaliciousUnknownBrowse
                                                                      • 13.214.70.119
                                                                      PONYNETUSsh4.elfGet hashmaliciousMirai, MoobotBrowse
                                                                      • 107.189.4.201
                                                                      uShK30bvrV.exeGet hashmaliciousRemcosBrowse
                                                                      • 172.86.115.221
                                                                      miori.spc.elfGet hashmaliciousUnknownBrowse
                                                                      • 107.189.6.73
                                                                      cZO.exeGet hashmaliciousUnknownBrowse
                                                                      • 107.189.28.6
                                                                      file.exeGet hashmaliciousUnknownBrowse
                                                                      • 205.185.126.56
                                                                      file.exeGet hashmaliciousUnknownBrowse
                                                                      • 205.185.126.56
                                                                      file.exeGet hashmaliciousGhostRat, NitolBrowse
                                                                      • 198.98.57.188
                                                                      lx64.elfGet hashmaliciousUnknownBrowse
                                                                      • 205.185.126.56
                                                                      https://u48917305.ct.sendgrid.net/ls/click?upn=u001.ztQPJiWtq2gO8V-2Ftd7SxY9UCAq3VScTPSloeIw5UEMPd6e3nbPRvJ98moPTqmrdQ1eNbvwZHJ-2BEb4HrooVFNCTltmXW6SgRONKSmPzdFoWfDQT97cczFZ0vj7M2xBd2izDTi-2BL-2BoVqB8yVzV2GW7vOPvy3s9yVghrOS5vs-2BSnWyzJMkXQxVEReq4oLCDet7QAOvo_JkpSD-2Bg6VoLAQppUKMb-2BxDh4v4nbOeQFT31aoN-2FLkhvFCzY6wdlGM7RTNIi47OKR1tTaghG8tTKssArDNPSXAfX9wO6nsZ2FHn-2FunyaOti-2FaII-2FnbKYDXJOImW-2Bs9f4tYnWj8rqO7L0kp4KNRHBDo0iHoL8DEOGc8GMtzqzsIqERel6-2FxJyY4DBnsnUTOc2I4HCPKA6lxcCEXMtxEA1-2FnQ-3D-3DGet hashmaliciousHTMLPhisherBrowse
                                                                      • 198.251.89.144
                                                                      arm6.elfGet hashmaliciousMirai, MoobotBrowse
                                                                      • 209.141.47.117
                                                                      No context
                                                                      No context
                                                                      No created / dropped files found
                                                                      File type:ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, stripped
                                                                      Entropy (8bit):6.162474954251594
                                                                      TrID:
                                                                      • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                      File name:spc.elf
                                                                      File size:58'688 bytes
                                                                      MD5:4f7f0dab1d24e937c23e6751ef51e43b
                                                                      SHA1:fd8c1dcea98b5299c1a3a9cba82951f3503e5b92
                                                                      SHA256:d5f3530e9847792931687d2d693fda27de9b6d32de5650d33f8aef6aa9c53af8
                                                                      SHA512:8fb72d081d30981935974c89218df7959040def1339619059850f7c8e27fbeede7795b4f6738251bff97a9ca447560b6a6e08514bd444b443858c9b65bdaf058
                                                                      SSDEEP:1536:v6dIzQlmFrKq+uhTsufe7xqIQuEL75WtfbNPr+:y4TDOx1mVgNPr+
                                                                      TLSH:D1433C21BA761E27C0C1A47621FB4B25B6F147DE26E8C60A3DB20D9FAF705406553EF8
                                                                      File Content Preview:.ELF...........................4.........4. ...(.......................................................p..%P........dt.Q................................@..(....@.1.................#.....cp..`.....!..... ...@.....".........`......$ ... ...@...........`....

                                                                      ELF header

                                                                      Class:ELF32
                                                                      Data:2's complement, big endian
                                                                      Version:1 (current)
                                                                      Machine:Sparc
                                                                      Version Number:0x1
                                                                      Type:EXEC (Executable file)
                                                                      OS/ABI:UNIX - System V
                                                                      ABI Version:0
                                                                      Entry Point Address:0x101a4
                                                                      Flags:0x0
                                                                      ELF Header Size:52
                                                                      Program Header Offset:52
                                                                      Program Header Size:32
                                                                      Number of Program Headers:3
                                                                      Section Header Offset:58288
                                                                      Section Header Size:40
                                                                      Number of Section Headers:10
                                                                      Header String Table Index:9
                                                                      NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                      NULL0x00x00x00x00x0000
                                                                      .initPROGBITS0x100940x940x1c0x00x6AX004
                                                                      .textPROGBITS0x100b00xb00xc4880x00x6AX004
                                                                      .finiPROGBITS0x1c5380xc5380x140x00x6AX004
                                                                      .rodataPROGBITS0x1c5500xc5500x1aa80x00x2A008
                                                                      .ctorsPROGBITS0x2e0000xe0000x80x00x3WA004
                                                                      .dtorsPROGBITS0x2e0080xe0080x80x00x3WA004
                                                                      .dataPROGBITS0x2e0180xe0180x3580x00x3WA008
                                                                      .bssNOBITS0x2e3700xe3700x21e00x00x3WA008
                                                                      .shstrtabSTRTAB0x00xe3700x3e0x00x0001
                                                                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                      LOAD0x00x100000x100000xdff80xdff86.20610x5R E0x10000.init .text .fini .rodata
                                                                      LOAD0xe0000x2e0000x2e0000x3700x25502.63360x6RW 0x10000.ctors .dtors .data .bss
                                                                      GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                                      TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                                      2025-01-11T14:46:20.765035+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360542107.189.4.20158431TCP
                                                                      2025-01-11T14:46:22.417059+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360544107.189.4.20158431TCP
                                                                      2025-01-11T14:46:24.181642+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360546107.189.4.20158431TCP
                                                                      2025-01-11T14:46:25.846831+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360548107.189.4.20158431TCP
                                                                      2025-01-11T14:46:27.645719+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360550107.189.4.20158431TCP
                                                                      2025-01-11T14:46:29.384069+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360552107.189.4.20158431TCP
                                                                      2025-01-11T14:46:31.370054+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360554107.189.4.20158431TCP
                                                                      2025-01-11T14:46:33.337002+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360556107.189.4.20158431TCP
                                                                      2025-01-11T14:46:35.006115+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360558107.189.4.20158431TCP
                                                                      2025-01-11T14:46:36.729349+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360560107.189.4.20158431TCP
                                                                      2025-01-11T14:46:38.380070+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360562107.189.4.20158431TCP
                                                                      2025-01-11T14:46:40.055199+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360564107.189.4.20158431TCP
                                                                      2025-01-11T14:46:41.742733+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360566107.189.4.20158431TCP
                                                                      2025-01-11T14:46:43.395293+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360568107.189.4.20158431TCP
                                                                      2025-01-11T14:46:45.055082+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360570107.189.4.20158431TCP
                                                                      2025-01-11T14:46:46.707600+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360572107.189.4.20158431TCP
                                                                      2025-01-11T14:46:48.378751+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360574107.189.4.20158431TCP
                                                                      2025-01-11T14:46:50.021590+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360576107.189.4.20158431TCP
                                                                      2025-01-11T14:46:51.681739+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360578107.189.4.20158431TCP
                                                                      2025-01-11T14:46:53.333534+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360580107.189.4.20158431TCP
                                                                      2025-01-11T14:46:55.022517+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360582107.189.4.20158431TCP
                                                                      2025-01-11T14:46:56.801030+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360584107.189.4.20158431TCP
                                                                      2025-01-11T14:46:58.461457+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360586107.189.4.20158431TCP
                                                                      2025-01-11T14:47:00.132101+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360588107.189.4.20158431TCP
                                                                      2025-01-11T14:47:01.930840+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360590107.189.4.20158431TCP
                                                                      2025-01-11T14:47:03.621060+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360592107.189.4.20158431TCP
                                                                      2025-01-11T14:47:05.289293+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360594107.189.4.20158431TCP
                                                                      2025-01-11T14:47:06.946604+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360596107.189.4.20158431TCP
                                                                      2025-01-11T14:47:08.599470+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360598107.189.4.20158431TCP
                                                                      2025-01-11T14:47:10.281030+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360600107.189.4.20158431TCP
                                                                      2025-01-11T14:47:11.947997+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360602107.189.4.20158431TCP
                                                                      2025-01-11T14:47:13.662891+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360604107.189.4.20158431TCP
                                                                      2025-01-11T14:47:15.303195+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360606107.189.4.20158431TCP
                                                                      2025-01-11T14:47:17.106759+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360608107.189.4.20158431TCP
                                                                      2025-01-11T14:47:18.756051+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360610107.189.4.20158431TCP
                                                                      2025-01-11T14:47:21.047177+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360612107.189.4.20158431TCP
                                                                      2025-01-11T14:47:22.712873+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360614107.189.4.20158431TCP
                                                                      2025-01-11T14:47:24.383104+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360616107.189.4.20158431TCP
                                                                      2025-01-11T14:47:26.040850+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360618107.189.4.20158431TCP
                                                                      2025-01-11T14:47:27.708947+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360620107.189.4.20158431TCP
                                                                      2025-01-11T14:47:29.351143+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360622107.189.4.20158431TCP
                                                                      2025-01-11T14:47:30.990277+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360624107.189.4.20158431TCP
                                                                      2025-01-11T14:47:32.652578+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360626107.189.4.20158431TCP
                                                                      2025-01-11T14:47:34.421577+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360628107.189.4.20158431TCP
                                                                      2025-01-11T14:47:36.088768+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360630107.189.4.20158431TCP
                                                                      2025-01-11T14:47:37.744539+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360632107.189.4.20158431TCP
                                                                      2025-01-11T14:47:39.416170+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360634107.189.4.20158431TCP
                                                                      2025-01-11T14:47:41.071612+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360636107.189.4.20158431TCP
                                                                      2025-01-11T14:47:42.730002+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360638107.189.4.20158431TCP
                                                                      2025-01-11T14:47:44.380677+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360640107.189.4.20158431TCP
                                                                      2025-01-11T14:47:46.069385+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360642107.189.4.20158431TCP
                                                                      2025-01-11T14:47:47.708788+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360644107.189.4.20158431TCP
                                                                      2025-01-11T14:47:49.366319+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360646107.189.4.20158431TCP
                                                                      2025-01-11T14:47:51.039289+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360648107.189.4.20158431TCP
                                                                      2025-01-11T14:47:52.862700+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360650107.189.4.20158431TCP
                                                                      2025-01-11T14:47:54.538393+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360652107.189.4.20158431TCP
                                                                      2025-01-11T14:47:56.178640+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360654107.189.4.20158431TCP
                                                                      2025-01-11T14:47:57.836945+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360656107.189.4.20158431TCP
                                                                      2025-01-11T14:47:59.490788+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360658107.189.4.20158431TCP
                                                                      2025-01-11T14:48:01.162041+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360660107.189.4.20158431TCP
                                                                      2025-01-11T14:48:02.821186+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360662107.189.4.20158431TCP
                                                                      2025-01-11T14:48:04.480279+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360664107.189.4.20158431TCP
                                                                      2025-01-11T14:48:06.149851+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360666107.189.4.20158431TCP
                                                                      2025-01-11T14:48:07.821260+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360668107.189.4.20158431TCP
                                                                      2025-01-11T14:48:09.488156+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360670107.189.4.20158431TCP
                                                                      2025-01-11T14:48:11.150747+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360672107.189.4.20158431TCP
                                                                      2025-01-11T14:48:12.804547+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360674107.189.4.20158431TCP
                                                                      2025-01-11T14:48:14.463271+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360676107.189.4.20158431TCP
                                                                      2025-01-11T14:48:16.147552+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360678107.189.4.20158431TCP
                                                                      2025-01-11T14:48:17.808063+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360680107.189.4.20158431TCP
                                                                      2025-01-11T14:48:19.488896+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360682107.189.4.20158431TCP
                                                                      2025-01-11T14:48:21.132399+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360684107.189.4.20158431TCP
                                                                      2025-01-11T14:48:22.809478+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360686107.189.4.20158431TCP
                                                                      2025-01-11T14:48:24.488996+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2360688107.189.4.20158431TCP
                                                                      TimestampSource PortDest PortSource IPDest IP
                                                                      Jan 11, 2025 14:46:19.871129036 CET43928443192.168.2.2391.189.91.42
                                                                      Jan 11, 2025 14:46:20.754048109 CET6054258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:20.758975029 CET5843160542107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:20.759198904 CET6054258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:20.765034914 CET6054258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:20.769849062 CET5843160542107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:22.396585941 CET5843160542107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:22.396871090 CET6054258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:22.401803970 CET5843160542107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:22.408826113 CET6054458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:22.413790941 CET5843160544107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:22.413863897 CET6054458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:22.417058945 CET6054458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:22.421905994 CET5843160544107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:24.055588961 CET5843160544107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:24.055879116 CET6054458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:24.060878992 CET5843160544107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:24.171421051 CET6054658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:24.176358938 CET5843160546107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:24.176431894 CET6054658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:24.181642056 CET6054658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:24.186491966 CET5843160546107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:25.818298101 CET5843160546107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:25.818423986 CET6054658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:25.823367119 CET5843160546107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:25.835344076 CET6054858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:25.842793941 CET5843160548107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:25.842924118 CET6054858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:25.846831083 CET6054858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:25.852937937 CET5843160548107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:27.476272106 CET5843160548107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:27.476377964 CET6054858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:27.481400967 CET5843160548107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:27.636008978 CET6055058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:27.640868902 CET5843160550107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:27.640925884 CET6055058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:27.645719051 CET6055058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:27.650572062 CET5843160550107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:29.272119045 CET5843160550107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:29.272217035 CET6055058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:29.277108908 CET5843160550107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:29.378113985 CET6055258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:29.382972956 CET5843160552107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:29.383030891 CET6055258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:29.384068966 CET6055258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:29.388894081 CET5843160552107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:30.780483961 CET4433925634.249.145.219192.168.2.23
                                                                      Jan 11, 2025 14:46:30.784094095 CET39256443192.168.2.2334.249.145.219
                                                                      Jan 11, 2025 14:46:30.789134026 CET4433925634.249.145.219192.168.2.23
                                                                      Jan 11, 2025 14:46:31.057384014 CET5843160552107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:31.057499886 CET6055258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:31.057499886 CET6055258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:31.062438011 CET5843160552107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:31.364274979 CET6055458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:31.369179010 CET5843160554107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:31.369235992 CET6055458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:31.370054007 CET6055458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:31.374866009 CET5843160554107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:33.041692019 CET5843160554107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:33.044116020 CET6055458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:33.049103022 CET5843160554107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:33.330926895 CET6055658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:33.335866928 CET5843160556107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:33.335938931 CET6055658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:33.337002039 CET6055658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:33.341902018 CET5843160556107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:34.717084885 CET4251680192.168.2.23109.202.202.202
                                                                      Jan 11, 2025 14:46:34.976592064 CET5843160556107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:34.976841927 CET6055658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:34.981874943 CET5843160556107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:34.998086929 CET6055858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:35.002984047 CET5843160558107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:35.003043890 CET6055858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:35.006114960 CET6055858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:35.011020899 CET5843160558107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:36.714483976 CET5843160558107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:36.714781046 CET6055858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:36.719815969 CET5843160558107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:36.722973108 CET6056058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:36.728696108 CET5843160560107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:36.728753090 CET6056058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:36.729348898 CET6056058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:36.734247923 CET5843160560107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:38.365942955 CET5843160560107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:38.366261005 CET6056058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:38.371192932 CET5843160560107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:38.374490023 CET6056258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:38.379358053 CET5843160562107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:38.379462957 CET6056258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:38.380069971 CET6056258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:38.384919882 CET5843160562107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:40.040726900 CET5843160562107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:40.040920973 CET6056258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:40.045902967 CET5843160562107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:40.049556017 CET6056458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:40.054531097 CET5843160564107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:40.054604053 CET6056458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:40.055198908 CET6056458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:40.060121059 CET5843160564107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:40.860251904 CET43928443192.168.2.2391.189.91.42
                                                                      Jan 11, 2025 14:46:41.728509903 CET5843160564107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:41.728704929 CET6056458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:41.733634949 CET5843160564107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:41.737128973 CET6056658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:41.742054939 CET5843160566107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:41.742136002 CET6056658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:41.742733002 CET6056658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:41.748184919 CET5843160566107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:43.381273985 CET5843160566107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:43.381558895 CET6056658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:43.386420965 CET5843160566107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:43.389753103 CET6056858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:43.394578934 CET5843160568107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:43.394649029 CET6056858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:43.395292997 CET6056858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:43.400187969 CET5843160568107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:45.040872097 CET5843160568107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:45.041074038 CET6056858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:45.045974970 CET5843160568107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:45.049357891 CET6057058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:45.054192066 CET5843160570107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:45.054248095 CET6057058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:45.055082083 CET6057058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:45.059849977 CET5843160570107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:46.694025993 CET5843160570107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:46.694230080 CET6057058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:46.699137926 CET5843160570107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:46.702258110 CET6057258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:46.707084894 CET5843160572107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:46.707129955 CET6057258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:46.707600117 CET6057258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:46.712333918 CET5843160572107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:48.365405083 CET5843160572107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:48.365556002 CET6057258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:48.370444059 CET5843160572107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:48.373363972 CET6057458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:48.378118038 CET5843160574107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:48.378200054 CET6057458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:48.378751040 CET6057458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:48.383501053 CET5843160574107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:50.005750895 CET5843160574107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:50.005975962 CET6057458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:50.010904074 CET5843160574107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:50.015610933 CET6057658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:50.020549059 CET5843160576107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:50.020629883 CET6057658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:50.021589994 CET6057658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:50.026417017 CET5843160576107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:51.667279959 CET5843160576107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:51.667530060 CET6057658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:51.672513962 CET5843160576107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:51.676069975 CET6057858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:51.680974960 CET5843160578107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:51.681094885 CET6057858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:51.681739092 CET6057858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:51.686578989 CET5843160578107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:53.319295883 CET5843160578107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:53.319467068 CET6057858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:53.324385881 CET5843160578107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:53.327883959 CET6058058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:53.332855940 CET5843160580107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:53.332963943 CET6058058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:53.333534002 CET6058058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:53.338433981 CET5843160580107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:55.008641958 CET5843160580107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:55.008822918 CET6058058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:55.013807058 CET5843160580107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:55.016962051 CET6058258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:55.021802902 CET5843160582107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:55.021861076 CET6058258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:55.022516966 CET6058258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:55.027345896 CET5843160582107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:56.666222095 CET5843160582107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:56.666428089 CET6058258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:56.671427965 CET5843160582107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:56.795051098 CET6058458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:56.799968958 CET5843160584107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:56.800029039 CET6058458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:56.801029921 CET6058458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:56.805881977 CET5843160584107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:58.446506023 CET5843160584107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:58.446666956 CET6058458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:58.451695919 CET5843160584107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:58.455473900 CET6058658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:58.460372925 CET5843160586107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:46:58.460428953 CET6058658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:58.461457014 CET6058658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:46:58.466319084 CET5843160586107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:00.116518021 CET5843160586107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:00.116767883 CET6058658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:00.121798038 CET5843160586107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:00.126106024 CET6058858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:00.131061077 CET5843160588107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:00.131128073 CET6058858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:00.132101059 CET6058858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:00.137048960 CET5843160588107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:01.772119999 CET5843160588107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:01.772309065 CET6058858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:01.777234077 CET5843160588107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:01.925071955 CET6059058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:01.930052996 CET5843160590107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:01.930123091 CET6059058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:01.930840015 CET6059058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:01.935676098 CET5843160590107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:03.605870008 CET5843160590107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:03.606043100 CET6059058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:03.611032009 CET5843160590107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:03.615189075 CET6059258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:03.620062113 CET5843160592107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:03.620115995 CET6059258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:03.621059895 CET6059258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:03.625914097 CET5843160592107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:05.273773909 CET5843160592107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:05.273974895 CET6059258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:05.278842926 CET5843160592107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:05.283164024 CET6059458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:05.288105965 CET5843160594107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:05.288189888 CET6059458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:05.289293051 CET6059458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:05.294121981 CET5843160594107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:06.931993961 CET5843160594107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:06.932173967 CET6059458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:06.937098980 CET5843160594107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:06.940639019 CET6059658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:06.945579052 CET5843160596107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:06.945640087 CET6059658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:06.946604013 CET6059658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:06.954011917 CET5843160596107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:08.584306955 CET5843160596107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:08.584516048 CET6059658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:08.589451075 CET5843160596107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:08.593533993 CET6059858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:08.598474979 CET5843160598107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:08.598550081 CET6059858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:08.599469900 CET6059858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:08.604362965 CET5843160598107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:10.262998104 CET5843160598107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:10.263169050 CET6059858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:10.269856930 CET5843160598107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:10.273828983 CET6060058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:10.280008078 CET5843160600107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:10.280061960 CET6060058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:10.281029940 CET6060058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:10.285842896 CET5843160600107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:11.933067083 CET5843160600107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:11.933233023 CET6060058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:11.938117027 CET5843160600107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:11.941993952 CET6060258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:11.946885109 CET5843160602107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:11.946947098 CET6060258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:11.947997093 CET6060258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:11.952877998 CET5843160602107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:13.647511959 CET5843160602107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:13.647821903 CET6060258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:13.652863979 CET5843160602107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:13.656737089 CET6060458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:13.661751986 CET5843160604107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:13.661808968 CET6060458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:13.662890911 CET6060458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:13.667768002 CET5843160604107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:15.287689924 CET5843160604107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:15.287888050 CET6060458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:15.292821884 CET5843160604107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:15.296586037 CET6060658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:15.302207947 CET5843160606107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:15.302275896 CET6060658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:15.303195000 CET6060658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:15.308038950 CET5843160606107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:16.948725939 CET5843160606107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:16.948890924 CET6060658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:16.953792095 CET5843160606107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:17.100740910 CET6060858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:17.105598927 CET5843160608107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:17.105668068 CET6060858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:17.106759071 CET6060858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:17.111576080 CET5843160608107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:18.740938902 CET5843160608107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:18.741228104 CET6060858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:18.746236086 CET5843160608107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:18.750086069 CET6061058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:18.754941940 CET5843160610107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:18.755013943 CET6061058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:18.756051064 CET6061058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:18.760879993 CET5843160610107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:21.032238960 CET5843160610107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:21.032332897 CET5843160610107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:21.032402992 CET6061058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:21.032450914 CET6061058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:21.032475948 CET5843160610107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:21.032541990 CET6061058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:21.037645102 CET5843160610107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:21.041321993 CET6061258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:21.046123981 CET5843160612107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:21.046179056 CET6061258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:21.047177076 CET6061258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:21.051950932 CET5843160612107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:21.814522028 CET43928443192.168.2.2391.189.91.42
                                                                      Jan 11, 2025 14:47:22.697746992 CET5843160612107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:22.697915077 CET6061258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:22.702837944 CET5843160612107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:22.706866980 CET6061458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:22.711735010 CET5843160614107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:22.711815119 CET6061458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:22.712872982 CET6061458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:22.717762947 CET5843160614107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:24.367686987 CET5843160614107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:24.367939949 CET6061458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:24.372813940 CET5843160614107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:24.377119064 CET6061658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:24.382008076 CET5843160616107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:24.382121086 CET6061658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:24.383104086 CET6061658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:24.387924910 CET5843160616107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:26.026506901 CET5843160616107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:26.026802063 CET6061658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:26.031750917 CET5843160616107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:26.035128117 CET6061858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:26.040046930 CET5843160618107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:26.040103912 CET6061858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:26.040849924 CET6061858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:26.045708895 CET5843160618107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:27.693886042 CET5843160618107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:27.694060087 CET6061858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:27.698951006 CET5843160618107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:27.703020096 CET6062058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:27.707942009 CET5843160620107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:27.708019972 CET6062058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:27.708946943 CET6062058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:27.713881016 CET5843160620107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:29.335171938 CET5843160620107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:29.335375071 CET6062058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:29.340358019 CET5843160620107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:29.345124006 CET6062258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:29.350075960 CET5843160622107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:29.350135088 CET6062258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:29.351142883 CET6062258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:29.355957985 CET5843160622107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:30.975722075 CET5843160622107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:30.976069927 CET6062258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:30.981086969 CET5843160622107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:30.984601974 CET6062458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:30.989588022 CET5843160624107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:30.989644051 CET6062458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:30.990277052 CET6062458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:30.995270967 CET5843160624107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:32.637253046 CET5843160624107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:32.637432098 CET6062458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:32.642369986 CET5843160624107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:32.646737099 CET6062658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:32.651635885 CET5843160626107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:32.651700974 CET6062658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:32.652578115 CET6062658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:32.657452106 CET5843160626107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:34.406706095 CET5843160626107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:34.406985044 CET6062658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:34.411936998 CET5843160626107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:34.415644884 CET6062858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:34.420547009 CET5843160628107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:34.420603037 CET6062858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:34.421576977 CET6062858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:34.426403999 CET5843160628107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:36.073985100 CET5843160628107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:36.074160099 CET6062858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:36.079092979 CET5843160628107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:36.082799911 CET6063058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:36.087660074 CET5843160630107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:36.087718964 CET6063058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:36.088768005 CET6063058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:36.093671083 CET5843160630107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:37.729747057 CET5843160630107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:37.730004072 CET6063058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:37.734759092 CET5843160630107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:37.738590002 CET6063258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:37.743443966 CET5843160632107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:37.743526936 CET6063258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:37.744539022 CET6063258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:37.749344110 CET5843160632107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:39.400984049 CET5843160632107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:39.401127100 CET6063258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:39.406052113 CET5843160632107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:39.410196066 CET6063458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:39.415087938 CET5843160634107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:39.415144920 CET6063458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:39.416169882 CET6063458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:39.420939922 CET5843160634107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:41.057213068 CET5843160634107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:41.057373047 CET6063458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:41.062305927 CET5843160634107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:41.065896988 CET6063658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:41.070795059 CET5843160636107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:41.070854902 CET6063658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:41.071611881 CET6063658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:41.076458931 CET5843160636107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:42.713618994 CET5843160636107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:42.713759899 CET6063658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:42.720807076 CET5843160636107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:42.724312067 CET6063858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:42.729177952 CET5843160638107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:42.729238033 CET6063858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:42.730001926 CET6063858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:42.734915972 CET5843160638107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:44.366625071 CET5843160638107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:44.366775990 CET6063858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:44.371711016 CET5843160638107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:44.374979019 CET6064058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:44.379818916 CET5843160640107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:44.379879951 CET6064058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:44.380676985 CET6064058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:44.385504961 CET5843160640107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:46.055170059 CET5843160640107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:46.055473089 CET6064058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:46.060461044 CET5843160640107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:46.063723087 CET6064258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:46.068618059 CET5843160642107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:46.068674088 CET6064258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:46.069385052 CET6064258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:46.074235916 CET5843160642107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:47.694375992 CET5843160642107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:47.694547892 CET6064258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:47.699496984 CET5843160642107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:47.703175068 CET6064458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:47.708148003 CET5843160644107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:47.708211899 CET6064458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:47.708787918 CET6064458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:47.713588953 CET5843160644107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:49.351531982 CET5843160644107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:49.351703882 CET6064458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:49.356631994 CET5843160644107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:49.360688925 CET6064658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:49.365588903 CET5843160646107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:49.365657091 CET6064658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:49.366318941 CET6064658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:49.371185064 CET5843160646107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:51.024877071 CET5843160646107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:51.025068045 CET6064658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:51.030016899 CET5843160646107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:51.033523083 CET6064858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:51.038485050 CET5843160648107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:51.038548946 CET6064858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:51.039288998 CET6064858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:51.044214010 CET5843160648107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:52.694683075 CET5843160648107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:52.694901943 CET6064858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:52.699840069 CET5843160648107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:52.856939077 CET6065058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:52.861850977 CET5843160650107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:52.861951113 CET6065058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:52.862699986 CET6065058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:52.867638111 CET5843160650107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:54.524533987 CET5843160650107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:54.524789095 CET6065058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:54.529647112 CET5843160650107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:54.532819986 CET6065258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:54.537702084 CET5843160652107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:54.537775040 CET6065258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:54.538393021 CET6065258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:54.543275118 CET5843160652107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:56.164845943 CET5843160652107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:56.165024996 CET6065258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:56.169955969 CET5843160652107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:56.173139095 CET6065458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:56.177970886 CET5843160654107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:56.178039074 CET6065458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:56.178639889 CET6065458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:56.183459997 CET5843160654107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:57.823438883 CET5843160654107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:57.823685884 CET6065458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:57.828583956 CET5843160654107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:57.831432104 CET6065658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:57.836272001 CET5843160656107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:57.836323977 CET6065658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:57.836945057 CET6065658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:57.841767073 CET5843160656107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:59.476666927 CET5843160656107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:59.476866007 CET6065658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:59.481838942 CET5843160656107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:59.485126972 CET6065858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:59.490087986 CET5843160658107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:47:59.490149975 CET6065858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:59.490787983 CET6065858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:47:59.495615959 CET5843160658107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:01.148066998 CET5843160658107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:01.148335934 CET6065858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:01.153261900 CET5843160658107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:01.156555891 CET6066058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:01.161410093 CET5843160660107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:01.161461115 CET6066058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:01.162040949 CET6066058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:01.166886091 CET5843160660107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:02.807383060 CET5843160660107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:02.807523012 CET6066058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:02.812388897 CET5843160660107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:02.815711975 CET6066258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:02.820563078 CET5843160662107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:02.820616961 CET6066258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:02.821186066 CET6066258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:02.826903105 CET5843160662107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:04.462202072 CET5843160662107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:04.462619066 CET6066258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:04.469257116 CET5843160662107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:04.472918987 CET6066458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:04.479145050 CET5843160664107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:04.479208946 CET6066458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:04.480278969 CET6066458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:04.485136986 CET5843160664107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:06.136445045 CET5843160664107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:06.136641026 CET6066458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:06.141654968 CET5843160664107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:06.144153118 CET6066658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:06.149219036 CET5843160666107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:06.149267912 CET6066658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:06.149851084 CET6066658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:06.154675961 CET5843160666107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:07.807385921 CET5843160666107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:07.807554007 CET6066658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:07.812405109 CET5843160666107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:07.815362930 CET6066858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:07.820611954 CET5843160668107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:07.820662975 CET6066858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:07.821259975 CET6066858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:07.826065063 CET5843160668107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:09.473999977 CET5843160668107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:09.474134922 CET6066858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:09.479110956 CET5843160668107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:09.482373953 CET6067058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:09.487282991 CET5843160670107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:09.487344980 CET6067058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:09.488156080 CET6067058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:09.493012905 CET5843160670107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:11.134708881 CET5843160670107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:11.134963036 CET6067058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:11.139867067 CET5843160670107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:11.144859076 CET6067258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:11.149784088 CET5843160672107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:11.149844885 CET6067258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:11.150747061 CET6067258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:11.155584097 CET5843160672107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:12.790821075 CET5843160672107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:12.790941000 CET6067258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:12.795917034 CET5843160672107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:12.799091101 CET6067458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:12.803983927 CET5843160674107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:12.804039955 CET6067458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:12.804547071 CET6067458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:12.809443951 CET5843160674107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:14.449305058 CET5843160674107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:14.449445009 CET6067458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:14.454374075 CET5843160674107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:14.457659960 CET6067658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:14.462608099 CET5843160676107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:14.462718964 CET6067658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:14.463270903 CET6067658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:14.468152046 CET5843160676107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:16.133724928 CET5843160676107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:16.133873940 CET6067658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:16.138818026 CET5843160676107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:16.142005920 CET6067858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:16.146912098 CET5843160678107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:16.147010088 CET6067858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:16.147552013 CET6067858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:16.152441025 CET5843160678107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:17.793811083 CET5843160678107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:17.793970108 CET6067858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:17.798959970 CET5843160678107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:17.802534103 CET6068058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:17.807424068 CET5843160680107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:17.807492971 CET6068058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:17.808063030 CET6068058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:17.812912941 CET5843160680107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:19.473944902 CET5843160680107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:19.474271059 CET6068058431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:19.479223967 CET5843160680107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:19.482903004 CET6068258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:19.487839937 CET5843160682107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:19.487915039 CET6068258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:19.488895893 CET6068258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:19.493731022 CET5843160682107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:21.117641926 CET5843160682107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:21.117780924 CET6068258431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:21.122744083 CET5843160682107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:21.126518965 CET6068458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:21.131418943 CET5843160684107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:21.131485939 CET6068458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:21.132399082 CET6068458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:21.137288094 CET5843160684107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:22.795846939 CET5843160684107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:22.796041965 CET6068458431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:22.800890923 CET5843160684107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:22.803955078 CET6068658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:22.808780909 CET5843160686107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:22.808836937 CET6068658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:22.809478045 CET6068658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:22.814270020 CET5843160686107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:24.474224091 CET5843160686107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:24.474499941 CET6068658431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:24.479343891 CET5843160686107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:24.483320951 CET6068858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:24.488195896 CET5843160688107.189.4.201192.168.2.23
                                                                      Jan 11, 2025 14:48:24.488245010 CET6068858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:24.488996029 CET6068858431192.168.2.23107.189.4.201
                                                                      Jan 11, 2025 14:48:24.493720055 CET5843160688107.189.4.201192.168.2.23
                                                                      TimestampSource PortDest PortSource IPDest IP
                                                                      Jan 11, 2025 14:46:20.621429920 CET4389753192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:46:20.750608921 CET53438978.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:46:22.400115967 CET3754053192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:46:22.407104015 CET53375408.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:46:24.065073013 CET5419453192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:46:24.167109966 CET53541948.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:46:25.824316025 CET4326053192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:46:25.831480980 CET53432608.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:46:27.478777885 CET3409353192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:46:27.635440111 CET53340938.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:46:29.273312092 CET5652053192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:46:29.377567053 CET53565208.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:46:31.209656954 CET3468253192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:46:31.363796949 CET53346828.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:46:33.168548107 CET4930453192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:46:33.330193996 CET53493048.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:46:34.990176916 CET4109153192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:46:34.997399092 CET53410918.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:46:36.715537071 CET4561853192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:46:36.722652912 CET53456188.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:46:38.367058992 CET5072553192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:46:38.374140024 CET53507258.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:46:40.041610003 CET4402353192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:46:40.049201012 CET53440238.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:46:41.729561090 CET3457353192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:46:41.736674070 CET53345738.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:46:43.382596016 CET3796953192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:46:43.389409065 CET53379698.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:46:45.041909933 CET3339153192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:46:45.049041033 CET53333918.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:46:46.694963932 CET3509753192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:46:46.701977015 CET53350978.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:46:48.366228104 CET4859653192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:46:48.373009920 CET53485968.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:46:50.007255077 CET5710853192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:46:50.015105009 CET53571088.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:46:51.668620110 CET5688953192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:46:51.675709963 CET53568898.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:46:53.320355892 CET5438153192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:46:53.327518940 CET53543818.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:46:55.009826899 CET6076653192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:46:55.016617060 CET53607668.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:46:56.667397022 CET5090553192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:46:56.794346094 CET53509058.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:46:58.448060036 CET3599753192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:46:58.454880953 CET53359978.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:00.118093967 CET5014353192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:00.125576019 CET53501438.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:01.773888111 CET3687353192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:01.924236059 CET53368738.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:03.607623100 CET5434653192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:03.614653111 CET53543468.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:05.275428057 CET3790253192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:05.282536030 CET53379028.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:06.933424950 CET4885253192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:06.940171957 CET53488528.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:08.585803032 CET4385953192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:08.593051910 CET53438598.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:10.264503002 CET5149553192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:10.273339033 CET53514958.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:11.934591055 CET4898653192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:11.941468954 CET53489868.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:13.649164915 CET4444553192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:13.656109095 CET53444458.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:15.289163113 CET3449653192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:15.296089888 CET53344968.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:16.950166941 CET4829953192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:17.099857092 CET53482998.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:18.742273092 CET3403253192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:18.749217987 CET53340328.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:21.033874035 CET3538653192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:21.040766001 CET53353868.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:22.699379921 CET5844853192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:22.706322908 CET53584488.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:24.369143009 CET3490553192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:24.376621962 CET53349058.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:26.027786016 CET3415053192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:26.034706116 CET53341508.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:27.695487022 CET5685153192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:27.702472925 CET53568518.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:29.336658955 CET3696353192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:29.344540119 CET53369638.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:30.977018118 CET3838753192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:30.984201908 CET53383878.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:32.638648987 CET3790653192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:32.646220922 CET53379068.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:34.408343077 CET5043053192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:34.415095091 CET53504308.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:36.075712919 CET6072453192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:36.082252979 CET53607248.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:37.731483936 CET3830453192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:37.738065004 CET53383048.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:39.402626991 CET4112953192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:39.409677982 CET53411298.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:41.058438063 CET4509553192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:41.065495014 CET53450958.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:42.714827061 CET3998153192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:42.723799944 CET53399818.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:44.367813110 CET5433553192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:44.374564886 CET53543358.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:46.056243896 CET4736753192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:46.063301086 CET53473678.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:47.695328951 CET3531553192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:47.702836037 CET53353158.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:49.352622986 CET5602553192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:49.360256910 CET53560258.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:51.026021004 CET3343553192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:51.033071041 CET53334358.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:52.695920944 CET4005153192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:52.856327057 CET53400518.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:54.525527954 CET5419753192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:54.532468081 CET53541978.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:56.165873051 CET4941953192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:56.172739983 CET53494198.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:57.824357986 CET5511953192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:57.831084013 CET53551198.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:47:59.477729082 CET5673953192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:47:59.484755039 CET53567398.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:48:01.149005890 CET4194953192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:48:01.156239033 CET53419498.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:48:02.808240891 CET4289253192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:48:02.815401077 CET53428928.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:48:04.464073896 CET5447553192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:48:04.472337008 CET53544758.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:48:06.137382030 CET4916753192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:48:06.143820047 CET53491678.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:48:07.808557034 CET5160053192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:48:07.815032005 CET53516008.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:48:09.474993944 CET5252053192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:48:09.482031107 CET53525208.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:48:11.136070013 CET4673153192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:48:11.144340038 CET53467318.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:48:12.791671991 CET3318053192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:48:12.798790932 CET53331808.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:48:14.450206041 CET5127253192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:48:14.457346916 CET53512728.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:48:16.134618998 CET4553153192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:48:16.141693115 CET53455318.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:48:17.794841051 CET3404053192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:48:17.802181959 CET53340408.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:48:19.475548983 CET5356953192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:48:19.482361078 CET53535698.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:48:21.118942976 CET4899153192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:48:21.126025915 CET53489918.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:48:22.796720982 CET5891053192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:48:22.803611994 CET53589108.8.8.8192.168.2.23
                                                                      Jan 11, 2025 14:48:24.475429058 CET5455053192.168.2.238.8.8.8
                                                                      Jan 11, 2025 14:48:24.482784033 CET53545508.8.8.8192.168.2.23
                                                                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                      Jan 11, 2025 14:46:20.621429920 CET192.168.2.238.8.8.80xdca8Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:22.400115967 CET192.168.2.238.8.8.80xdae3Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:24.065073013 CET192.168.2.238.8.8.80x6f8aStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:25.824316025 CET192.168.2.238.8.8.80xfb3fStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:27.478777885 CET192.168.2.238.8.8.80x7480Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:29.273312092 CET192.168.2.238.8.8.80xa985Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:31.209656954 CET192.168.2.238.8.8.80x9f0aStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:33.168548107 CET192.168.2.238.8.8.80x3b72Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:34.990176916 CET192.168.2.238.8.8.80xe495Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:36.715537071 CET192.168.2.238.8.8.80x577Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:38.367058992 CET192.168.2.238.8.8.80xae89Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:40.041610003 CET192.168.2.238.8.8.80xfe21Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:41.729561090 CET192.168.2.238.8.8.80x4bceStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:43.382596016 CET192.168.2.238.8.8.80x51c2Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:45.041909933 CET192.168.2.238.8.8.80x82eeStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:46.694963932 CET192.168.2.238.8.8.80x610dStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:48.366228104 CET192.168.2.238.8.8.80x7396Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:50.007255077 CET192.168.2.238.8.8.80xf56cStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:51.668620110 CET192.168.2.238.8.8.80x2a5dStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:53.320355892 CET192.168.2.238.8.8.80xd899Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:55.009826899 CET192.168.2.238.8.8.80x8c6eStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:56.667397022 CET192.168.2.238.8.8.80x9abbStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:58.448060036 CET192.168.2.238.8.8.80x3669Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:00.118093967 CET192.168.2.238.8.8.80x96bcStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:01.773888111 CET192.168.2.238.8.8.80x36d8Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:03.607623100 CET192.168.2.238.8.8.80x941aStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:05.275428057 CET192.168.2.238.8.8.80x5d33Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:06.933424950 CET192.168.2.238.8.8.80xb7c2Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:08.585803032 CET192.168.2.238.8.8.80xdd35Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:10.264503002 CET192.168.2.238.8.8.80xf188Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:11.934591055 CET192.168.2.238.8.8.80xf09aStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:13.649164915 CET192.168.2.238.8.8.80x96b1Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:15.289163113 CET192.168.2.238.8.8.80x3590Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:16.950166941 CET192.168.2.238.8.8.80xd154Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:18.742273092 CET192.168.2.238.8.8.80xf91dStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:21.033874035 CET192.168.2.238.8.8.80xf071Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:22.699379921 CET192.168.2.238.8.8.80x3118Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:24.369143009 CET192.168.2.238.8.8.80x8d56Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:26.027786016 CET192.168.2.238.8.8.80x14bfStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:27.695487022 CET192.168.2.238.8.8.80x539cStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:29.336658955 CET192.168.2.238.8.8.80x8079Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:30.977018118 CET192.168.2.238.8.8.80xe1beStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:32.638648987 CET192.168.2.238.8.8.80xf325Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:34.408343077 CET192.168.2.238.8.8.80xbb4eStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:36.075712919 CET192.168.2.238.8.8.80xcc16Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:37.731483936 CET192.168.2.238.8.8.80x172dStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:39.402626991 CET192.168.2.238.8.8.80x8275Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:41.058438063 CET192.168.2.238.8.8.80x2635Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:42.714827061 CET192.168.2.238.8.8.80x24d2Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:44.367813110 CET192.168.2.238.8.8.80x38edStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:46.056243896 CET192.168.2.238.8.8.80xfa80Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:47.695328951 CET192.168.2.238.8.8.80x944aStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:49.352622986 CET192.168.2.238.8.8.80x3f5Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:51.026021004 CET192.168.2.238.8.8.80x19b4Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:52.695920944 CET192.168.2.238.8.8.80x7cccStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:54.525527954 CET192.168.2.238.8.8.80xc86aStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:56.165873051 CET192.168.2.238.8.8.80x30f6Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:57.824357986 CET192.168.2.238.8.8.80x1c99Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:59.477729082 CET192.168.2.238.8.8.80xf696Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:01.149005890 CET192.168.2.238.8.8.80x4a38Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:02.808240891 CET192.168.2.238.8.8.80x77d1Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:04.464073896 CET192.168.2.238.8.8.80x4715Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:06.137382030 CET192.168.2.238.8.8.80x9947Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:07.808557034 CET192.168.2.238.8.8.80x794bStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:09.474993944 CET192.168.2.238.8.8.80xd6caStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:11.136070013 CET192.168.2.238.8.8.80xfa19Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:12.791671991 CET192.168.2.238.8.8.80xe1f4Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:14.450206041 CET192.168.2.238.8.8.80xefbfStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:16.134618998 CET192.168.2.238.8.8.80xfdfcStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:17.794841051 CET192.168.2.238.8.8.80xef0cStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:19.475548983 CET192.168.2.238.8.8.80x103aStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:21.118942976 CET192.168.2.238.8.8.80x620bStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:22.796720982 CET192.168.2.238.8.8.80x9e28Standard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:24.475429058 CET192.168.2.238.8.8.80xce8aStandard query (0)update.byeux.comA (IP address)IN (0x0001)false
                                                                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                      Jan 11, 2025 14:46:20.750608921 CET8.8.8.8192.168.2.230xdca8No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:22.407104015 CET8.8.8.8192.168.2.230xdae3No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:24.167109966 CET8.8.8.8192.168.2.230x6f8aNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:25.831480980 CET8.8.8.8192.168.2.230xfb3fNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:27.635440111 CET8.8.8.8192.168.2.230x7480No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:29.377567053 CET8.8.8.8192.168.2.230xa985No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:31.363796949 CET8.8.8.8192.168.2.230x9f0aNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:33.330193996 CET8.8.8.8192.168.2.230x3b72No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:34.997399092 CET8.8.8.8192.168.2.230xe495No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:36.722652912 CET8.8.8.8192.168.2.230x577No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:38.374140024 CET8.8.8.8192.168.2.230xae89No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:40.049201012 CET8.8.8.8192.168.2.230xfe21No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:41.736674070 CET8.8.8.8192.168.2.230x4bceNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:43.389409065 CET8.8.8.8192.168.2.230x51c2No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:45.049041033 CET8.8.8.8192.168.2.230x82eeNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:46.701977015 CET8.8.8.8192.168.2.230x610dNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:48.373009920 CET8.8.8.8192.168.2.230x7396No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:50.015105009 CET8.8.8.8192.168.2.230xf56cNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:51.675709963 CET8.8.8.8192.168.2.230x2a5dNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:53.327518940 CET8.8.8.8192.168.2.230xd899No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:55.016617060 CET8.8.8.8192.168.2.230x8c6eNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:56.794346094 CET8.8.8.8192.168.2.230x9abbNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:46:58.454880953 CET8.8.8.8192.168.2.230x3669No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:00.125576019 CET8.8.8.8192.168.2.230x96bcNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:01.924236059 CET8.8.8.8192.168.2.230x36d8No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:03.614653111 CET8.8.8.8192.168.2.230x941aNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:05.282536030 CET8.8.8.8192.168.2.230x5d33No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:06.940171957 CET8.8.8.8192.168.2.230xb7c2No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:08.593051910 CET8.8.8.8192.168.2.230xdd35No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:10.273339033 CET8.8.8.8192.168.2.230xf188No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:11.941468954 CET8.8.8.8192.168.2.230xf09aNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:13.656109095 CET8.8.8.8192.168.2.230x96b1No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:15.296089888 CET8.8.8.8192.168.2.230x3590No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:17.099857092 CET8.8.8.8192.168.2.230xd154No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:18.749217987 CET8.8.8.8192.168.2.230xf91dNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:21.040766001 CET8.8.8.8192.168.2.230xf071No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:22.706322908 CET8.8.8.8192.168.2.230x3118No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:24.376621962 CET8.8.8.8192.168.2.230x8d56No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:26.034706116 CET8.8.8.8192.168.2.230x14bfNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:27.702472925 CET8.8.8.8192.168.2.230x539cNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:29.344540119 CET8.8.8.8192.168.2.230x8079No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:30.984201908 CET8.8.8.8192.168.2.230xe1beNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:32.646220922 CET8.8.8.8192.168.2.230xf325No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:34.415095091 CET8.8.8.8192.168.2.230xbb4eNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:36.082252979 CET8.8.8.8192.168.2.230xcc16No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:37.738065004 CET8.8.8.8192.168.2.230x172dNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:39.409677982 CET8.8.8.8192.168.2.230x8275No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:41.065495014 CET8.8.8.8192.168.2.230x2635No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:42.723799944 CET8.8.8.8192.168.2.230x24d2No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:44.374564886 CET8.8.8.8192.168.2.230x38edNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:46.063301086 CET8.8.8.8192.168.2.230xfa80No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:47.702836037 CET8.8.8.8192.168.2.230x944aNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:49.360256910 CET8.8.8.8192.168.2.230x3f5No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:51.033071041 CET8.8.8.8192.168.2.230x19b4No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:52.856327057 CET8.8.8.8192.168.2.230x7cccNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:54.532468081 CET8.8.8.8192.168.2.230xc86aNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:56.172739983 CET8.8.8.8192.168.2.230x30f6No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:57.831084013 CET8.8.8.8192.168.2.230x1c99No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:47:59.484755039 CET8.8.8.8192.168.2.230xf696No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:01.156239033 CET8.8.8.8192.168.2.230x4a38No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:02.815401077 CET8.8.8.8192.168.2.230x77d1No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:04.472337008 CET8.8.8.8192.168.2.230x4715No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:06.143820047 CET8.8.8.8192.168.2.230x9947No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:07.815032005 CET8.8.8.8192.168.2.230x794bNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:09.482031107 CET8.8.8.8192.168.2.230xd6caNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:11.144340038 CET8.8.8.8192.168.2.230xfa19No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:12.798790932 CET8.8.8.8192.168.2.230xe1f4No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:14.457346916 CET8.8.8.8192.168.2.230xefbfNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:16.141693115 CET8.8.8.8192.168.2.230xfdfcNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:17.802181959 CET8.8.8.8192.168.2.230xef0cNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:19.482361078 CET8.8.8.8192.168.2.230x103aNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:21.126025915 CET8.8.8.8192.168.2.230x620bNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:22.803611994 CET8.8.8.8192.168.2.230x9e28No error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false
                                                                      Jan 11, 2025 14:48:24.482784033 CET8.8.8.8192.168.2.230xce8aNo error (0)update.byeux.com107.189.4.201A (IP address)IN (0x0001)false

                                                                      System Behavior

                                                                      Start time (UTC):13:46:19
                                                                      Start date (UTC):11/01/2025
                                                                      Path:/tmp/spc.elf
                                                                      Arguments:/tmp/spc.elf
                                                                      File size:4379400 bytes
                                                                      MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                                                                      Start time (UTC):13:46:19
                                                                      Start date (UTC):11/01/2025
                                                                      Path:/tmp/spc.elf
                                                                      Arguments:-
                                                                      File size:4379400 bytes
                                                                      MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                                                                      Start time (UTC):13:46:19
                                                                      Start date (UTC):11/01/2025
                                                                      Path:/tmp/spc.elf
                                                                      Arguments:-
                                                                      File size:4379400 bytes
                                                                      MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                                                                      Start time (UTC):13:46:19
                                                                      Start date (UTC):11/01/2025
                                                                      Path:/tmp/spc.elf
                                                                      Arguments:-
                                                                      File size:4379400 bytes
                                                                      MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                                                                      Start time (UTC):13:46:19
                                                                      Start date (UTC):11/01/2025
                                                                      Path:/tmp/spc.elf
                                                                      Arguments:-
                                                                      File size:4379400 bytes
                                                                      MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                                                                      Start time (UTC):13:46:29
                                                                      Start date (UTC):11/01/2025
                                                                      Path:/usr/bin/dash
                                                                      Arguments:-
                                                                      File size:129816 bytes
                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                      Start time (UTC):13:46:29
                                                                      Start date (UTC):11/01/2025
                                                                      Path:/usr/bin/rm
                                                                      Arguments:rm -f /tmp/tmp.lmaZ6NiHPq /tmp/tmp.Hdcvw0I1J0 /tmp/tmp.EKhH8LMmJS
                                                                      File size:72056 bytes
                                                                      MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                      Start time (UTC):13:46:30
                                                                      Start date (UTC):11/01/2025
                                                                      Path:/usr/bin/dash
                                                                      Arguments:-
                                                                      File size:129816 bytes
                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                      Start time (UTC):13:46:30
                                                                      Start date (UTC):11/01/2025
                                                                      Path:/usr/bin/rm
                                                                      Arguments:rm -f /tmp/tmp.lmaZ6NiHPq /tmp/tmp.Hdcvw0I1J0 /tmp/tmp.EKhH8LMmJS
                                                                      File size:72056 bytes
                                                                      MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b