Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
boatnet.m68k.elf

Overview

General Information

Sample name:boatnet.m68k.elf
Analysis ID:1590465
MD5:a84322e22795675d9d33efc728c79558
SHA1:5f919cdf09a6b0fd5910b8d83b29c3036eab6aec
SHA256:d66438e78071a9d599f6c85127e7cdd693afb6315d741118a849ccd2620a4c65
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:84
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Sample tries to kill multiple processes (SIGKILL)
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Sample tries to kill a process (SIGKILL)
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1590465
Start date and time:2025-01-14 04:22:07 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 12s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:boatnet.m68k.elf
Detection:MAL
Classification:mal84.spre.troj.linELF@0/0@0/0
Command:/tmp/boatnet.m68k.elf
PID:6248
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6219, Parent: 4331)
  • rm (PID: 6219, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.BB4QsoPOHa /tmp/tmp.yjVWbGs7iW /tmp/tmp.fXaABbdPM7
  • dash New Fork (PID: 6220, Parent: 4331)
  • rm (PID: 6220, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.BB4QsoPOHa /tmp/tmp.yjVWbGs7iW /tmp/tmp.fXaABbdPM7
  • wrapper-2.0 (PID: 6260, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
  • wrapper-2.0 (PID: 6261, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
  • wrapper-2.0 (PID: 6262, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
  • wrapper-2.0 (PID: 6263, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
  • wrapper-2.0 (PID: 6264, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
  • wrapper-2.0 (PID: 6265, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
  • xfconfd (PID: 6269, Parent: 6268, MD5: 4c7a0d6d258bb970905b19b84abcd8e9) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
boatnet.m68k.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    boatnet.m68k.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
    • 0x11c2b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11c3f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11c53:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11c67:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11c7b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11c8f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11ca3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11cb7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11ccb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11cdf:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11cf3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11d07:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11d1b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11d2f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11d43:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11d57:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11d6b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11d7f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11d93:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11da7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11dbb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    boatnet.m68k.elfLinux_Trojan_Gafgyt_ea92cca8unknownunknown
    • 0x1217c:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
    SourceRuleDescriptionAuthorStrings
    6251.1.00007f98a4001000.00007f98a4015000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      6251.1.00007f98a4001000.00007f98a4015000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x11c2b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11c3f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11c53:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11c67:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11c7b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11c8f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11ca3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11cb7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11ccb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11cdf:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11cf3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11d07:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11d1b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11d2f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11d43:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11d57:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11d6b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11d7f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11d93:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11da7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11dbb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      6251.1.00007f98a4001000.00007f98a4015000.r-x.sdmpLinux_Trojan_Gafgyt_ea92cca8unknownunknown
      • 0x1217c:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
      6248.1.00007f98a4001000.00007f98a4015000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
        6248.1.00007f98a4001000.00007f98a4015000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
        • 0x11c2b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x11c3f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x11c53:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x11c67:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x11c7b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x11c8f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x11ca3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x11cb7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x11ccb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x11cdf:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x11cf3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x11d07:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x11d1b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x11d2f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x11d43:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x11d57:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x11d6b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x11d7f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x11d93:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x11da7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x11dbb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        Click to see the 9 entries
        No Suricata rule has matched

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: boatnet.m68k.elfAvira: detected
        Source: boatnet.m68k.elfVirustotal: Detection: 63%Perma Link
        Source: boatnet.m68k.elfReversingLabs: Detection: 65%
        Source: global trafficTCP traffic: 192.168.2.23:57514 -> 96.62.214.10:3778
        Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
        Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
        Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownTCP traffic detected without corresponding DNS query: 96.62.214.10
        Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

        System Summary

        barindex
        Source: boatnet.m68k.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: boatnet.m68k.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: 6251.1.00007f98a4001000.00007f98a4015000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: 6251.1.00007f98a4001000.00007f98a4015000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: 6248.1.00007f98a4001000.00007f98a4015000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: 6248.1.00007f98a4001000.00007f98a4015000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: Process Memory Space: boatnet.m68k.elf PID: 6248, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: Process Memory Space: boatnet.m68k.elf PID: 6248, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: Process Memory Space: boatnet.m68k.elf PID: 6251, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: Process Memory Space: boatnet.m68k.elf PID: 6251, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 2018, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 2077, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 2078, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 2079, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 2080, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 2083, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 2084, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 2114, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 2156, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 6260, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 6261, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 6262, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 6263, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 6264, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 6265, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 6269, result: successfulJump to behavior
        Source: ELF static info symbol of initial sample.symtab present: no
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 2018, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 2077, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 2078, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 2079, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 2080, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 2083, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 2084, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 2114, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 2156, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 6260, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 6261, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 6262, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 6263, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 6264, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 6265, result: successfulJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)SIGKILL sent: pid: 6269, result: successfulJump to behavior
        Source: boatnet.m68k.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: boatnet.m68k.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: 6251.1.00007f98a4001000.00007f98a4015000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: 6251.1.00007f98a4001000.00007f98a4015000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: 6248.1.00007f98a4001000.00007f98a4015000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: 6248.1.00007f98a4001000.00007f98a4015000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: Process Memory Space: boatnet.m68k.elf PID: 6248, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: Process Memory Space: boatnet.m68k.elf PID: 6248, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: Process Memory Space: boatnet.m68k.elf PID: 6251, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: Process Memory Space: boatnet.m68k.elf PID: 6251, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: classification engineClassification label: mal84.spre.troj.linELF@0/0@0/0
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /home/saturnino/.Xdefaults-galassiaJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/local/share/fonts/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /home/saturnino/.local/share/fonts/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /home/saturnino/.fonts/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/X11/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/cMap/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/cmap/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/opentype/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/type1/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/X11/Type1/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/X11/encodings/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/X11/misc/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/X11/util/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/cmap/adobe-cns1/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/cmap/adobe-gb1/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/cmap/adobe-japan1/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/cmap/adobe-japan2/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/cmap/adobe-korea1/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/opentype/malayalam/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/opentype/mathjax/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/opentype/noto/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/opentype/urw-base35/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/Gargi/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/Gubbi/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/Nakula/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/Navilu/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/Sahadeva/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/Sarai/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/abyssinica/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/ancient-scripts/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/dejavu/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/droid/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/fonts-beng-extra/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/fonts-deva-extra/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/fonts-gujr-extra/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/fonts-guru-extra/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/fonts-kalapi/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/fonts-orya-extra/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/fonts-telu-extra/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/fonts-yrsa-rasa/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/freefont/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/kacst/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/kacst-one/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/lao/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/lato/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/liberation/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/liberation2/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/lohit-assamese/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/lohit-bengali/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/lohit-devanagari/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/lohit-gujarati/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/lohit-kannada/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/lohit-malayalam/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/lohit-oriya/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/lohit-punjabi/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/lohit-tamil/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/lohit-tamil-classical/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/lohit-telugu/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/malayalam/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/noto/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/openoffice/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/padauk/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/pagul/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/samyak/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/samyak-fonts/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/sinhala/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/tibetan-machine/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/tlwg/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/ttf-khmeros-core/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/truetype/ubuntu/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/type1/urw-base35/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Directory: /usr/share/fonts/X11/encodings/large/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd (PID: 6269)Directory: /home/saturnino/.cacheJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd (PID: 6269)Directory: /home/saturnino/.localJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd (PID: 6269)Directory: /home/saturnino/.configJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd (PID: 6269)Directory: /home/saturnino/.configJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/6357/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1582/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/2033/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/2275/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/3088/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1612/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1579/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1699/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1335/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1698/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/2028/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1334/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1576/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/2302/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/3236/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/2025/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/2146/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/910/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/4444/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/4445/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/912/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/517/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/759/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/2307/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/918/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1594/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/2285/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/2281/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1349/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1623/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/761/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1622/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/884/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1983/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/2038/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1344/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1465/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1586/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1463/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/2156/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/800/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/801/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1629/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1627/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1900/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/6254/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/6256/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/4476/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/3021/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/491/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/2294/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/2050/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1877/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/772/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1633/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/4509/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1599/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1632/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/774/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1477/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/654/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/896/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1476/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1872/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/2048/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/655/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1475/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/2289/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/656/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/777/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/657/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/658/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/419/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/936/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1639/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1638/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/2208/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/2180/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/6263/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/6262/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/6265/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/6264/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/4486/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/6269/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1809/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1494/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1890/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/2063/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/2062/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/6261/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/6260/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1888/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1886/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/420/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1489/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/785/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1642/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/788/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/667/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/789/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/4479/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/1648/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/2078/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/2077/cmdlineJump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6250)File opened: /proc/2074/cmdlineJump to behavior
        Source: /usr/bin/dash (PID: 6219)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.BB4QsoPOHa /tmp/tmp.yjVWbGs7iW /tmp/tmp.fXaABbdPM7Jump to behavior
        Source: /usr/bin/dash (PID: 6220)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.BB4QsoPOHa /tmp/tmp.yjVWbGs7iW /tmp/tmp.fXaABbdPM7Jump to behavior
        Source: /tmp/boatnet.m68k.elf (PID: 6248)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6265)Queries kernel information via 'uname': Jump to behavior
        Source: boatnet.m68k.elf, 6248.1.000055bf29c74000.000055bf29cf9000.rw-.sdmp, boatnet.m68k.elf, 6251.1.000055bf29c74000.000055bf29cf9000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/m68k
        Source: boatnet.m68k.elf, 6248.1.00007fffb4364000.00007fffb4385000.rw-.sdmp, boatnet.m68k.elf, 6251.1.00007fffb4364000.00007fffb4385000.rw-.sdmpBinary or memory string: /usr/bin/qemu-m68k
        Source: boatnet.m68k.elf, 6248.1.000055bf29c74000.000055bf29cf9000.rw-.sdmp, boatnet.m68k.elf, 6251.1.000055bf29c74000.000055bf29cf9000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/m68k
        Source: boatnet.m68k.elf, 6248.1.00007fffb4364000.00007fffb4385000.rw-.sdmp, boatnet.m68k.elf, 6251.1.00007fffb4364000.00007fffb4385000.rw-.sdmpBinary or memory string: =x86_64/usr/bin/qemu-m68k/tmp/boatnet.m68k.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/boatnet.m68k.elf

        Stealing of Sensitive Information

        barindex
        Source: Yara matchFile source: Process Memory Space: boatnet.m68k.elf PID: 6248, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: boatnet.m68k.elf PID: 6251, type: MEMORYSTR
        Source: Yara matchFile source: boatnet.m68k.elf, type: SAMPLE
        Source: Yara matchFile source: 6251.1.00007f98a4001000.00007f98a4015000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6248.1.00007f98a4001000.00007f98a4015000.r-x.sdmp, type: MEMORY

        Remote Access Functionality

        barindex
        Source: Yara matchFile source: Process Memory Space: boatnet.m68k.elf PID: 6248, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: boatnet.m68k.elf PID: 6251, type: MEMORYSTR
        Source: Yara matchFile source: boatnet.m68k.elf, type: SAMPLE
        Source: Yara matchFile source: 6251.1.00007f98a4001000.00007f98a4015000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6248.1.00007f98a4001000.00007f98a4015000.r-x.sdmp, type: MEMORY
        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
        Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
        Hidden Files and Directories
        1
        OS Credential Dumping
        11
        Security Software Discovery
        Remote ServicesData from Local System1
        Encrypted Channel
        Exfiltration Over Other Network Medium1
        Service Stop
        CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
        File Deletion
        LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
        Non-Standard Port
        Exfiltration Over BluetoothNetwork Denial of Service
        Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
        Application Layer Protocol
        Automated ExfiltrationData Encrypted for Impact
        No configs have been found
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Number of created Files
        • Is malicious
        • Internet
        behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1590465 Sample: boatnet.m68k.elf Startdate: 14/01/2025 Architecture: LINUX Score: 84 22 96.62.214.10, 3778, 57514, 57516 VPLSNETUS United States 2->22 24 109.202.202.202, 80 INIT7CH Switzerland 2->24 26 2 other IPs or domains 2->26 28 Malicious sample detected (through community Yara rule) 2->28 30 Antivirus / Scanner detection for submitted sample 2->30 32 Multi AV Scanner detection for submitted file 2->32 34 Yara detected Mirai 2->34 7 dash rm boatnet.m68k.elf 2->7         started        9 dash rm 2->9         started        11 xfce4-panel wrapper-2.0 2->11         started        13 6 other processes 2->13 signatures3 process4 process5 15 boatnet.m68k.elf 7->15         started        18 boatnet.m68k.elf 7->18         started        20 boatnet.m68k.elf 7->20         started        signatures6 36 Sample tries to kill multiple processes (SIGKILL) 15->36

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.


        windows-stand
        SourceDetectionScannerLabelLink
        boatnet.m68k.elf63%VirustotalBrowse
        boatnet.m68k.elf66%ReversingLabsLinux.Trojan.Mirai
        boatnet.m68k.elf100%AviraEXP/ELF.Gafgyt.Z.F
        No Antivirus matches
        No Antivirus matches
        No Antivirus matches
        No contacted domains info
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        96.62.214.10
        unknownUnited States
        35908VPLSNETUSfalse
        109.202.202.202
        unknownSwitzerland
        13030INIT7CHfalse
        91.189.91.43
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        91.189.91.42
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        96.62.214.10boatnet.mips.elfGet hashmaliciousMiraiBrowse
          boatnet.ppc.elfGet hashmaliciousMiraiBrowse
            boatnet.arm.elfGet hashmaliciousMiraiBrowse
              boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                  boatnet.spc.elfGet hashmaliciousMiraiBrowse
                    boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                      96.62.214.10-boatnet.x86-2025-01-13T13_31_47.elfGet hashmaliciousMiraiBrowse
                        109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                        • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                        91.189.91.43tftp.elfGet hashmaliciousUnknownBrowse
                          na.elfGet hashmaliciousPrometeiBrowse
                            na.elfGet hashmaliciousPrometeiBrowse
                              camp.m68k.elfGet hashmaliciousMiraiBrowse
                                camp.ppc.elfGet hashmaliciousMiraiBrowse
                                  camp.arc.elfGet hashmaliciousMiraiBrowse
                                    boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                      boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                        na.elfGet hashmaliciousPrometeiBrowse
                                          na.elfGet hashmaliciousPrometeiBrowse
                                            91.189.91.42tftp.elfGet hashmaliciousUnknownBrowse
                                              na.elfGet hashmaliciousPrometeiBrowse
                                                na.elfGet hashmaliciousPrometeiBrowse
                                                  camp.m68k.elfGet hashmaliciousMiraiBrowse
                                                    camp.ppc.elfGet hashmaliciousMiraiBrowse
                                                      camp.arc.elfGet hashmaliciousMiraiBrowse
                                                        boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                                          boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                                No context
                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                CANONICAL-ASGBtftp.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 91.189.91.42
                                                                camp.mips.elfGet hashmaliciousMiraiBrowse
                                                                • 185.125.190.26
                                                                camp.m68k.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                camp.arm6.elfGet hashmaliciousMiraiBrowse
                                                                • 185.125.190.26
                                                                camp.ppc.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                camp.arc.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                                • 185.125.190.26
                                                                CANONICAL-ASGBtftp.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 91.189.91.42
                                                                camp.mips.elfGet hashmaliciousMiraiBrowse
                                                                • 185.125.190.26
                                                                camp.m68k.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                camp.arm6.elfGet hashmaliciousMiraiBrowse
                                                                • 185.125.190.26
                                                                camp.ppc.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                camp.arc.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                                • 185.125.190.26
                                                                INIT7CHtftp.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 109.202.202.202
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 109.202.202.202
                                                                camp.m68k.elfGet hashmaliciousMiraiBrowse
                                                                • 109.202.202.202
                                                                camp.ppc.elfGet hashmaliciousMiraiBrowse
                                                                • 109.202.202.202
                                                                camp.arc.elfGet hashmaliciousMiraiBrowse
                                                                • 109.202.202.202
                                                                boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                                                • 109.202.202.202
                                                                boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                                                • 109.202.202.202
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 109.202.202.202
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 109.202.202.202
                                                                VPLSNETUSboatnet.mips.elfGet hashmaliciousMiraiBrowse
                                                                • 96.62.214.10
                                                                boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                                • 96.62.214.10
                                                                boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                                                • 96.62.214.10
                                                                boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                                                • 96.62.214.10
                                                                boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                                                • 96.62.214.10
                                                                boatnet.spc.elfGet hashmaliciousMiraiBrowse
                                                                • 96.62.214.10
                                                                boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                                • 96.62.214.10
                                                                96.62.214.10-boatnet.x86-2025-01-13T13_31_47.elfGet hashmaliciousMiraiBrowse
                                                                • 96.62.214.10
                                                                armv6l.elfGet hashmaliciousUnknownBrowse
                                                                • 174.139.77.182
                                                                Tepe - 20000000826476479.exeGet hashmaliciousMassLogger RATBrowse
                                                                • 74.119.238.7
                                                                No context
                                                                No context
                                                                No created / dropped files found
                                                                File type:ELF 32-bit MSB executable, Motorola m68k, 68020, version 1 (SYSV), statically linked, stripped
                                                                Entropy (8bit):6.380117901526744
                                                                TrID:
                                                                • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                File name:boatnet.m68k.elf
                                                                File size:80'024 bytes
                                                                MD5:a84322e22795675d9d33efc728c79558
                                                                SHA1:5f919cdf09a6b0fd5910b8d83b29c3036eab6aec
                                                                SHA256:d66438e78071a9d599f6c85127e7cdd693afb6315d741118a849ccd2620a4c65
                                                                SHA512:745984d25b85fd92029c2f042e727e2575dac29cdf74ef7b4f572534328d6e62a812f92167d71091a25ed4bfcfa1cf165f22968810796b07708ea6ffb8bfb43b
                                                                SSDEEP:1536:OwUvSHdufBYf3s/gblSk+Z1E5jK02o18W8VwieZYbnOFwZCcMrBJCrWXpdxs8q6o:0SigblSk+Z1E5jK02jW8VneZynOFwZC4
                                                                TLSH:CF733999B4029E7CF94BDABD54164E0EE821678152830F27A7BBFD933C731A5AD03C85
                                                                File Content Preview:.ELF.......................D...4..7......4. ...(......................4...4....... .......4...T...T....(.......... .dt.Q............................NV..a....da.....N^NuNV..J9..V.f>"y..T. QJ.g.X.#...T.N."y..T. QJ.f.A.....J.g.Hy..4.N.X.......V.N^NuNV..N^NuN

                                                                ELF header

                                                                Class:ELF32
                                                                Data:2's complement, big endian
                                                                Version:1 (current)
                                                                Machine:MC68000
                                                                Version Number:0x1
                                                                Type:EXEC (Executable file)
                                                                OS/ABI:UNIX - System V
                                                                ABI Version:0
                                                                Entry Point Address:0x80000144
                                                                Flags:0x0
                                                                ELF Header Size:52
                                                                Program Header Offset:52
                                                                Program Header Size:32
                                                                Number of Program Headers:3
                                                                Section Header Offset:79624
                                                                Section Header Size:40
                                                                Number of Section Headers:10
                                                                Header String Table Index:9
                                                                NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                NULL0x00x00x00x00x0000
                                                                .initPROGBITS0x800000940x940x140x00x6AX002
                                                                .textPROGBITS0x800000a80xa80x11b1e0x00x6AX004
                                                                .finiPROGBITS0x80011bc60x11bc60xe0x00x6AX002
                                                                .rodataPROGBITS0x80011bd40x11bd40x18c80x00x2A002
                                                                .ctorsPROGBITS0x800154a00x134a00x80x00x3WA004
                                                                .dtorsPROGBITS0x800154a80x134a80x80x00x3WA004
                                                                .dataPROGBITS0x800154b40x134b40x2140x00x3WA004
                                                                .bssNOBITS0x800156c80x136c80x37c0x00x3WA004
                                                                .shstrtabSTRTAB0x00x136c80x3e0x00x0001
                                                                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                LOAD0x00x800000000x800000000x1349c0x1349c6.40450x5R E0x2000.init .text .fini .rodata
                                                                LOAD0x134a00x800154a00x800154a00x2280x5a43.11190x6RW 0x2000.ctors .dtors .data .bss
                                                                GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                                TimestampSource PortDest PortSource IPDest IP
                                                                Jan 14, 2025 04:22:52.753716946 CET43928443192.168.2.2391.189.91.42
                                                                Jan 14, 2025 04:22:54.316020966 CET575143778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:54.321114063 CET37785751496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:54.321185112 CET575143778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:54.364689112 CET575143778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:54.369914055 CET37785751496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:54.369971037 CET575143778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:54.374937057 CET37785751496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:55.094600916 CET37785751496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:55.094784021 CET575143778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:55.094990969 CET575143778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:55.095997095 CET575163778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:55.100832939 CET37785751696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:55.100955009 CET575163778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:55.102004051 CET575163778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:55.106772900 CET37785751696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:55.106844902 CET575163778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:55.111670017 CET37785751696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:55.877994061 CET37785751696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:55.878393888 CET575163778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:55.878496885 CET575163778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:55.879271030 CET575183778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:55.884171963 CET37785751896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:55.884239912 CET575183778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:55.884953022 CET575183778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:55.889779091 CET37785751896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:55.889831066 CET575183778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:55.894721985 CET37785751896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:56.685894966 CET37785751896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:56.686296940 CET575183778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:56.686523914 CET575183778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:56.687661886 CET575203778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:56.692527056 CET37785752096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:56.692610979 CET575203778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:56.693378925 CET575203778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:56.698163986 CET37785752096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:56.698211908 CET575203778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:56.703052044 CET37785752096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:57.469607115 CET37785752096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:57.469861984 CET575203778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:57.469890118 CET575203778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:57.470760107 CET575223778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:57.476650953 CET37785752296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:57.476732016 CET575223778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:57.477770090 CET575223778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:57.482628107 CET37785752296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:57.482692957 CET575223778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:57.488215923 CET37785752296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:58.249885082 CET37785752296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:58.250117064 CET575223778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:58.250199080 CET575223778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:58.251204014 CET575243778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:58.256158113 CET37785752496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:58.256290913 CET575243778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:58.257261992 CET575243778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:58.262109995 CET37785752496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:58.262201071 CET575243778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:58.267704964 CET37785752496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:58.384809017 CET42836443192.168.2.2391.189.91.43
                                                                Jan 14, 2025 04:22:59.063402891 CET37785752496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:59.063663960 CET575243778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:59.063750029 CET575243778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:59.064611912 CET575263778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:59.069540977 CET37785752696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:59.069633961 CET575263778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:59.070940971 CET575263778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:59.075777054 CET37785752696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:59.075850964 CET575263778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:59.080743074 CET37785752696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:59.152715921 CET4251680192.168.2.23109.202.202.202
                                                                Jan 14, 2025 04:22:59.858727932 CET37785752696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:59.858810902 CET575263778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:59.858900070 CET575263778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:59.861568928 CET575283778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:59.866611004 CET37785752896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:59.866678953 CET575283778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:59.873342037 CET575283778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:59.878190041 CET37785752896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:22:59.878257990 CET575283778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:22:59.883143902 CET37785752896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:00.636699915 CET37785752896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:00.636989117 CET575283778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:00.636990070 CET575283778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:00.641670942 CET575303778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:00.646594048 CET37785753096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:00.646799088 CET575303778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:00.662201881 CET575303778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:00.667058945 CET37785753096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:00.667118073 CET575303778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:00.671892881 CET37785753096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:01.419893980 CET37785753096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:01.420047045 CET575303778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:01.420047045 CET575303778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:01.421968937 CET575323778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:01.426831961 CET37785753296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:01.426888943 CET575323778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:01.430362940 CET575323778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:01.435216904 CET37785753296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:01.435271978 CET575323778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:01.440087080 CET37785753296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:02.199587107 CET37785753296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:02.199690104 CET575323778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:02.199690104 CET575323778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:02.200120926 CET575343778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:02.204941988 CET37785753496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:02.204992056 CET575343778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:02.205957890 CET575343778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:02.210861921 CET37785753496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:02.210906982 CET575343778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:02.215718031 CET37785753496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:02.989883900 CET37785753496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:02.990143061 CET575343778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:02.990215063 CET575343778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:02.992517948 CET575363778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:02.997421980 CET37785753696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:02.997533083 CET575363778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:03.003381014 CET575363778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:03.008325100 CET37785753696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:03.008641005 CET575363778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:03.013520956 CET37785753696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:03.782319069 CET37785753696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:03.782524109 CET575363778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:03.782609940 CET575363778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:03.783328056 CET575383778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:03.788189888 CET37785753896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:03.788290977 CET575383778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:03.789228916 CET575383778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:03.794368029 CET37785753896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:03.794450045 CET575383778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:03.799875021 CET37785753896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:04.568800926 CET37785753896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:04.568905115 CET575383778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:04.568945885 CET575383778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:04.569406033 CET575403778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:04.574261904 CET37785754096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:04.574321032 CET575403778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:04.575006962 CET575403778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:04.579823971 CET37785754096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:04.579916954 CET575403778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:04.584810972 CET37785754096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:05.347265959 CET37785754096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:05.347497940 CET575403778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:05.347640038 CET575403778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:05.348119020 CET575423778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:05.352993011 CET37785754296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:05.353055954 CET575423778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:05.353699923 CET575423778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:05.358503103 CET37785754296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:05.358551025 CET575423778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:05.363392115 CET37785754296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:06.125679970 CET37785754296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:06.125785112 CET575423778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:06.125969887 CET575423778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:06.126318932 CET575443778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:06.131128073 CET37785754496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:06.131184101 CET575443778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:06.131834030 CET575443778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:06.136626959 CET37785754496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:06.136678934 CET575443778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:06.141442060 CET37785754496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:06.910717010 CET37785754496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:06.911103010 CET575443778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:06.911142111 CET575443778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:06.911799908 CET575463778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:06.916749954 CET37785754696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:06.916817904 CET575463778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:06.917511940 CET575463778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:06.922363043 CET37785754696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:06.922424078 CET575463778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:06.927285910 CET37785754696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:07.694042921 CET37785754696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:07.694564104 CET575463778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:07.694829941 CET575463778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:07.695947886 CET575483778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:07.701349974 CET37785754896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:07.701431990 CET575483778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:07.702367067 CET575483778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:07.707185984 CET37785754896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:07.707251072 CET575483778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:07.712110043 CET37785754896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:08.476839066 CET37785754896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:08.477238894 CET575483778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:08.477238894 CET575483778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:08.477806091 CET575503778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:08.482634068 CET37785755096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:08.482697964 CET575503778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:08.483383894 CET575503778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:08.488181114 CET37785755096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:08.488240957 CET575503778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:08.493043900 CET37785755096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:09.260238886 CET37785755096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:09.260322094 CET575503778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:09.260591984 CET575503778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:09.261748075 CET575523778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:09.266799927 CET37785755296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:09.266921043 CET575523778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:09.267750025 CET575523778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:09.272830009 CET37785755296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:09.272947073 CET575523778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:09.277812004 CET37785755296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:10.047427893 CET37785755296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:10.047796965 CET575523778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:10.047796965 CET575523778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:10.048444986 CET575543778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:10.053921938 CET37785755496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:10.053987980 CET575543778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:10.054933071 CET575543778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:10.060215950 CET37785755496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:10.060267925 CET575543778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:10.065675974 CET37785755496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:10.846549034 CET37785755496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:10.847001076 CET575543778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:10.847001076 CET575543778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:10.847574949 CET575563778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:10.853920937 CET37785755696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:10.853985071 CET575563778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:10.854656935 CET575563778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:10.860752106 CET37785755696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:10.860802889 CET575563778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:10.867408037 CET37785755696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:11.646076918 CET37785755696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:11.646230936 CET575563778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:11.646284103 CET575563778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:11.646889925 CET575583778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:11.651747942 CET37785755896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:11.651865005 CET575583778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:11.652472973 CET575583778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:11.657376051 CET37785755896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:11.657423973 CET575583778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:11.662516117 CET37785755896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:12.435141087 CET37785755896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:12.435452938 CET575583778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:12.435452938 CET575583778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:12.437055111 CET575603778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:12.442478895 CET37785756096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:12.442662001 CET575603778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:12.443569899 CET575603778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:12.448463917 CET37785756096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:12.448532104 CET575603778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:12.453461885 CET37785756096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:13.232119083 CET37785756096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:13.232400894 CET575603778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:13.232400894 CET575603778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:13.232803106 CET575623778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:13.237641096 CET37785756296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:13.237725973 CET575623778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:13.238279104 CET575623778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:13.243082047 CET37785756296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:13.243160009 CET575623778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:13.251575947 CET37785756296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:14.030467033 CET37785756296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:14.030966043 CET575623778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:14.030966043 CET575623778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:14.032068014 CET575643778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:14.037458897 CET37785756496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:14.037605047 CET575643778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:14.038851976 CET575643778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:14.044269085 CET37785756496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:14.044334888 CET575643778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:14.049762011 CET37785756496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:14.510656118 CET43928443192.168.2.2391.189.91.42
                                                                Jan 14, 2025 04:23:14.827137947 CET37785756496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:14.827508926 CET575643778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:14.827613115 CET575643778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:14.828453064 CET575663778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:14.833225965 CET37785756696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:14.833312988 CET575663778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:14.834217072 CET575663778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:14.839050055 CET37785756696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:14.839101076 CET575663778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:14.843869925 CET37785756696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:15.605710030 CET37785756696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:15.605922937 CET575663778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:15.605923891 CET575663778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:15.606800079 CET575683778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:15.611757040 CET37785756896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:15.611839056 CET575683778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:15.612581968 CET575683778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:15.617435932 CET37785756896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:15.617497921 CET575683778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:15.622338057 CET37785756896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:16.385481119 CET37785756896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:16.385703087 CET575683778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:16.385803938 CET575683778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:16.386311054 CET575703778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:16.391205072 CET37785757096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:16.391324043 CET575703778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:16.391943932 CET575703778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:16.396851063 CET37785757096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:16.396981955 CET575703778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:16.402005911 CET37785757096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:17.164202929 CET37785757096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:17.164411068 CET575703778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:17.164411068 CET575703778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:17.164853096 CET575723778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:17.169935942 CET37785757296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:17.170061111 CET575723778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:17.171025991 CET575723778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:17.175867081 CET37785757296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:17.175918102 CET575723778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:17.180774927 CET37785757296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:17.942783117 CET37785757296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:17.942977905 CET575723778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:17.943056107 CET575723778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:17.943921089 CET575743778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:17.952042103 CET37785757496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:17.952126980 CET575743778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:17.953183889 CET575743778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:17.960438967 CET37785757496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:17.960510015 CET575743778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:17.968233109 CET37785757496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:18.735718966 CET37785757496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:18.736053944 CET575743778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:18.736187935 CET575743778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:18.737098932 CET575763778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:18.741930962 CET37785757696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:18.741995096 CET575763778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:18.742862940 CET575763778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:18.748893976 CET37785757696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:18.748951912 CET575763778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:18.753801107 CET37785757696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:19.535331011 CET37785757696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:19.535749912 CET575763778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:19.535840034 CET575763778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:19.537055016 CET575783778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:19.541878939 CET37785757896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:19.542129040 CET575783778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:19.542974949 CET575783778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:19.548437119 CET37785757896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:19.548543930 CET575783778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:19.554059982 CET37785757896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:20.344701052 CET37785757896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:20.344937086 CET575783778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:20.345027924 CET575783778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:20.345958948 CET575803778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:20.351794958 CET37785758096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:20.351860046 CET575803778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:20.352982044 CET575803778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:20.358256102 CET37785758096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:20.358326912 CET575803778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:20.363182068 CET37785758096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:21.144541979 CET37785758096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:21.144783020 CET575803778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:21.144881964 CET575803778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:21.146178961 CET575823778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:21.151112080 CET37785758296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:21.151226997 CET575823778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:21.152340889 CET575823778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:21.157222986 CET37785758296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:21.157320976 CET575823778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:21.162215948 CET37785758296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:21.944370985 CET37785758296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:21.944801092 CET575823778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:21.944801092 CET575823778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:21.945796013 CET575843778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:21.950611115 CET37785758496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:21.950728893 CET575843778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:21.952173948 CET575843778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:21.957020044 CET37785758496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:21.957128048 CET575843778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:21.962002993 CET37785758496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:22.727591991 CET37785758496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:22.728007078 CET575843778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:22.728185892 CET575843778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:22.730074883 CET575863778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:22.735038996 CET37785758696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:22.735230923 CET575863778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:22.736622095 CET575863778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:22.741533041 CET37785758696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:22.741614103 CET575863778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:22.746458054 CET37785758696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:23.509573936 CET37785758696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:23.509993076 CET575863778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:23.509993076 CET575863778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:23.511039972 CET575883778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:23.516038895 CET37785758896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:23.516127110 CET575883778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:23.517529964 CET575883778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:23.522391081 CET37785758896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:23.522488117 CET575883778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:23.527247906 CET37785758896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:24.316049099 CET37785758896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:24.316338062 CET575883778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:24.316338062 CET575883778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:24.316884041 CET575903778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:24.321753025 CET37785759096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:24.321815968 CET575903778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:24.322679996 CET575903778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:24.328535080 CET37785759096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:24.328593016 CET575903778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:24.334314108 CET37785759096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:24.749275923 CET42836443192.168.2.2391.189.91.43
                                                                Jan 14, 2025 04:23:25.114818096 CET37785759096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:25.115000963 CET575903778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:25.115163088 CET575903778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:25.115987062 CET575923778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:25.120846033 CET37785759296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:25.120908976 CET575923778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:25.121778011 CET575923778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:25.126662970 CET37785759296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:25.126754999 CET575923778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:25.131670952 CET37785759296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:25.900580883 CET37785759296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:25.900867939 CET575923778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:25.900949955 CET575923778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:25.902024031 CET575943778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:25.906894922 CET37785759496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:25.906991959 CET575943778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:25.908127069 CET575943778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:25.912980080 CET37785759496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:25.913053989 CET575943778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:25.917911053 CET37785759496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:26.725248098 CET37785759496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:26.725507021 CET575943778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:26.725596905 CET575943778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:26.726728916 CET575963778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:26.731611967 CET37785759696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:26.731684923 CET575963778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:26.732816935 CET575963778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:26.737626076 CET37785759696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:26.737708092 CET575963778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:26.742629051 CET37785759696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:27.544070959 CET37785759696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:27.544549942 CET575963778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:27.544549942 CET575963778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:27.545605898 CET575983778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:27.550497055 CET37785759896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:27.550714016 CET575983778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:27.552299023 CET575983778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:27.557234049 CET37785759896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:27.557410002 CET575983778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:27.562278986 CET37785759896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:28.844753027 CET4251680192.168.2.23109.202.202.202
                                                                Jan 14, 2025 04:23:37.561244965 CET575983778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:37.566536903 CET37785759896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:37.824569941 CET37785759896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:23:37.824724913 CET575983778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:23:55.465003967 CET43928443192.168.2.2391.189.91.42
                                                                Jan 14, 2025 04:24:37.855241060 CET575983778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:24:37.861202955 CET37785759896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:24:38.119385004 CET37785759896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:24:38.120079994 CET575983778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:25:02.093791008 CET37785759896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:25:02.094608068 CET575983778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:25:02.100486994 CET37785759896.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:25:03.102586031 CET576003778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:25:03.108063936 CET37785760096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:25:03.108197927 CET576003778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:25:03.111583948 CET576003778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:25:03.116878986 CET37785760096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:25:03.117132902 CET576003778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:25:03.121993065 CET37785760096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:25:24.484807014 CET37785760096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:25:24.485563993 CET576003778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:25:24.490612030 CET37785760096.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:25:25.491478920 CET576023778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:25:25.496896982 CET37785760296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:25:25.497124910 CET576023778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:25:25.499104023 CET576023778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:25:25.504200935 CET37785760296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:25:25.504292965 CET576023778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:25:25.509641886 CET37785760296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:25:26.276854038 CET37785760296.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:25:26.277237892 CET576023778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:25:26.277237892 CET576023778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:25:26.278273106 CET576043778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:25:26.283363104 CET37785760496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:25:26.283601999 CET576043778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:25:26.285779953 CET576043778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:25:26.290724039 CET37785760496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:25:26.290930986 CET576043778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:25:26.295927048 CET37785760496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:25:27.085472107 CET37785760496.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:25:27.085843086 CET576043778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:25:27.085843086 CET576043778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:25:27.087953091 CET576063778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:25:27.093668938 CET37785760696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:25:27.094095945 CET576063778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:25:27.096560955 CET576063778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:25:27.102016926 CET37785760696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:25:27.102490902 CET576063778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:25:27.108138084 CET37785760696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:25:47.114428043 CET576063778192.168.2.2396.62.214.10
                                                                Jan 14, 2025 04:25:47.120382071 CET37785760696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:25:47.378038883 CET37785760696.62.214.10192.168.2.23
                                                                Jan 14, 2025 04:25:47.378699064 CET576063778192.168.2.2396.62.214.10

                                                                System Behavior

                                                                Start time (UTC):03:22:49
                                                                Start date (UTC):14/01/2025
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):03:22:49
                                                                Start date (UTC):14/01/2025
                                                                Path:/usr/bin/rm
                                                                Arguments:rm -f /tmp/tmp.BB4QsoPOHa /tmp/tmp.yjVWbGs7iW /tmp/tmp.fXaABbdPM7
                                                                File size:72056 bytes
                                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                Start time (UTC):03:22:49
                                                                Start date (UTC):14/01/2025
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):03:22:49
                                                                Start date (UTC):14/01/2025
                                                                Path:/usr/bin/rm
                                                                Arguments:rm -f /tmp/tmp.BB4QsoPOHa /tmp/tmp.yjVWbGs7iW /tmp/tmp.fXaABbdPM7
                                                                File size:72056 bytes
                                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                Start time (UTC):03:22:52
                                                                Start date (UTC):14/01/2025
                                                                Path:/tmp/boatnet.m68k.elf
                                                                Arguments:/tmp/boatnet.m68k.elf
                                                                File size:4463432 bytes
                                                                MD5 hash:cd177594338c77b895ae27c33f8f86cc

                                                                Start time (UTC):03:22:53
                                                                Start date (UTC):14/01/2025
                                                                Path:/tmp/boatnet.m68k.elf
                                                                Arguments:-
                                                                File size:4463432 bytes
                                                                MD5 hash:cd177594338c77b895ae27c33f8f86cc

                                                                Start time (UTC):03:22:53
                                                                Start date (UTC):14/01/2025
                                                                Path:/tmp/boatnet.m68k.elf
                                                                Arguments:-
                                                                File size:4463432 bytes
                                                                MD5 hash:cd177594338c77b895ae27c33f8f86cc

                                                                Start time (UTC):03:22:53
                                                                Start date (UTC):14/01/2025
                                                                Path:/tmp/boatnet.m68k.elf
                                                                Arguments:-
                                                                File size:4463432 bytes
                                                                MD5 hash:cd177594338c77b895ae27c33f8f86cc

                                                                Start time (UTC):03:22:58
                                                                Start date (UTC):14/01/2025
                                                                Path:/usr/bin/xfce4-panel
                                                                Arguments:-
                                                                File size:375768 bytes
                                                                MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                                Start time (UTC):03:22:58
                                                                Start date (UTC):14/01/2025
                                                                Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                                Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
                                                                File size:35136 bytes
                                                                MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                                Start time (UTC):03:22:58
                                                                Start date (UTC):14/01/2025
                                                                Path:/usr/bin/xfce4-panel
                                                                Arguments:-
                                                                File size:375768 bytes
                                                                MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                                Start time (UTC):03:22:58
                                                                Start date (UTC):14/01/2025
                                                                Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                                Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
                                                                File size:35136 bytes
                                                                MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                                Start time (UTC):03:22:58
                                                                Start date (UTC):14/01/2025
                                                                Path:/usr/bin/xfce4-panel
                                                                Arguments:-
                                                                File size:375768 bytes
                                                                MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                                Start time (UTC):03:22:58
                                                                Start date (UTC):14/01/2025
                                                                Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                                Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
                                                                File size:35136 bytes
                                                                MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                                Start time (UTC):03:22:58
                                                                Start date (UTC):14/01/2025
                                                                Path:/usr/bin/xfce4-panel
                                                                Arguments:-
                                                                File size:375768 bytes
                                                                MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                                Start time (UTC):03:22:58
                                                                Start date (UTC):14/01/2025
                                                                Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                                Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
                                                                File size:35136 bytes
                                                                MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                                Start time (UTC):03:22:58
                                                                Start date (UTC):14/01/2025
                                                                Path:/usr/bin/xfce4-panel
                                                                Arguments:-
                                                                File size:375768 bytes
                                                                MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                                Start time (UTC):03:22:58
                                                                Start date (UTC):14/01/2025
                                                                Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                                Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
                                                                File size:35136 bytes
                                                                MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                                Start time (UTC):03:22:58
                                                                Start date (UTC):14/01/2025
                                                                Path:/usr/bin/xfce4-panel
                                                                Arguments:-
                                                                File size:375768 bytes
                                                                MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                                Start time (UTC):03:22:58
                                                                Start date (UTC):14/01/2025
                                                                Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                                Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
                                                                File size:35136 bytes
                                                                MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                                Start time (UTC):03:22:59
                                                                Start date (UTC):14/01/2025
                                                                Path:/usr/bin/dbus-daemon
                                                                Arguments:-
                                                                File size:249032 bytes
                                                                MD5 hash:3089d47e3f3ab84cd81c48fd406d7a8c

                                                                Start time (UTC):03:22:59
                                                                Start date (UTC):14/01/2025
                                                                Path:/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
                                                                Arguments:/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
                                                                File size:112880 bytes
                                                                MD5 hash:4c7a0d6d258bb970905b19b84abcd8e9