Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
debug.dbg.elf

Overview

General Information

Sample name:debug.dbg.elf
Analysis ID:1590778
MD5:af8e209a53a3fde3d3dda2e113621b46
SHA1:23d7da7ad9f9e6138eb978e040c0adcab0ba4fcc
SHA256:ea778e0edc6d14d9bc2aeca2eaf2fa5d2054ce43562c1f13061167f2782db80d
Tags:elfMiraiuser-abuse_ch
Infos:

Detection

Mirai, Moobot
Score:100
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Detected Mirai
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Mirai
Yara detected Moobot
Machine Learning detection for sample
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Yara signature match

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1590778
Start date and time:2025-01-14 16:30:12 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 42s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:debug.dbg.elf
Detection:MAL
Classification:mal100.troj.evad.linELF@0/0@1/0
Command:/tmp/debug.dbg.elf
PID:6230
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
done.
Standard Error:
  • system is lnxubuntu20
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
NameDescriptionAttributionBlogpost URLsLink
MooBotNo Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.moobot
SourceRuleDescriptionAuthorStrings
debug.dbg.elfJoeSecurity_MoobotYara detected MoobotJoe Security
    debug.dbg.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      debug.dbg.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0xc61c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc630:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc644:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc658:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc66c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc680:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc694:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc6a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc6bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc6d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc6e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc6f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc70c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc720:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc734:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc748:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc75c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc770:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc784:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc798:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc7ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      debug.dbg.elfLinux_Trojan_Mirai_b14f4c5dunknownunknown
      • 0x4b60:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
      debug.dbg.elfLinux_Trojan_Mirai_88de437funknownunknown
      • 0x76f2:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
      Click to see the 3 entries
      SourceRuleDescriptionAuthorStrings
      6230.1.0000000008048000.0000000008057000.r-x.sdmpJoeSecurity_MoobotYara detected MoobotJoe Security
        6230.1.0000000008048000.0000000008057000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          6230.1.0000000008048000.0000000008057000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
          • 0xc61c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc630:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc644:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc658:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc66c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc680:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc694:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc6a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc6bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc6d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc6e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc6f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc70c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc720:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc734:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc748:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc75c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc770:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc784:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc798:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xc7ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          6230.1.0000000008048000.0000000008057000.r-x.sdmpLinux_Trojan_Mirai_b14f4c5dunknownunknown
          • 0x4b60:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
          6230.1.0000000008048000.0000000008057000.r-x.sdmpLinux_Trojan_Mirai_88de437funknownunknown
          • 0x76f2:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
          Click to see the 5 entries
          TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
          2025-01-14T16:31:06.512970+010020304911Malware Command and Control Activity Detected192.168.2.2343962107.189.3.21430242TCP
          TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
          2025-01-14T16:31:07.046620+010020304891Malware Command and Control Activity Detected107.189.3.21430242192.168.2.2343962TCP
          2025-01-14T16:31:09.271769+010020304891Malware Command and Control Activity Detected107.189.3.21430242192.168.2.2343962TCP
          2025-01-14T16:31:29.274707+010020304891Malware Command and Control Activity Detected107.189.3.21430242192.168.2.2343962TCP
          2025-01-14T16:31:49.277873+010020304891Malware Command and Control Activity Detected107.189.3.21430242192.168.2.2343962TCP
          2025-01-14T16:32:09.280846+010020304891Malware Command and Control Activity Detected107.189.3.21430242192.168.2.2343962TCP
          2025-01-14T16:32:29.283637+010020304891Malware Command and Control Activity Detected107.189.3.21430242192.168.2.2343962TCP
          2025-01-14T16:32:49.286622+010020304891Malware Command and Control Activity Detected107.189.3.21430242192.168.2.2343962TCP
          2025-01-14T16:33:09.291877+010020304891Malware Command and Control Activity Detected107.189.3.21430242192.168.2.2343962TCP

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: debug.dbg.elfAvira: detected
          Source: debug.dbg.elfVirustotal: Detection: 56%Perma Link
          Source: debug.dbg.elfReversingLabs: Detection: 50%
          Source: debug.dbg.elfJoe Sandbox ML: detected

          Networking

          barindex
          Source: Network trafficSuricata IDS: 2030491 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) : 192.168.2.23:43962 -> 107.189.3.214:30242
          Source: Network trafficSuricata IDS: 2030489 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response : 107.189.3.214:30242 -> 192.168.2.23:43962
          Source: global trafficTCP traffic: 192.168.2.23:43962 -> 107.189.3.214:30242
          Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
          Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
          Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
          Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
          Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
          Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
          Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
          Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
          Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
          Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
          Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
          Source: global trafficDNS traffic detected: DNS query: bot.tianyadd.top
          Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

          System Summary

          barindex
          Source: debug.dbg.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: debug.dbg.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
          Source: debug.dbg.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
          Source: debug.dbg.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
          Source: debug.dbg.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
          Source: debug.dbg.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
          Source: 6230.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 6230.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
          Source: 6230.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
          Source: 6230.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
          Source: 6230.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
          Source: 6230.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
          Source: Process Memory Space: debug.dbg.elf PID: 6230, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: ELF static info symbol of initial sample.symtab present: no
          Source: debug.dbg.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: debug.dbg.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
          Source: debug.dbg.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
          Source: debug.dbg.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
          Source: debug.dbg.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
          Source: debug.dbg.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
          Source: 6230.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 6230.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
          Source: 6230.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
          Source: 6230.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
          Source: 6230.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
          Source: 6230.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
          Source: Process Memory Space: debug.dbg.elf PID: 6230, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: classification engineClassification label: mal100.troj.evad.linELF@0/0@1/0
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/6234/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/6233/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/1582/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/3088/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/230/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/110/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/231/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/111/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/232/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/1579/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/112/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/233/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/1699/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/113/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/234/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/1335/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/1698/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/114/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/235/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/1334/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/1576/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/2302/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/115/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/236/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/116/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/237/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/117/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/118/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/910/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/119/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/912/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/10/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/2307/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/11/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/918/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/12/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/13/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/14/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/15/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/16/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/17/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/18/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/1594/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/120/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/121/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/1349/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/1/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/122/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/243/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/123/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/2/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/124/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/3/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/4/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/125/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/126/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/1344/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/1465/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/1586/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/127/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/6/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/248/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/128/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/249/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/1463/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/800/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/9/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/801/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/20/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/21/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/1900/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/22/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/23/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/24/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/25/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/26/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/27/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/28/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/29/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/491/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/250/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/130/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/251/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/252/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/132/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/253/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/254/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/255/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/256/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/1599/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/257/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/1477/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/379/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/258/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/1476/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/259/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/1475/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/4501/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/936/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/4503/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/30/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/2208/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/35/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/1809/cmdlineJump to behavior
          Source: /tmp/debug.dbg.elf (PID: 6232)File opened: /proc/1494/cmdlineJump to behavior

          Hooking and other Techniques for Hiding and Protection

          barindex
          Source: /tmp/debug.dbg.elf (PID: 6230)File: /tmp/debug.dbg.elfJump to behavior

          Stealing of Sensitive Information

          barindex
          Source: Yara matchFile source: debug.dbg.elf, type: SAMPLE
          Source: Yara matchFile source: 6230.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: debug.dbg.elf PID: 6230, type: MEMORYSTR
          Source: Yara matchFile source: debug.dbg.elf, type: SAMPLE
          Source: Yara matchFile source: 6230.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORY

          Remote Access Functionality

          barindex
          Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)
          Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response
          Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response
          Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response
          Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response
          Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response
          Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response
          Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response
          Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response
          Source: Yara matchFile source: debug.dbg.elf, type: SAMPLE
          Source: Yara matchFile source: 6230.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: debug.dbg.elf PID: 6230, type: MEMORYSTR
          Source: Yara matchFile source: debug.dbg.elf, type: SAMPLE
          Source: Yara matchFile source: 6230.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORY
          ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
          Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
          File Deletion
          1
          OS Credential Dumping
          System Service DiscoveryRemote ServicesData from Local System1
          Encrypted Channel
          Exfiltration Over Other Network MediumAbuse Accessibility Features
          CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
          Non-Standard Port
          Exfiltration Over BluetoothNetwork Denial of Service
          Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
          Non-Application Layer Protocol
          Automated ExfiltrationData Encrypted for Impact
          Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
          Application Layer Protocol
          Traffic DuplicationData Destruction
          No configs have been found
          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Number of created Files
          • Is malicious
          • Internet
          behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1590778 Sample: debug.dbg.elf Startdate: 14/01/2025 Architecture: LINUX Score: 100 20 bot.tianyadd.top 107.189.3.214, 30242, 43962 PONYNETUS United States 2->20 22 109.202.202.202, 80 INIT7CH Switzerland 2->22 24 2 other IPs or domains 2->24 26 Suricata IDS alerts for network traffic 2->26 28 Malicious sample detected (through community Yara rule) 2->28 30 Antivirus / Scanner detection for submitted sample 2->30 32 5 other signatures 2->32 9 debug.dbg.elf 2->9         started        signatures3 process4 signatures5 34 Sample deletes itself 9->34 12 debug.dbg.elf 9->12         started        process6 process7 14 debug.dbg.elf 12->14         started        16 debug.dbg.elf 12->16         started        process8 18 debug.dbg.elf 14->18         started       
          SourceDetectionScannerLabelLink
          debug.dbg.elf56%VirustotalBrowse
          debug.dbg.elf50%ReversingLabsLinux.Trojan.Mirai
          debug.dbg.elf100%AviraEXP/ELF.Mirai.Z.A
          debug.dbg.elf100%Joe Sandbox ML
          No Antivirus matches
          No Antivirus matches
          No Antivirus matches
          NameIPActiveMaliciousAntivirus DetectionReputation
          bot.tianyadd.top
          107.189.3.214
          truefalse
            high
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            107.189.3.214
            bot.tianyadd.topUnited States
            53667PONYNETUSfalse
            109.202.202.202
            unknownSwitzerland
            13030INIT7CHfalse
            91.189.91.43
            unknownUnited Kingdom
            41231CANONICAL-ASGBfalse
            91.189.91.42
            unknownUnited Kingdom
            41231CANONICAL-ASGBfalse
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            107.189.3.214arm7.elfGet hashmaliciousMirai, MoobotBrowse
              mips.elfGet hashmaliciousMirai, MoobotBrowse
                m68k.elfGet hashmaliciousMirai, MoobotBrowse
                  x86.elfGet hashmaliciousMirai, MoobotBrowse
                    x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                      ppc.elfGet hashmaliciousMirai, MoobotBrowse
                        spc.elfGet hashmaliciousMirai, MoobotBrowse
                          mpsl.elfGet hashmaliciousMirai, MoobotBrowse
                            109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                            • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                            91.189.91.43m-p.s-l.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                              x-3.2-.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                                rebirth.i686.elfGet hashmaliciousGafgytBrowse
                                  arm6.elfGet hashmaliciousMirai, MoobotBrowse
                                    meth12.elfGet hashmaliciousMiraiBrowse
                                      rebirth.ppc.elfGet hashmaliciousGafgytBrowse
                                        x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                                          p-p.c-.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                                            rebirth.arm5.elfGet hashmaliciousGafgytBrowse
                                              Aqua.i686.elfGet hashmaliciousUnknownBrowse
                                                91.189.91.42m-p.s-l.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                  x-3.2-.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                    rebirth.i686.elfGet hashmaliciousGafgytBrowse
                                                      arm6.elfGet hashmaliciousMirai, MoobotBrowse
                                                        meth12.elfGet hashmaliciousMiraiBrowse
                                                          rebirth.ppc.elfGet hashmaliciousGafgytBrowse
                                                            x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                                                              p-p.c-.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                rebirth.arm5.elfGet hashmaliciousGafgytBrowse
                                                                  Aqua.i686.elfGet hashmaliciousUnknownBrowse
                                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                    bot.tianyadd.toparm7.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    • 107.189.3.214
                                                                    mips.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    • 107.189.3.214
                                                                    m68k.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    • 107.189.3.214
                                                                    x86.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    • 107.189.3.214
                                                                    x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    • 107.189.3.214
                                                                    ppc.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    • 107.189.3.214
                                                                    spc.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    • 107.189.3.214
                                                                    mpsl.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    • 107.189.3.214
                                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                    CANONICAL-ASGBm-p.s-l.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                    • 91.189.91.42
                                                                    x-3.2-.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                    • 91.189.91.42
                                                                    rebirth.i686.elfGet hashmaliciousGafgytBrowse
                                                                    • 91.189.91.42
                                                                    arm6.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    • 91.189.91.42
                                                                    meth12.elfGet hashmaliciousMiraiBrowse
                                                                    • 91.189.91.42
                                                                    m68k.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    • 185.125.190.26
                                                                    x86.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    • 185.125.190.26
                                                                    rebirth.ppc.elfGet hashmaliciousGafgytBrowse
                                                                    • 91.189.91.42
                                                                    x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    • 91.189.91.42
                                                                    p-p.c-.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                    • 91.189.91.42
                                                                    CANONICAL-ASGBm-p.s-l.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                    • 91.189.91.42
                                                                    x-3.2-.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                    • 91.189.91.42
                                                                    rebirth.i686.elfGet hashmaliciousGafgytBrowse
                                                                    • 91.189.91.42
                                                                    arm6.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    • 91.189.91.42
                                                                    meth12.elfGet hashmaliciousMiraiBrowse
                                                                    • 91.189.91.42
                                                                    m68k.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    • 185.125.190.26
                                                                    x86.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    • 185.125.190.26
                                                                    rebirth.ppc.elfGet hashmaliciousGafgytBrowse
                                                                    • 91.189.91.42
                                                                    x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    • 91.189.91.42
                                                                    p-p.c-.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                    • 91.189.91.42
                                                                    PONYNETUSarm7.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    • 107.189.3.214
                                                                    mips.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    • 107.189.3.214
                                                                    m68k.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    • 107.189.3.214
                                                                    x86.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    • 107.189.3.214
                                                                    x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    • 107.189.3.214
                                                                    ppc.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    • 107.189.3.214
                                                                    spc.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    • 107.189.3.214
                                                                    mpsl.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    • 107.189.3.214
                                                                    https://clients.dedicatedservicesusa.comGet hashmaliciousUnknownBrowse
                                                                    • 198.98.59.241
                                                                    m68k.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    • 107.189.4.201
                                                                    INIT7CHm-p.s-l.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                    • 109.202.202.202
                                                                    x-3.2-.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                    • 109.202.202.202
                                                                    rebirth.i686.elfGet hashmaliciousGafgytBrowse
                                                                    • 109.202.202.202
                                                                    arm6.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    • 109.202.202.202
                                                                    meth12.elfGet hashmaliciousMiraiBrowse
                                                                    • 109.202.202.202
                                                                    rebirth.ppc.elfGet hashmaliciousGafgytBrowse
                                                                    • 109.202.202.202
                                                                    x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    • 109.202.202.202
                                                                    p-p.c-.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                    • 109.202.202.202
                                                                    rebirth.arm5.elfGet hashmaliciousGafgytBrowse
                                                                    • 109.202.202.202
                                                                    Aqua.i686.elfGet hashmaliciousUnknownBrowse
                                                                    • 109.202.202.202
                                                                    No context
                                                                    No context
                                                                    No created / dropped files found
                                                                    File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
                                                                    Entropy (8bit):6.582797089770973
                                                                    TrID:
                                                                    • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                    • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                    File name:debug.dbg.elf
                                                                    File size:60'080 bytes
                                                                    MD5:af8e209a53a3fde3d3dda2e113621b46
                                                                    SHA1:23d7da7ad9f9e6138eb978e040c0adcab0ba4fcc
                                                                    SHA256:ea778e0edc6d14d9bc2aeca2eaf2fa5d2054ce43562c1f13061167f2782db80d
                                                                    SHA512:52c94ca70ae4271092f3e506d2d12b843e7fb3360304d8e45f1d910c82ffd174e5237c149c115cf3ea977b7fa0aee1b9d411c3d340ba8c6fd6667b3865f19f18
                                                                    SSDEEP:1536:DIqD1xfYqyDgZtmYXw8pJcpJoC2TwY5ts0Aj+ISeWYesu:DIqDXfYqykZ4YXwIJcp+1wytzG+MWYeb
                                                                    TLSH:10436DC6D143D8F6E80B0570602BE72BAE71E4EA2219FF47C768D631FC86641A5179DC
                                                                    File Content Preview:.ELF....................d...4... .......4. ...(.....................\...\...............`...`v..`v.......'..........Q.td............................U..S............h....S...[]...$.............U......=.x...t..5.....v......v......u........t....h\f..........

                                                                    ELF header

                                                                    Class:ELF32
                                                                    Data:2's complement, little endian
                                                                    Version:1 (current)
                                                                    Machine:Intel 80386
                                                                    Version Number:0x1
                                                                    Type:EXEC (Executable file)
                                                                    OS/ABI:UNIX - System V
                                                                    ABI Version:0
                                                                    Entry Point Address:0x8048164
                                                                    Flags:0x0
                                                                    ELF Header Size:52
                                                                    Program Header Offset:52
                                                                    Program Header Size:32
                                                                    Number of Program Headers:3
                                                                    Section Header Offset:59680
                                                                    Section Header Size:40
                                                                    Number of Section Headers:10
                                                                    Header String Table Index:9
                                                                    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                    NULL0x00x00x00x00x0000
                                                                    .initPROGBITS0x80480940x940x1c0x00x6AX001
                                                                    .textPROGBITS0x80480b00xb00xc1760x00x6AX0016
                                                                    .finiPROGBITS0x80542260xc2260x170x00x6AX001
                                                                    .rodataPROGBITS0x80542400xc2400x241c0x00x2A0032
                                                                    .ctorsPROGBITS0x80576600xe6600x80x00x3WA004
                                                                    .dtorsPROGBITS0x80576680xe6680x80x00x3WA004
                                                                    .dataPROGBITS0x80576800xe6800x2600x00x3WA0032
                                                                    .bssNOBITS0x80578e00xe8e00x25200x00x3WA0032
                                                                    .shstrtabSTRTAB0x00xe8e00x3e0x00x0001
                                                                    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                    LOAD0x00x80480000x80480000xe65c0xe65c6.61840x5R E0x1000.init .text .fini .rodata
                                                                    LOAD0xe6600x80576600x80576600x2800x27a03.44420x6RW 0x1000.ctors .dtors .data .bss
                                                                    GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                                    TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                                    2025-01-14T16:31:06.512970+01002030491ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+)1192.168.2.2343962107.189.3.21430242TCP
                                                                    2025-01-14T16:31:07.046620+01002030489ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response1107.189.3.21430242192.168.2.2343962TCP
                                                                    2025-01-14T16:31:09.271769+01002030489ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response1107.189.3.21430242192.168.2.2343962TCP
                                                                    2025-01-14T16:31:29.274707+01002030489ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response1107.189.3.21430242192.168.2.2343962TCP
                                                                    2025-01-14T16:31:49.277873+01002030489ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response1107.189.3.21430242192.168.2.2343962TCP
                                                                    2025-01-14T16:32:09.280846+01002030489ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response1107.189.3.21430242192.168.2.2343962TCP
                                                                    2025-01-14T16:32:29.283637+01002030489ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response1107.189.3.21430242192.168.2.2343962TCP
                                                                    2025-01-14T16:32:49.286622+01002030489ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response1107.189.3.21430242192.168.2.2343962TCP
                                                                    2025-01-14T16:33:09.291877+01002030489ET MALWARE ELF/MooBot Mirai DDoS Variant Server Response1107.189.3.21430242192.168.2.2343962TCP
                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                    Jan 14, 2025 16:31:03.627011061 CET43928443192.168.2.2391.189.91.42
                                                                    Jan 14, 2025 16:31:06.507875919 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:06.512820959 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:06.512908936 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:06.512969971 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:06.517736912 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:06.518481016 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:06.523509026 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:06.532653093 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:06.537506104 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:06.549555063 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:06.554326057 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:06.565347910 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:06.570182085 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:06.594273090 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:06.599998951 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:06.602911949 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:06.607856989 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:06.608843088 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:06.613699913 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:06.613760948 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:06.618720055 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:06.618779898 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:06.623579979 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:06.623640060 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:06.628468037 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:06.628535986 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:06.633382082 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:06.633436918 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:06.638422012 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:06.641299963 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:06.646586895 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:06.648075104 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:06.652971029 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:06.653037071 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:06.657928944 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:06.657980919 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:06.662791014 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:06.662847042 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:06.667676926 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:06.667726040 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:06.672492981 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:06.672550917 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:06.677369118 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:06.677438021 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:06.682256937 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:06.682307959 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:06.687145948 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:06.687189102 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:06.692029953 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:06.692122936 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:06.696970940 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:06.697082043 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:06.702053070 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:07.046619892 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:07.046773911 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:07.047595978 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:07.052381992 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:07.052431107 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:07.057197094 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:07.057240963 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:07.062026024 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:07.062067986 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:07.066828012 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:07.066890001 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:07.071716070 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:07.071772099 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:07.076533079 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:07.076587915 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:07.081357002 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:07.081409931 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:07.086189032 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:07.086245060 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:07.090990067 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:07.091048002 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:07.095889091 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:07.095932007 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:07.100646973 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:07.100697994 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:07.105452061 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:07.105504990 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:07.110285997 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:07.110358000 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:07.115140915 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:07.115185022 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:07.119899035 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:07.119941950 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:07.124658108 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:07.124699116 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:07.129492998 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:07.129554033 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:07.134326935 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:09.002216101 CET42836443192.168.2.2391.189.91.43
                                                                    Jan 14, 2025 16:31:09.271769047 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:09.272080898 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:09.273158073 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:09.277916908 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:09.277964115 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:09.282720089 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:09.282771111 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:09.287528038 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:09.287584066 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:09.292377949 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:09.292443991 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:09.301862955 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:09.301917076 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:09.306701899 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:09.306765079 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:09.311505079 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:09.311570883 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:09.316881895 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:09.316931009 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:09.321676016 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:09.321722031 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:09.326556921 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:09.326616049 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:09.331363916 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:09.331403971 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:09.336179972 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:09.336225033 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:09.341068029 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:09.341118097 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:09.345865011 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:09.345911980 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:09.350707054 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:09.350752115 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:09.355576992 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:09.355628014 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:09.360903025 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:09.360987902 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:09.366081953 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:10.794142008 CET4251680192.168.2.23109.202.202.202
                                                                    Jan 14, 2025 16:31:19.364566088 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:19.369409084 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:24.871934891 CET43928443192.168.2.2391.189.91.42
                                                                    Jan 14, 2025 16:31:29.274707079 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:29.274879932 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:29.275851965 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:29.280659914 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:29.280710936 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:29.285523891 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:29.285569906 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:29.290420055 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:29.290474892 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:29.295352936 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:29.295399904 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:29.300244093 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:29.300296068 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:29.305210114 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:29.305258989 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:29.310121059 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:29.310158014 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:29.315066099 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:29.315140009 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:29.320019007 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:29.320082903 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:29.324953079 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:29.325018883 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:29.329894066 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:29.329948902 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:29.334814072 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:29.334887981 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:29.339756966 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:29.339812040 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:29.344728947 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:29.344786882 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:29.349621058 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:29.349669933 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:29.354569912 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:29.354621887 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:29.359761953 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:29.359833956 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:29.364757061 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:29.364825964 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:29.370906115 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:29.371059895 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:29.375963926 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:35.110501051 CET42836443192.168.2.2391.189.91.43
                                                                    Jan 14, 2025 16:31:41.253621101 CET4251680192.168.2.23109.202.202.202
                                                                    Jan 14, 2025 16:31:49.277873039 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.279886961 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.284708977 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.284796953 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.289583921 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.289634943 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.294472933 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.294517040 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.299248934 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.299463034 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.304212093 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.308602095 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.313391924 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.316725016 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.321458101 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.321505070 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.326318979 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.326358080 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.331088066 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.331152916 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.335980892 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.336024046 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.340766907 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.340830088 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.345621109 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.345676899 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.350471020 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.350512981 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.355249882 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.355293989 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.360042095 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.360085964 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.364844084 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.364890099 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.369668007 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.369709969 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.374528885 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.374593973 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.380120993 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.380167961 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.384924889 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.384965897 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.389758110 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.389822960 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.456897974 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.480355024 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.606093884 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.606110096 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.606118917 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.606164932 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.618469954 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.618530035 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.623506069 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.623543978 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.628479004 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.628634930 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.633433104 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.633502960 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.638421059 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:31:49.638473034 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:31:49.643246889 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:05.826174974 CET43928443192.168.2.2391.189.91.42
                                                                    Jan 14, 2025 16:32:09.280846119 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:09.281699896 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:09.286597013 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:09.286649942 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:09.291507006 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:09.291548967 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:09.296376944 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:09.296410084 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:09.301258087 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:09.301368952 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:09.306216002 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:09.306256056 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:09.311069012 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:09.311105967 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:09.315912962 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:09.315949917 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:09.320874929 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:09.320913076 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:09.325695038 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:09.325736046 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:09.330570936 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:09.330611944 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:09.335485935 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:09.335521936 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:09.340368986 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:09.340400934 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:09.345251083 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:09.345294952 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:09.350085020 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:09.350130081 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:09.354994059 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:09.355037928 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:09.359999895 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:09.360038996 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:09.364871979 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:09.364914894 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:09.369741917 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:09.369785070 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:09.375425100 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:09.375462055 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:09.380312920 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:09.380359888 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:09.385216951 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:09.385261059 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:09.390125036 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:09.390168905 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:09.395042896 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:09.395090103 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:09.399930954 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:09.399985075 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:09.404855967 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:09.404917002 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:09.409722090 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:26.303248882 CET42836443192.168.2.2391.189.91.43
                                                                    Jan 14, 2025 16:32:29.283637047 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:29.284900904 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:29.289686918 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:29.289751053 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:29.294579983 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:29.294629097 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:29.299340963 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:29.299396992 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:29.304157972 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:29.304202080 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:29.308924913 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:29.308968067 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:29.313723087 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:29.313774109 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:29.318593979 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:29.318633080 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:29.323431015 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:29.323460102 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:29.328289032 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:29.328325987 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:29.333089113 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:29.333131075 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:29.337893009 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:29.337934017 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:29.342699051 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:29.342746973 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:29.347475052 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:29.347570896 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:29.352298021 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:29.352349997 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:29.357151031 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:29.357187986 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:29.361974955 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:29.362018108 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:29.366767883 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:29.366805077 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:29.371649981 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:29.371691942 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:29.376449108 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:29.376493931 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:29.381330967 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:49.286622047 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:49.287688017 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:49.292448044 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:49.292478085 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:49.297220945 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:49.297250986 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:49.302004099 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:49.302045107 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:49.306833982 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:49.306862116 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:49.311660051 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:49.311697006 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:49.316451073 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:49.316481113 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:49.321233988 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:49.321266890 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:49.326035023 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:49.326075077 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:49.330842972 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:49.330874920 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:49.335617065 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:49.335647106 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:49.340411901 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:49.340445042 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:49.346141100 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:49.346173048 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:49.351068020 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:49.351098061 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:49.358853102 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:49.358887911 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:49.364407063 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:49.364444017 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:49.369204044 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:49.369239092 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:49.376986027 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:32:49.377041101 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:32:49.382230997 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:33:09.291877031 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:33:09.293179035 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:33:09.298083067 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:33:09.298130035 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:33:09.302923918 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:33:09.302963972 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:33:09.307718992 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:33:09.307758093 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:33:09.312511921 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:33:09.312553883 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:33:09.317404985 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:33:09.317460060 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:33:09.322211027 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:33:09.322258949 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:33:09.327034950 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:33:09.327074051 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:33:09.331914902 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:33:09.331952095 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:33:09.336699963 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:33:09.336760998 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:33:09.341543913 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:33:09.341584921 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:33:09.346694946 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:33:09.346729994 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:33:09.351468086 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:33:09.351505041 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:33:09.356275082 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:33:09.356311083 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:33:09.361042976 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:33:09.361078024 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:33:09.365888119 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:33:09.365935087 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:33:09.370768070 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:33:09.370805979 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:33:09.375628948 CET3024243962107.189.3.214192.168.2.23
                                                                    Jan 14, 2025 16:33:09.375682116 CET4396230242192.168.2.23107.189.3.214
                                                                    Jan 14, 2025 16:33:09.380474091 CET3024243962107.189.3.214192.168.2.23
                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                    Jan 14, 2025 16:31:04.825575113 CET5703853192.168.2.238.8.8.8
                                                                    Jan 14, 2025 16:31:06.035572052 CET53570388.8.8.8192.168.2.23
                                                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                    Jan 14, 2025 16:31:04.825575113 CET192.168.2.238.8.8.80xf42fStandard query (0)bot.tianyadd.topA (IP address)IN (0x0001)false
                                                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                    Jan 14, 2025 16:31:06.035572052 CET8.8.8.8192.168.2.230xf42fNo error (0)bot.tianyadd.top107.189.3.214A (IP address)IN (0x0001)false

                                                                    System Behavior

                                                                    Start time (UTC):15:31:04
                                                                    Start date (UTC):14/01/2025
                                                                    Path:/tmp/debug.dbg.elf
                                                                    Arguments:/tmp/debug.dbg.elf
                                                                    File size:60080 bytes
                                                                    MD5 hash:af8e209a53a3fde3d3dda2e113621b46

                                                                    Start time (UTC):15:31:04
                                                                    Start date (UTC):14/01/2025
                                                                    Path:/tmp/debug.dbg.elf
                                                                    Arguments:-
                                                                    File size:60080 bytes
                                                                    MD5 hash:af8e209a53a3fde3d3dda2e113621b46

                                                                    Start time (UTC):15:31:04
                                                                    Start date (UTC):14/01/2025
                                                                    Path:/tmp/debug.dbg.elf
                                                                    Arguments:-
                                                                    File size:60080 bytes
                                                                    MD5 hash:af8e209a53a3fde3d3dda2e113621b46

                                                                    Start time (UTC):15:31:04
                                                                    Start date (UTC):14/01/2025
                                                                    Path:/tmp/debug.dbg.elf
                                                                    Arguments:-
                                                                    File size:60080 bytes
                                                                    MD5 hash:af8e209a53a3fde3d3dda2e113621b46

                                                                    Start time (UTC):15:31:04
                                                                    Start date (UTC):14/01/2025
                                                                    Path:/tmp/debug.dbg.elf
                                                                    Arguments:-
                                                                    File size:60080 bytes
                                                                    MD5 hash:af8e209a53a3fde3d3dda2e113621b46