Edit tour

Linux Analysis Report
arm6.elf

Overview

General Information

Sample name:arm6.elf
Analysis ID:1594461
MD5:410b9040b58c71e514067ee09b1c93c2
SHA1:f0c544c87fffa86689856c515d8d438c819c9798
SHA256:9b3a4b23dc55ac8cdbe4f835f5cc1b78f23e3841a53d12f9743ad80e1e4b5cd7
Tags:elfuser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Detected TCP or UDP traffic on non-standard ports
Executes commands using a shell command-line interpreter
Executes the "chmod" command used to modify permissions
Executes the "mkdir" command used to create folders
Sample has stripped symbol table
Sample tries to set the executable flag
Sets full permissions to files and/or directories
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1594461
Start date and time:2025-01-19 02:07:12 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 49s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:arm6.elf
Detection:MAL
Classification:mal48.linELF@0/0@0/0
Command:/tmp/arm6.elf
PID:6242
Exit Code:1
Exit Code Info:
Killed:False
Standard Output:
GOLDFISHGANG
Standard Error:
  • system is lnxubuntu20
  • arm6.elf (PID: 6242, Parent: 6163, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/arm6.elf
    • arm6.elf New Fork (PID: 6244, Parent: 6242)
      • arm6.elf New Fork (PID: 6246, Parent: 6244)
        • arm6.elf New Fork (PID: 6252, Parent: 6246)
        • sh (PID: 6252, Parent: 6246, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "mkdir /mc8mav6i7g/ && >/mc8mav6i7g/mc8mav6i7g && cd /mc8mav6i7g/ >/dev/null"
          • sh New Fork (PID: 6254, Parent: 6252)
          • mkdir (PID: 6254, Parent: 6252, MD5: 088c9d1df5a28ed16c726eca15964cb7) Arguments: mkdir /mc8mav6i7g/
        • arm6.elf New Fork (PID: 6255, Parent: 6246)
        • sh (PID: 6255, Parent: 6246, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "mv /tmp/arm6.elf /mc8mav6i7g/mc8mav6i7g && chmod 777 /mc8mav6i7g/mc8mav6i7g >/dev/null"
          • sh New Fork (PID: 6257, Parent: 6255)
          • mv (PID: 6257, Parent: 6255, MD5: 504f0590fa482d4da070a702260e3716) Arguments: mv /tmp/arm6.elf /mc8mav6i7g/mc8mav6i7g
          • sh New Fork (PID: 6258, Parent: 6255)
          • chmod (PID: 6258, Parent: 6255, MD5: 739483b900c045ae1374d6f53a86a279) Arguments: chmod 777 /mc8mav6i7g/mc8mav6i7g
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: arm6.elfReversingLabs: Detection: 52%
Source: global trafficTCP traffic: 192.168.2.23:48740 -> 85.239.34.134:5683
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.linELF@0/0@0/0
Source: /tmp/arm6.elf (PID: 6252)Shell command executed: sh -c "mkdir /mc8mav6i7g/ && >/mc8mav6i7g/mc8mav6i7g && cd /mc8mav6i7g/ >/dev/null"Jump to behavior
Source: /tmp/arm6.elf (PID: 6255)Shell command executed: sh -c "mv /tmp/arm6.elf /mc8mav6i7g/mc8mav6i7g && chmod 777 /mc8mav6i7g/mc8mav6i7g >/dev/null"Jump to behavior
Source: /bin/sh (PID: 6258)Chmod executable: /usr/bin/chmod -> chmod 777 /mc8mav6i7g/mc8mav6i7gJump to behavior
Source: /bin/sh (PID: 6254)Mkdir executable: /usr/bin/mkdir -> mkdir /mc8mav6i7g/Jump to behavior
Source: /usr/bin/chmod (PID: 6258)File: /mc8mav6i7g/mc8mav6i7g (bits: - usr: rwx grp: rwx all: rwx)Jump to behavior
Source: /bin/sh (PID: 6258)Chmod executable with 777: /usr/bin/chmod -> chmod 777 /mc8mav6i7g/mc8mav6i7gJump to behavior
Source: /tmp/arm6.elf (PID: 6242)Queries kernel information via 'uname': Jump to behavior
Source: arm6.elf, 6242.1.00005606141f3000.0000560614321000.rw-.sdmp, arm6.elf, 6244.1.00005606141f3000.0000560614321000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: arm6.elf, 6242.1.00007ffc3c3bd000.00007ffc3c3de000.rw-.sdmp, arm6.elf, 6244.1.00007ffc3c3bd000.00007ffc3c3de000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: arm6.elf, 6242.1.00005606141f3000.0000560614321000.rw-.sdmp, arm6.elf, 6244.1.00005606141f3000.0000560614321000.rw-.sdmpBinary or memory string: V!/etc/qemu-binfmt/arm
Source: arm6.elf, 6242.1.00007ffc3c3bd000.00007ffc3c3de000.rw-.sdmp, arm6.elf, 6244.1.00007ffc3c3bd000.00007ffc3c3de000.rw-.sdmpBinary or memory string: p}x86_64/usr/bin/qemu-arm/tmp/arm6.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/arm6.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid AccountsWindows Management Instrumentation1
Scripting
Path Interception2
File and Directory Permissions Modification
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1594461 Sample: arm6.elf Startdate: 19/01/2025 Architecture: LINUX Score: 48 26 85.239.34.134, 48740, 48742, 48744 RAINBOW-HKRainbownetworklimitedHK Russian Federation 2->26 28 109.202.202.202, 80 INIT7CH Switzerland 2->28 30 2 other IPs or domains 2->30 32 Multi AV Scanner detection for submitted file 2->32 10 arm6.elf 2->10         started        signatures3 process4 process5 12 arm6.elf 10->12         started        process6 14 arm6.elf 12->14         started        process7 16 arm6.elf sh 14->16         started        18 arm6.elf sh 14->18         started        process8 20 sh mv 16->20         started        22 sh chmod 16->22         started        24 sh mkdir 18->24         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
arm6.elf53%ReversingLabsLinux.Trojan.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
85.239.34.134
unknownRussian Federation
134121RAINBOW-HKRainbownetworklimitedHKfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
85.239.34.134arm7.elfGet hashmaliciousUnknownBrowse
    ppc.elfGet hashmaliciousUnknownBrowse
      mips.elfGet hashmaliciousUnknownBrowse
        m68k.elfGet hashmaliciousUnknownBrowse
          sh4.elfGet hashmaliciousUnknownBrowse
            x86.elfGet hashmaliciousUnknownBrowse
              arm5.elfGet hashmaliciousUnknownBrowse
                spc.elfGet hashmaliciousUnknownBrowse
                  harm.elfGet hashmaliciousUnknownBrowse
                    arm6.elfGet hashmaliciousUnknownBrowse
                      109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                      • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                      91.189.91.43na.elfGet hashmaliciousPrometeiBrowse
                        na.elfGet hashmaliciousPrometeiBrowse
                          bin.sh.elfGet hashmaliciousMiraiBrowse
                            sshd.elfGet hashmaliciousUnknownBrowse
                              na.elfGet hashmaliciousPrometeiBrowse
                                sshd.elfGet hashmaliciousUnknownBrowse
                                  Mozi.m.elfGet hashmaliciousMiraiBrowse
                                    na.elfGet hashmaliciousPrometeiBrowse
                                      nabarm7.elfGet hashmaliciousUnknownBrowse
                                        nabarm5.elfGet hashmaliciousUnknownBrowse
                                          No context
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          RAINBOW-HKRainbownetworklimitedHKarm7.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          ppc.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          mips.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          m68k.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          sh4.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          x86.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          arm5.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          spc.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          harm.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          arm6.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 91.189.91.42
                                          bin.sh.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          sshd.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 91.189.91.42
                                          sshd.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          Mozi.m.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 91.189.91.42
                                          nabarm7.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          nabarm5.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          INIT7CHna.elfGet hashmaliciousPrometeiBrowse
                                          • 109.202.202.202
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 109.202.202.202
                                          bin.sh.elfGet hashmaliciousMiraiBrowse
                                          • 109.202.202.202
                                          sshd.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 109.202.202.202
                                          sshd.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          Mozi.m.elfGet hashmaliciousMiraiBrowse
                                          • 109.202.202.202
                                          na.elfGet hashmaliciousPrometeiBrowse
                                          • 109.202.202.202
                                          nabarm7.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          nabarm5.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          No context
                                          No context
                                          No created / dropped files found
                                          File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
                                          Entropy (8bit):6.125535342821544
                                          TrID:
                                          • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                          File name:arm6.elf
                                          File size:62'988 bytes
                                          MD5:410b9040b58c71e514067ee09b1c93c2
                                          SHA1:f0c544c87fffa86689856c515d8d438c819c9798
                                          SHA256:9b3a4b23dc55ac8cdbe4f835f5cc1b78f23e3841a53d12f9743ad80e1e4b5cd7
                                          SHA512:e0626b44a31fbfd3a3022922ab547cef4f799f04576ec44caa98f9be0743813b93a14d147fadce09edd6069e6305269bab515f4a080b9a3f6e20440ffd148f40
                                          SSDEEP:1536:pwneMGe5b0C5Rax59oc56WK56oS5Wwp9jWLNgtQbQas9/8I1ig4Sz+salAm50YOQ:De54C5Ex5Cc5nK5RS5WACGJae4Sz+saO
                                          TLSH:02533A56B9C19B11D9D0127AFE0E114E335313BCE3DFB2269D20AB31778B9670EAB416
                                          File Content Preview:.ELF..............(.....T...4...........4. ...(.....................h...h...............h...h...h........'..........Q.td..................................-...L..................@-.,@...0....S..... 0....S.........../..0...0...@..../.`.......h.....-.@0....S

                                          ELF header

                                          Class:ELF32
                                          Data:2's complement, little endian
                                          Version:1 (current)
                                          Machine:ARM
                                          Version Number:0x1
                                          Type:EXEC (Executable file)
                                          OS/ABI:UNIX - System V
                                          ABI Version:0
                                          Entry Point Address:0x8154
                                          Flags:0x4000002
                                          ELF Header Size:52
                                          Program Header Offset:52
                                          Program Header Size:32
                                          Number of Program Headers:3
                                          Section Header Offset:62428
                                          Section Header Size:40
                                          Number of Section Headers:14
                                          Header String Table Index:13
                                          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                          NULL0x00x00x00x00x0000
                                          .initPROGBITS0x80940x940x100x00x6AX004
                                          .textPROGBITS0x80b00xb00xdc1c0x00x6AX0016
                                          .finiPROGBITS0x15ccc0xdccc0x100x00x6AX004
                                          .rodataPROGBITS0x15ce00xdce00x13880x00x2A008
                                          .eh_framePROGBITS0x1f0680xf0680x40x00x3WA004
                                          .init_arrayINIT_ARRAY0x1f06c0xf06c0x40x00x3WA004
                                          .fini_arrayFINI_ARRAY0x1f0700xf0700x40x00x3WA004
                                          .jcrPROGBITS0x1f0740xf0740x40x00x3WA004
                                          .gotPROGBITS0x1f0780xf0780x740x40x3WA004
                                          .dataPROGBITS0x1f0ec0xf0ec0x2740x00x3WA004
                                          .bssNOBITS0x1f3600xf3600x24880x00x3WA004
                                          .ARM.attributesARM_ATTRIBUTES0x00xf3600x100x00x0001
                                          .shstrtabSTRTAB0x00xf3700x6c0x00x0001
                                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                          LOAD0x00x80000x80000xf0680xf0686.15230x5R E0x8000.init .text .fini .rodata
                                          LOAD0xf0680x1f0680x1f0680x2f80x27803.89350x6RW 0x8000.eh_frame .init_array .fini_array .jcr .got .data .bss
                                          GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                                          Download Network PCAP: filteredfull

                                          • Total Packets: 190
                                          • 5683 undefined
                                          • 443 (HTTPS)
                                          • 80 (HTTP)
                                          TimestampSource PortDest PortSource IPDest IP
                                          Jan 19, 2025 02:08:07.136218071 CET487405683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:07.141254902 CET56834874085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:07.141441107 CET487405683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:07.141561985 CET487405683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:07.146354914 CET56834874085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:08.905507088 CET56834874085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:08.905893087 CET487405683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:08.910919905 CET56834874085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:09.324316025 CET42836443192.168.2.2391.189.91.43
                                          Jan 19, 2025 02:08:09.908216000 CET487425683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:09.913418055 CET56834874285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:09.913508892 CET487425683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:09.913543940 CET487425683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:09.918423891 CET56834874285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:10.092379093 CET4251680192.168.2.23109.202.202.202
                                          Jan 19, 2025 02:08:11.688697100 CET56834874285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:11.688986063 CET487425683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:11.693888903 CET56834874285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:12.690613985 CET487445683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:12.695888042 CET56834874485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:12.695997000 CET487445683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:12.696064949 CET487445683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:12.700850964 CET56834874485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:14.448796988 CET56834874485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:14.449294090 CET487445683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:14.454137087 CET56834874485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:15.451777935 CET487465683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:15.456923962 CET56834874685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:15.457020998 CET487465683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:15.457067966 CET487465683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:15.461975098 CET56834874685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:17.214715004 CET56834874685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:17.215429068 CET487465683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:17.220438957 CET56834874685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:18.218496084 CET487485683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:18.223771095 CET56834874885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:18.223921061 CET487485683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:18.223959923 CET487485683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:18.228806973 CET56834874885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:20.001394033 CET56834874885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:20.001929045 CET487485683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:20.007003069 CET56834874885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:21.004332066 CET487505683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:21.009371996 CET56834875085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:21.009459019 CET487505683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:21.009499073 CET487505683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:21.014323950 CET56834875085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:22.763438940 CET56834875085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:22.763936996 CET487505683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:22.768862963 CET56834875085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:23.766625881 CET487525683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:23.771667004 CET56834875285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:23.771785975 CET487525683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:23.771830082 CET487525683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:23.776668072 CET56834875285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:24.682545900 CET43928443192.168.2.2391.189.91.42
                                          Jan 19, 2025 02:08:25.548803091 CET56834875285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:25.549314976 CET487525683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:25.554619074 CET56834875285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:26.552896023 CET487545683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:26.557971001 CET56834875485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:26.558069944 CET487545683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:26.558131933 CET487545683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:26.563002110 CET56834875485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:28.310339928 CET56834875485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:28.310712099 CET487545683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:28.315602064 CET56834875485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:29.312941074 CET487565683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:29.318090916 CET56834875685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:29.318176031 CET487565683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:29.318243027 CET487565683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:29.323091984 CET56834875685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:31.094018936 CET56834875685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:31.094542027 CET487565683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:31.099566936 CET56834875685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:32.097676992 CET487585683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:32.103565931 CET56834875885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:32.103663921 CET487585683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:32.103718996 CET487585683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:32.109766006 CET56834875885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:33.855669022 CET56834875885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:33.856189013 CET487585683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:33.861284018 CET56834875885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:34.858526945 CET487605683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:34.863791943 CET56834876085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:34.863892078 CET487605683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:34.863892078 CET487605683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:34.869204998 CET56834876085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:34.920939922 CET42836443192.168.2.2391.189.91.43
                                          Jan 19, 2025 02:08:36.621268034 CET56834876085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:36.621846914 CET487605683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:36.626859903 CET56834876085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:37.625102997 CET487625683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:37.630237103 CET56834876285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:37.630321026 CET487625683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:37.630373955 CET487625683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:37.635191917 CET56834876285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:39.388433933 CET56834876285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:39.388992071 CET487625683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:39.393955946 CET56834876285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:40.394078970 CET487645683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:40.399131060 CET56834876485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:40.399336100 CET487645683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:40.399472952 CET487645683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:40.404352903 CET56834876485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:41.064146996 CET4251680192.168.2.23109.202.202.202
                                          Jan 19, 2025 02:08:42.154706001 CET56834876485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:42.155445099 CET487645683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:42.160427094 CET56834876485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:43.159343958 CET487665683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:43.164520979 CET56834876685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:43.164616108 CET487665683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:43.164661884 CET487665683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:43.169517040 CET56834876685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:44.937551975 CET56834876685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:44.937973022 CET487665683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:44.943110943 CET56834876685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:45.940891981 CET487685683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:45.947721004 CET56834876885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:45.947824955 CET487685683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:45.947997093 CET487685683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:45.954677105 CET56834876885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:47.699568987 CET56834876885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:47.700012922 CET487685683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:47.705041885 CET56834876885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:48.702775002 CET487705683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:48.707968950 CET56834877085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:48.708038092 CET487705683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:48.708076954 CET487705683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:48.712940931 CET56834877085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:50.467132092 CET56834877085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:50.467632055 CET487705683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:50.472866058 CET56834877085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:51.471242905 CET487725683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:51.476171017 CET56834877285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:51.476253033 CET487725683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:51.476268053 CET487725683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:51.481137037 CET56834877285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:53.234031916 CET56834877285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:53.234313011 CET487725683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:53.240294933 CET56834877285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:54.236293077 CET487745683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:54.241421938 CET56834877485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:54.241533995 CET487745683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:54.241580009 CET487745683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:54.246485949 CET56834877485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:56.018634081 CET56834877485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:56.018908024 CET487745683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:56.024085045 CET56834877485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:57.020652056 CET487765683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:57.026036024 CET56834877685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:57.026129961 CET487765683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:57.026173115 CET487765683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:57.031260014 CET56834877685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:58.779990911 CET56834877685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:58.780503988 CET487765683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:58.785537004 CET56834877685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:59.784693956 CET487785683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:59.789849997 CET56834877885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:08:59.789937973 CET487785683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:59.789937973 CET487785683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:08:59.794831038 CET56834877885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:01.563335896 CET56834877885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:01.563764095 CET487785683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:01.568778992 CET56834877885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:02.566123962 CET487805683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:02.571335077 CET56834878085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:02.571521997 CET487805683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:02.571729898 CET487805683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:02.576816082 CET56834878085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:04.325082064 CET56834878085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:04.325409889 CET487805683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:04.330358028 CET56834878085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:05.328284025 CET487825683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:05.333448887 CET56834878285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:05.333537102 CET487825683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:05.333583117 CET487825683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:05.338448048 CET56834878285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:05.637104034 CET43928443192.168.2.2391.189.91.42
                                          Jan 19, 2025 02:09:07.092739105 CET56834878285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:07.092928886 CET487825683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:07.097763062 CET56834878285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:08.096112967 CET487845683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:08.101021051 CET56834878485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:08.101150036 CET487845683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:08.101200104 CET487845683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:08.106045008 CET56834878485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:09.856234074 CET56834878485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:09.856672049 CET487845683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:09.862279892 CET56834878485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:10.859725952 CET487865683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:10.864700079 CET56834878685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:10.864840031 CET487865683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:10.864866972 CET487865683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:10.870381117 CET56834878685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:12.622591019 CET56834878685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:12.622858047 CET487865683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:12.627753019 CET56834878685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:13.626779079 CET487885683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:13.631988049 CET56834878885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:13.632128000 CET487885683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:13.632369995 CET487885683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:13.638159990 CET56834878885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:15.388170004 CET56834878885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:15.388833046 CET487885683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:15.393774033 CET56834878885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:16.391726971 CET487905683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:16.397926092 CET56834879085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:16.398104906 CET487905683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:16.398205996 CET487905683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:16.404566050 CET56834879085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:18.153417110 CET56834879085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:18.153846979 CET487905683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:18.158729076 CET56834879085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:19.156013966 CET487925683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:19.160990000 CET56834879285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:19.161180973 CET487925683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:19.161225080 CET487925683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:19.166059017 CET56834879285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:20.925698042 CET56834879285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:20.926480055 CET487925683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:20.931433916 CET56834879285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:21.929723024 CET487945683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:21.936255932 CET56834879485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:21.936412096 CET487945683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:21.936459064 CET487945683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:21.941320896 CET56834879485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:23.686650038 CET56834879485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:23.687289953 CET487945683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:23.693870068 CET56834879485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:24.689903021 CET487965683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:24.696177959 CET56834879685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:24.696302891 CET487965683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:24.696352959 CET487965683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:24.701131105 CET56834879685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:26.114156961 CET42836443192.168.2.2391.189.91.43
                                          Jan 19, 2025 02:09:26.434783936 CET56834879685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:26.435365915 CET487965683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:26.440300941 CET56834879685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:27.438077927 CET487985683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:27.443133116 CET56834879885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:27.443265915 CET487985683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:27.443305969 CET487985683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:27.448297977 CET56834879885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:29.202039003 CET56834879885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:29.202634096 CET487985683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:29.207526922 CET56834879885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:30.205579996 CET488005683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:30.210555077 CET56834880085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:30.210634947 CET488005683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:30.210684061 CET488005683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:30.215482950 CET56834880085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:31.967643023 CET56834880085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:31.968144894 CET488005683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:31.972975969 CET56834880085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:32.970705986 CET488025683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:32.975558043 CET56834880285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:32.975631952 CET488025683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:32.975673914 CET488025683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:32.980680943 CET56834880285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:34.751262903 CET56834880285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:34.751526117 CET488025683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:34.756325006 CET56834880285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:35.754256010 CET488045683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:35.759253979 CET56834880485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:35.759346008 CET488045683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:35.759390116 CET488045683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:35.764210939 CET56834880485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:37.513057947 CET56834880485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:37.513412952 CET488045683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:37.518237114 CET56834880485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:38.515877962 CET488065683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:38.520839930 CET56834880685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:38.520941973 CET488065683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:38.521012068 CET488065683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:38.525835037 CET56834880685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:40.279452085 CET56834880685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:40.279850960 CET488065683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:40.284964085 CET56834880685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:41.282278061 CET488085683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:41.287250996 CET56834880885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:41.287322044 CET488085683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:41.287343025 CET488085683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:41.292221069 CET56834880885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:43.048300982 CET56834880885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:43.048563004 CET488085683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:43.053426981 CET56834880885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:44.051430941 CET488105683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:44.056554079 CET56834881085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:44.056629896 CET488105683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:44.056629896 CET488105683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:44.062156916 CET56834881085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:45.810188055 CET56834881085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:45.810441971 CET488105683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:45.815393925 CET56834881085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:46.813720942 CET488125683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:46.818640947 CET56834881285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:46.818737030 CET488125683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:46.818802118 CET488125683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:46.823661089 CET56834881285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:48.576953888 CET56834881285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:48.577224970 CET488125683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:48.582042933 CET56834881285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:49.579514980 CET488145683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:49.584547043 CET56834881485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:49.584650040 CET488145683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:49.584709883 CET488145683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:49.589566946 CET56834881485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:51.345309973 CET56834881485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:51.345602036 CET488145683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:51.350552082 CET56834881485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:52.348644972 CET488165683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:52.353554010 CET56834881685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:52.353696108 CET488165683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:52.353733063 CET488165683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:52.358551979 CET56834881685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:54.091834068 CET56834881685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:54.092004061 CET488165683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:54.096909046 CET56834881685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:55.094404936 CET488185683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:55.099303007 CET56834881885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:55.099430084 CET488185683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:55.099476099 CET488185683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:55.104242086 CET56834881885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:56.841236115 CET56834881885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:56.841665983 CET488185683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:56.846641064 CET56834881885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:57.843085051 CET488205683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:57.847975016 CET56834882085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:57.848104954 CET488205683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:57.848104954 CET488205683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:57.852926016 CET56834882085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:59.608937025 CET56834882085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:09:59.609477997 CET488205683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:09:59.614379883 CET56834882085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:10:00.611826897 CET488225683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:10:00.616851091 CET56834882285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:10:00.617043972 CET488225683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:10:00.617089987 CET488225683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:10:00.621886015 CET56834882285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:10:02.425661087 CET56834882285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:10:02.425997972 CET488225683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:10:02.430851936 CET56834882285.239.34.134192.168.2.23
                                          Jan 19, 2025 02:10:03.429004908 CET488245683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:10:03.434092045 CET56834882485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:10:03.434222937 CET488245683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:10:03.434269905 CET488245683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:10:03.439150095 CET56834882485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:10:05.209218025 CET56834882485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:10:05.209743023 CET488245683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:10:05.216804981 CET56834882485.239.34.134192.168.2.23
                                          Jan 19, 2025 02:10:06.212450027 CET488265683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:10:06.218038082 CET56834882685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:10:06.218159914 CET488265683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:10:06.218209982 CET488265683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:10:06.223403931 CET56834882685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:10:07.986550093 CET56834882685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:10:07.987118959 CET488265683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:10:07.992074966 CET56834882685.239.34.134192.168.2.23
                                          Jan 19, 2025 02:10:08.989752054 CET488285683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:10:08.994923115 CET56834882885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:10:08.995066881 CET488285683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:10:08.995106936 CET488285683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:10:09.000402927 CET56834882885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:10:10.767805099 CET56834882885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:10:10.767997026 CET488285683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:10:10.772948980 CET56834882885.239.34.134192.168.2.23
                                          Jan 19, 2025 02:10:11.770123005 CET488305683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:10:11.775496006 CET56834883085.239.34.134192.168.2.23
                                          Jan 19, 2025 02:10:11.775743008 CET488305683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:10:11.775743008 CET488305683192.168.2.2385.239.34.134
                                          Jan 19, 2025 02:10:11.780718088 CET56834883085.239.34.134192.168.2.23

                                          System Behavior

                                          Start time (UTC):01:08:05
                                          Start date (UTC):19/01/2025
                                          Path:/tmp/arm6.elf
                                          Arguments:/tmp/arm6.elf
                                          File size:4956856 bytes
                                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                          Start time (UTC):01:08:05
                                          Start date (UTC):19/01/2025
                                          Path:/tmp/arm6.elf
                                          Arguments:-
                                          File size:4956856 bytes
                                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                          Start time (UTC):01:08:05
                                          Start date (UTC):19/01/2025
                                          Path:/tmp/arm6.elf
                                          Arguments:-
                                          File size:4956856 bytes
                                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                          Start time (UTC):01:08:05
                                          Start date (UTC):19/01/2025
                                          Path:/tmp/arm6.elf
                                          Arguments:-
                                          File size:4956856 bytes
                                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                          Start time (UTC):01:08:05
                                          Start date (UTC):19/01/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "mkdir /mc8mav6i7g/ && >/mc8mav6i7g/mc8mav6i7g && cd /mc8mav6i7g/ >/dev/null"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):01:08:06
                                          Start date (UTC):19/01/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):01:08:06
                                          Start date (UTC):19/01/2025
                                          Path:/usr/bin/mkdir
                                          Arguments:mkdir /mc8mav6i7g/
                                          File size:88408 bytes
                                          MD5 hash:088c9d1df5a28ed16c726eca15964cb7

                                          Start time (UTC):01:08:06
                                          Start date (UTC):19/01/2025
                                          Path:/tmp/arm6.elf
                                          Arguments:-
                                          File size:4956856 bytes
                                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                          Start time (UTC):01:08:06
                                          Start date (UTC):19/01/2025
                                          Path:/bin/sh
                                          Arguments:sh -c "mv /tmp/arm6.elf /mc8mav6i7g/mc8mav6i7g && chmod 777 /mc8mav6i7g/mc8mav6i7g >/dev/null"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):01:08:06
                                          Start date (UTC):19/01/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):01:08:06
                                          Start date (UTC):19/01/2025
                                          Path:/usr/bin/mv
                                          Arguments:mv /tmp/arm6.elf /mc8mav6i7g/mc8mav6i7g
                                          File size:149888 bytes
                                          MD5 hash:504f0590fa482d4da070a702260e3716

                                          Start time (UTC):01:08:06
                                          Start date (UTC):19/01/2025
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):01:08:06
                                          Start date (UTC):19/01/2025
                                          Path:/usr/bin/chmod
                                          Arguments:chmod 777 /mc8mav6i7g/mc8mav6i7g
                                          File size:63864 bytes
                                          MD5 hash:739483b900c045ae1374d6f53a86a279