Edit tour

Linux Analysis Report
mips.elf

Overview

General Information

Sample name:mips.elf
Analysis ID:1594465
MD5:25d6f74cee520e07b91927f0dcf36bde
SHA1:adb7e1e0d463636fbea1a884b2764293f2d4c9f1
SHA256:d467ee63d44e1e601beb9ec8802eaeb4b6e9123a79b98c633d71c529d539e11e
Tags:elfuser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Detected TCP or UDP traffic on non-standard ports
Executes commands using a shell command-line interpreter
Executes the "chmod" command used to modify permissions
Executes the "mkdir" command used to create folders
Sample has stripped symbol table
Sample tries to set the executable flag
Sets full permissions to files and/or directories
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1594465
Start date and time:2025-01-19 02:12:10 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 47s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:mips.elf
Detection:MAL
Classification:mal48.linELF@0/0@0/0
Command:/tmp/mips.elf
PID:6244
Exit Code:1
Exit Code Info:
Killed:False
Standard Output:
GOLDFISHGANG
Standard Error:
  • system is lnxubuntu20
  • mips.elf (PID: 6244, Parent: 6165, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/mips.elf
    • mips.elf New Fork (PID: 6247, Parent: 6244)
      • mips.elf New Fork (PID: 6249, Parent: 6247)
        • mips.elf New Fork (PID: 6255, Parent: 6249)
        • sh (PID: 6255, Parent: 6249, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -c "mkdir /uc1b3ie67v/ && >/uc1b3ie67v/uc1b3ie67v && cd /uc1b3ie67v/ >/dev/null"
          • sh New Fork (PID: 6257, Parent: 6255)
          • mkdir (PID: 6257, Parent: 6255, MD5: 088c9d1df5a28ed16c726eca15964cb7) Arguments: mkdir /uc1b3ie67v/
        • mips.elf New Fork (PID: 6258, Parent: 6249)
        • sh (PID: 6258, Parent: 6249, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -c "mv /tmp/mips.elf /uc1b3ie67v/uc1b3ie67v && chmod 777 /uc1b3ie67v/uc1b3ie67v >/dev/null"
          • sh New Fork (PID: 6260, Parent: 6258)
          • mv (PID: 6260, Parent: 6258, MD5: 504f0590fa482d4da070a702260e3716) Arguments: mv /tmp/mips.elf /uc1b3ie67v/uc1b3ie67v
          • sh New Fork (PID: 6261, Parent: 6258)
          • chmod (PID: 6261, Parent: 6258, MD5: 739483b900c045ae1374d6f53a86a279) Arguments: chmod 777 /uc1b3ie67v/uc1b3ie67v
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: mips.elfReversingLabs: Detection: 50%
Source: global trafficTCP traffic: 192.168.2.23:48740 -> 85.239.34.134:5683
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.linELF@0/0@0/0
Source: /tmp/mips.elf (PID: 6255)Shell command executed: /bin/sh -c "mkdir /uc1b3ie67v/ && >/uc1b3ie67v/uc1b3ie67v && cd /uc1b3ie67v/ >/dev/null"Jump to behavior
Source: /tmp/mips.elf (PID: 6258)Shell command executed: /bin/sh -c "mv /tmp/mips.elf /uc1b3ie67v/uc1b3ie67v && chmod 777 /uc1b3ie67v/uc1b3ie67v >/dev/null"Jump to behavior
Source: /bin/sh (PID: 6261)Chmod executable: /usr/bin/chmod -> chmod 777 /uc1b3ie67v/uc1b3ie67vJump to behavior
Source: /bin/sh (PID: 6257)Mkdir executable: /usr/bin/mkdir -> mkdir /uc1b3ie67v/Jump to behavior
Source: /usr/bin/chmod (PID: 6261)File: /uc1b3ie67v/uc1b3ie67v (bits: - usr: rwx grp: rwx all: rwx)Jump to behavior
Source: /bin/sh (PID: 6261)Chmod executable with 777: /usr/bin/chmod -> chmod 777 /uc1b3ie67v/uc1b3ie67vJump to behavior
Source: /tmp/mips.elf (PID: 6244)Queries kernel information via 'uname': Jump to behavior
Source: mips.elf, 6244.1.0000562377afd000.0000562377b84000.rw-.sdmp, mips.elf, 6247.1.0000562377afd000.0000562377b84000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: mips.elf, 6244.1.00007fff0b80e000.00007fff0b82f000.rw-.sdmp, mips.elf, 6247.1.00007fff0b80e000.00007fff0b82f000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/mips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/mips.elf
Source: mips.elf, 6244.1.0000562377afd000.0000562377b84000.rw-.sdmp, mips.elf, 6247.1.0000562377afd000.0000562377b84000.rw-.sdmpBinary or memory string: w#V!/etc/qemu-binfmt/mips
Source: mips.elf, 6244.1.00007fff0b80e000.00007fff0b82f000.rw-.sdmp, mips.elf, 6247.1.00007fff0b80e000.00007fff0b82f000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid AccountsWindows Management Instrumentation1
Scripting
Path Interception2
File and Directory Permissions Modification
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1594465 Sample: mips.elf Startdate: 19/01/2025 Architecture: LINUX Score: 48 26 85.239.34.134, 48740, 48742, 48744 RAINBOW-HKRainbownetworklimitedHK Russian Federation 2->26 28 109.202.202.202, 80 INIT7CH Switzerland 2->28 30 2 other IPs or domains 2->30 32 Multi AV Scanner detection for submitted file 2->32 10 mips.elf 2->10         started        signatures3 process4 process5 12 mips.elf 10->12         started        process6 14 mips.elf 12->14         started        process7 16 mips.elf sh 14->16         started        18 mips.elf sh 14->18         started        process8 20 sh mv 16->20         started        22 sh chmod 16->22         started        24 sh mkdir 18->24         started       
SourceDetectionScannerLabelLink
mips.elf50%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
85.239.34.134
unknownRussian Federation
134121RAINBOW-HKRainbownetworklimitedHKfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
85.239.34.134arm6.elfGet hashmaliciousUnknownBrowse
    arm7.elfGet hashmaliciousUnknownBrowse
      ppc.elfGet hashmaliciousUnknownBrowse
        mips.elfGet hashmaliciousUnknownBrowse
          m68k.elfGet hashmaliciousUnknownBrowse
            sh4.elfGet hashmaliciousUnknownBrowse
              x86.elfGet hashmaliciousUnknownBrowse
                arm5.elfGet hashmaliciousUnknownBrowse
                  spc.elfGet hashmaliciousUnknownBrowse
                    harm.elfGet hashmaliciousUnknownBrowse
                      109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                      • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                      91.189.91.43arm6.elfGet hashmaliciousUnknownBrowse
                        na.elfGet hashmaliciousPrometeiBrowse
                          na.elfGet hashmaliciousPrometeiBrowse
                            bin.sh.elfGet hashmaliciousMiraiBrowse
                              sshd.elfGet hashmaliciousUnknownBrowse
                                na.elfGet hashmaliciousPrometeiBrowse
                                  sshd.elfGet hashmaliciousUnknownBrowse
                                    Mozi.m.elfGet hashmaliciousMiraiBrowse
                                      na.elfGet hashmaliciousPrometeiBrowse
                                        nabarm7.elfGet hashmaliciousUnknownBrowse
                                          91.189.91.42arm6.elfGet hashmaliciousUnknownBrowse
                                            na.elfGet hashmaliciousPrometeiBrowse
                                              na.elfGet hashmaliciousPrometeiBrowse
                                                bin.sh.elfGet hashmaliciousMiraiBrowse
                                                  sshd.elfGet hashmaliciousUnknownBrowse
                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                      sshd.elfGet hashmaliciousUnknownBrowse
                                                        Mozi.m.elfGet hashmaliciousMiraiBrowse
                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                            nabarm7.elfGet hashmaliciousUnknownBrowse
                                                              No context
                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                              RAINBOW-HKRainbownetworklimitedHKarm6.elfGet hashmaliciousUnknownBrowse
                                                              • 85.239.34.134
                                                              arm7.elfGet hashmaliciousUnknownBrowse
                                                              • 85.239.34.134
                                                              ppc.elfGet hashmaliciousUnknownBrowse
                                                              • 85.239.34.134
                                                              mips.elfGet hashmaliciousUnknownBrowse
                                                              • 85.239.34.134
                                                              m68k.elfGet hashmaliciousUnknownBrowse
                                                              • 85.239.34.134
                                                              sh4.elfGet hashmaliciousUnknownBrowse
                                                              • 85.239.34.134
                                                              x86.elfGet hashmaliciousUnknownBrowse
                                                              • 85.239.34.134
                                                              arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 85.239.34.134
                                                              spc.elfGet hashmaliciousUnknownBrowse
                                                              • 85.239.34.134
                                                              harm.elfGet hashmaliciousUnknownBrowse
                                                              • 85.239.34.134
                                                              CANONICAL-ASGBarm6.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              bin.sh.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              sshd.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              sshd.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              Mozi.m.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              nabarm7.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              CANONICAL-ASGBarm6.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              bin.sh.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              sshd.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              sshd.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              Mozi.m.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              nabarm7.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              INIT7CHarm6.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              bin.sh.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              sshd.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              sshd.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              Mozi.m.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              nabarm7.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              No context
                                                              No context
                                                              No created / dropped files found
                                                              File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                                              Entropy (8bit):5.558404149925746
                                                              TrID:
                                                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                              File name:mips.elf
                                                              File size:84'836 bytes
                                                              MD5:25d6f74cee520e07b91927f0dcf36bde
                                                              SHA1:adb7e1e0d463636fbea1a884b2764293f2d4c9f1
                                                              SHA256:d467ee63d44e1e601beb9ec8802eaeb4b6e9123a79b98c633d71c529d539e11e
                                                              SHA512:3beeead8c3c82a86493013e1c601eb8fb0bfa5bf18b55ebe82332f22d9a8c9bc7f32f9249604eba9a30420b1b55f241289025173849c12d2d0694e38b0291c42
                                                              SSDEEP:1536:aMn7tRJGxqu4vSiiOziDzFDsawmawDPQ8p1:aeGxX4vAOzKJsaswDQ8p1
                                                              TLSH:C783D61E2E118F6DF39CD63407FB1A2156A622D517F2C182E2ACD6102F6274E685FFE4
                                                              File Content Preview:.ELF.....................@.....4..H......4. ...(.............@...@....@H..@H..............@H.APH.APH...0..8...............@..AP..AP.................dt.Q............................<...'..L...!'.......................<...'..(...!........'9... .............

                                                              ELF header

                                                              Class:ELF32
                                                              Data:2's complement, big endian
                                                              Version:1 (current)
                                                              Machine:MIPS R3000
                                                              Version Number:0x1
                                                              Type:EXEC (Executable file)
                                                              OS/ABI:UNIX - System V
                                                              ABI Version:0
                                                              Entry Point Address:0x400290
                                                              Flags:0x1007
                                                              ELF Header Size:52
                                                              Program Header Offset:52
                                                              Program Header Size:32
                                                              Number of Program Headers:4
                                                              Section Header Offset:84196
                                                              Section Header Size:40
                                                              Number of Section Headers:16
                                                              Header String Table Index:15
                                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                              NULL0x00x00x00x00x0000
                                                              .initPROGBITS0x4000b40xb40x8c0x00x6AX004
                                                              .textPROGBITS0x4001400x1400x125e00x00x6AX0016
                                                              .finiPROGBITS0x4127200x127200x5c0x00x6AX004
                                                              .rodataPROGBITS0x4127800x127800x18c80x00x2A0016
                                                              .eh_framePROGBITS0x4150480x140480x440x00x3WA004
                                                              .tbssNOBITS0x41508c0x1408c0x80x00x403WAT004
                                                              .ctorsPROGBITS0x41508c0x1408c0x80x00x3WA004
                                                              .dtorsPROGBITS0x4150940x140940x80x00x3WA004
                                                              .jcrPROGBITS0x41509c0x1409c0x40x00x3WA004
                                                              .dataPROGBITS0x4150a00x140a00x2640x00x3WA0016
                                                              .gotPROGBITS0x4153100x143100x5680x40x10000003WAp0016
                                                              .sbssNOBITS0x4158780x148780x380x00x10000003WAp004
                                                              .bssNOBITS0x4158b00x148780x2fa80x00x3WA0016
                                                              .mdebug.abi32PROGBITS0xad40x148780x00x00x0001
                                                              .shstrtabSTRTAB0x00x148780x6c0x00x0001
                                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                              LOAD0x00x4000000x4000000x140480x140485.58390x5R E0x1000.init .text .fini .rodata
                                                              LOAD0x140480x4150480x4150480x8300x38104.06650x6RW 0x1000.eh_frame .tbss .ctors .dtors .jcr .data .got .sbss .bss
                                                              TLS0x1408c0x41508c0x41508c0x00x80.00000x4R 0x4.tbss
                                                              GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                                                              Download Network PCAP: filteredfull

                                                              • Total Packets: 190
                                                              • 5683 undefined
                                                              • 443 (HTTPS)
                                                              • 80 (HTTP)
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Jan 19, 2025 02:12:56.887978077 CET43928443192.168.2.2391.189.91.42
                                                              Jan 19, 2025 02:12:58.640800953 CET487405683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:12:58.672941923 CET56834874085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:12:58.673118114 CET487405683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:12:58.673367977 CET487405683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:12:58.678183079 CET56834874085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:00.425345898 CET56834874085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:00.426244974 CET487405683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:00.431476116 CET56834874085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:01.428697109 CET487425683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:01.434736967 CET56834874285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:01.434830904 CET487425683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:01.434849024 CET487425683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:01.441426039 CET56834874285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:02.263360977 CET42836443192.168.2.2391.189.91.43
                                                              Jan 19, 2025 02:13:03.240417957 CET56834874285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:03.241022110 CET487425683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:03.245939016 CET56834874285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:03.287358046 CET4251680192.168.2.23109.202.202.202
                                                              Jan 19, 2025 02:13:04.242327929 CET487445683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:04.249037027 CET56834874485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:04.249135971 CET487445683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:04.249185085 CET487445683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:04.255665064 CET56834874485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:06.025901079 CET56834874485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:06.026454926 CET487445683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:06.031630993 CET56834874485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:07.028549910 CET487465683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:07.033515930 CET56834874685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:07.033658981 CET487465683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:07.033718109 CET487465683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:07.038543940 CET56834874685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:08.801178932 CET56834874685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:08.801553965 CET487465683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:08.807152987 CET56834874685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:09.802946091 CET487485683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:09.808648109 CET56834874885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:09.808773994 CET487485683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:09.808811903 CET487485683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:09.815303087 CET56834874885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:11.564377069 CET56834874885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:11.564821959 CET487485683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:11.569688082 CET56834874885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:12.568433046 CET487505683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:12.573513031 CET56834875085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:12.573674917 CET487505683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:12.573821068 CET487505683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:12.578680038 CET56834875085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:14.334918976 CET56834875085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:14.335696936 CET487505683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:14.340626955 CET56834875085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:15.337680101 CET487525683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:15.342506886 CET56834875285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:15.342595100 CET487525683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:15.342663050 CET487525683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:15.347522974 CET56834875285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:17.098134041 CET56834875285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:17.098381042 CET487525683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:17.103220940 CET56834875285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:17.365302086 CET43928443192.168.2.2391.189.91.42
                                                              Jan 19, 2025 02:13:18.100224018 CET487545683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:18.105190992 CET56834875485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:18.105292082 CET487545683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:18.105362892 CET487545683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:18.110143900 CET56834875485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:19.882550001 CET56834875485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:19.883065939 CET487545683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:19.888027906 CET56834875485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:20.885173082 CET487565683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:20.890213013 CET56834875685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:20.890330076 CET487565683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:20.890330076 CET487565683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:20.895169020 CET56834875685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:22.647231102 CET56834875685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:22.647511959 CET487565683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:22.652427912 CET56834875685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:23.649698019 CET487585683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:23.654630899 CET56834875885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:23.654704094 CET487585683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:23.654757977 CET487585683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:23.659562111 CET56834875885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:25.395670891 CET56834875885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:25.396047115 CET487585683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:25.400861979 CET56834875885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:26.398489952 CET487605683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:26.404895067 CET56834876085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:26.404989958 CET487605683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:26.405025959 CET487605683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:26.412465096 CET56834876085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:28.142996073 CET56834876085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:28.143415928 CET487605683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:28.148349047 CET56834876085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:29.145747900 CET487625683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:29.335643053 CET56834876285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:29.335803032 CET487625683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:29.335850954 CET487625683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:29.340665102 CET56834876285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:29.651629925 CET42836443192.168.2.2391.189.91.43
                                                              Jan 19, 2025 02:13:31.100997925 CET56834876285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:31.101505995 CET487625683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:31.107775927 CET56834876285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:32.104449987 CET487645683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:32.109272957 CET56834876485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:32.109349966 CET487645683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:32.109411955 CET487645683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:32.114144087 CET56834876485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:33.747026920 CET4251680192.168.2.23109.202.202.202
                                                              Jan 19, 2025 02:13:33.864120007 CET56834876485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:33.864470005 CET487645683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:33.869292974 CET56834876485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:34.866890907 CET487665683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:34.873951912 CET56834876685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:34.874036074 CET487665683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:34.874080896 CET487665683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:34.878818989 CET56834876685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:36.629281998 CET56834876685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:36.629553080 CET487665683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:36.634414911 CET56834876685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:37.631357908 CET487685683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:37.636558056 CET56834876885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:37.636635065 CET487685683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:37.636687994 CET487685683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:37.641426086 CET56834876885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:39.395737886 CET56834876885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:39.396140099 CET487685683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:39.401014090 CET56834876885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:40.399491072 CET487705683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:40.404450893 CET56834877085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:40.404551029 CET487705683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:40.404611111 CET487705683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:40.409404039 CET56834877085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:42.159483910 CET56834877085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:42.159900904 CET487705683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:42.164736032 CET56834877085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:43.163121939 CET487725683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:43.168436050 CET56834877285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:43.168520927 CET487725683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:43.168591022 CET487725683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:43.174452066 CET56834877285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:44.924709082 CET56834877285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:44.925087929 CET487725683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:44.930068016 CET56834877285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:45.927330017 CET487745683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:45.932425022 CET56834877485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:45.932517052 CET487745683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:45.932596922 CET487745683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:45.937412977 CET56834877485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:47.696064949 CET56834877485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:47.696491003 CET487745683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:47.702330112 CET56834877485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:48.698554993 CET487765683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:48.703679085 CET56834877685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:48.703768969 CET487765683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:48.703835964 CET487765683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:48.708754063 CET56834877685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:50.456587076 CET56834877685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:50.457035065 CET487765683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:50.464947939 CET56834877685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:51.461075068 CET487785683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:51.466173887 CET56834877885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:51.466264009 CET487785683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:51.466320038 CET487785683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:51.471194983 CET56834877885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:53.221621990 CET56834877885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:53.222012997 CET487785683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:53.227005005 CET56834877885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:54.225004911 CET487805683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:54.308904886 CET56834878085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:54.309201002 CET487805683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:54.309281111 CET487805683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:54.314138889 CET56834878085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:56.067920923 CET56834878085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:56.068188906 CET487805683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:56.073100090 CET56834878085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:57.070118904 CET487825683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:57.075198889 CET56834878285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:57.075301886 CET487825683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:57.075350046 CET487825683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:57.080233097 CET56834878285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:58.319878101 CET43928443192.168.2.2391.189.91.42
                                                              Jan 19, 2025 02:13:58.816281080 CET56834878285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:58.816564083 CET487825683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:58.821463108 CET56834878285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:59.819175959 CET487845683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:59.825413942 CET56834878485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:13:59.825572968 CET487845683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:59.825573921 CET487845683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:13:59.830712080 CET56834878485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:01.603213072 CET56834878485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:01.603806973 CET487845683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:01.608722925 CET56834878485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:02.607218981 CET487865683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:02.612524986 CET56834878685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:02.612673998 CET487865683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:02.612715006 CET487865683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:02.618118048 CET56834878685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:04.380466938 CET56834878685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:04.380772114 CET487865683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:04.385610104 CET56834878685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:05.382081032 CET487885683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:05.387095928 CET56834878885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:05.387201071 CET487885683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:05.387248993 CET487885683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:05.392052889 CET56834878885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:07.146336079 CET56834878885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:07.146858931 CET487885683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:07.151917934 CET56834878885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:08.151154995 CET487905683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:08.156450987 CET56834879085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:08.156939983 CET487905683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:08.156939983 CET487905683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:08.161883116 CET56834879085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:09.929939985 CET56834879085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:09.930341005 CET487905683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:09.935244083 CET56834879085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:10.932226896 CET487925683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:10.937218904 CET56834879285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:10.937357903 CET487925683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:10.937398911 CET487925683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:10.942214012 CET56834879285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:12.730201006 CET56834879285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:12.730742931 CET487925683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:12.736037970 CET56834879285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:13.734462976 CET487945683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:13.739578009 CET56834879485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:13.739788055 CET487945683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:13.739788055 CET487945683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:13.744657993 CET56834879485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:15.505637884 CET56834879485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:15.505965948 CET487945683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:15.510888100 CET56834879485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:16.508172989 CET487965683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:16.514761925 CET56834879685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:16.514884949 CET487965683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:16.514931917 CET487965683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:16.521127939 CET56834879685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:18.269800901 CET56834879685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:18.270219088 CET487965683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:18.275192022 CET56834879685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:19.273853064 CET487985683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:19.366415977 CET56834879885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:19.366743088 CET487985683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:19.366966009 CET487985683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:19.371880054 CET56834879885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:21.129852057 CET56834879885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:21.130300999 CET487985683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:21.135081053 CET56834879885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:22.132617950 CET488005683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:22.137619019 CET56834880085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:22.137691021 CET488005683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:22.137764931 CET488005683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:22.143825054 CET56834880085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:24.357374907 CET56834880085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:24.357666969 CET56834880085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:24.357809067 CET488005683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:24.357827902 CET56834880085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:24.357848883 CET488005683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:24.357878923 CET488005683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:24.362735033 CET56834880085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:25.361268044 CET488025683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:25.462914944 CET56834880285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:25.463134050 CET488025683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:25.463211060 CET488025683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:25.468061924 CET56834880285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:27.225044012 CET56834880285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:27.225483894 CET488025683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:27.230618000 CET56834880285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:28.228475094 CET488045683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:28.233653069 CET56834880485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:28.233784914 CET488045683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:28.233827114 CET488045683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:28.239168882 CET56834880485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:30.010098934 CET56834880485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:30.010458946 CET488045683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:30.015444040 CET56834880485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:31.013374090 CET488065683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:31.018621922 CET56834880685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:31.018735886 CET488065683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:31.018802881 CET488065683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:31.023649931 CET56834880685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:32.770854950 CET56834880685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:32.771167994 CET488065683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:32.776154995 CET56834880685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:33.774224043 CET488085683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:33.779381037 CET56834880885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:33.779454947 CET488085683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:33.779508114 CET488085683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:33.784370899 CET56834880885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:35.536057949 CET56834880885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:35.536436081 CET488085683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:35.541627884 CET56834880885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:36.541959047 CET488105683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:36.547043085 CET56834881085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:36.547127008 CET488105683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:36.547198057 CET488105683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:36.552062035 CET56834881085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:38.322801113 CET56834881085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:38.323606014 CET488105683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:38.329075098 CET56834881085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:39.328044891 CET488125683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:39.333137035 CET56834881285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:39.333231926 CET488125683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:39.333273888 CET488125683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:39.338113070 CET56834881285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:41.100708961 CET56834881285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:41.101284981 CET488125683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:41.106688023 CET56834881285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:42.104542017 CET488145683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:42.109940052 CET56834881485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:42.110055923 CET488145683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:42.110100985 CET488145683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:42.114995956 CET56834881485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:43.864136934 CET56834881485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:43.864512920 CET488145683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:43.869491100 CET56834881485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:44.867211103 CET488165683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:44.872437954 CET56834881685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:44.872589111 CET488165683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:44.872626066 CET488165683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:44.877512932 CET56834881685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:46.729099035 CET56834881685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:46.729485989 CET488165683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:46.734397888 CET56834881685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:47.732912064 CET488185683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:47.738290071 CET56834881885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:47.738405943 CET488185683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:47.738547087 CET488185683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:47.743459940 CET56834881885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:49.489445925 CET56834881885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:49.489653111 CET488185683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:49.494862080 CET56834881885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:50.493618965 CET488205683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:50.498641014 CET56834882085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:50.498867035 CET488205683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:50.499064922 CET488205683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:50.503849030 CET56834882085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:52.274780035 CET56834882085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:52.275384903 CET488205683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:52.280328989 CET56834882085.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:53.278008938 CET488225683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:53.283204079 CET56834882285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:53.283333063 CET488225683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:53.283385992 CET488225683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:53.288199902 CET56834882285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:55.021764994 CET56834882285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:55.022300959 CET488225683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:55.028598070 CET56834882285.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:56.027821064 CET488245683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:56.033205032 CET56834882485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:56.033442974 CET488245683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:56.033543110 CET488245683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:56.038408995 CET56834882485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:57.785803080 CET56834882485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:57.786428928 CET488245683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:57.791379929 CET56834882485.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:58.791944981 CET488265683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:58.797146082 CET56834882685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:14:58.797405958 CET488265683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:58.797405958 CET488265683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:14:58.802335024 CET56834882685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:15:00.571290970 CET56834882685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:15:00.571743965 CET488265683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:15:00.576750040 CET56834882685.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:15:01.576823950 CET488285683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:15:01.581928015 CET56834882885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:15:01.582104921 CET488285683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:15:01.582124949 CET488285683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:15:01.586980104 CET56834882885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:15:03.593645096 CET56834882885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:15:03.594156981 CET56834882885.239.34.134192.168.2.23
                                                              Jan 19, 2025 02:15:03.594180107 CET488285683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:15:03.594253063 CET488285683192.168.2.2385.239.34.134
                                                              Jan 19, 2025 02:15:03.599013090 CET56834882885.239.34.134192.168.2.23

                                                              System Behavior

                                                              Start time (UTC):01:12:56
                                                              Start date (UTC):19/01/2025
                                                              Path:/tmp/mips.elf
                                                              Arguments:/tmp/mips.elf
                                                              File size:5777432 bytes
                                                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                              Start time (UTC):01:12:57
                                                              Start date (UTC):19/01/2025
                                                              Path:/tmp/mips.elf
                                                              Arguments:-
                                                              File size:5777432 bytes
                                                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                              Start time (UTC):01:12:57
                                                              Start date (UTC):19/01/2025
                                                              Path:/tmp/mips.elf
                                                              Arguments:-
                                                              File size:5777432 bytes
                                                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                              Start time (UTC):01:12:57
                                                              Start date (UTC):19/01/2025
                                                              Path:/tmp/mips.elf
                                                              Arguments:-
                                                              File size:5777432 bytes
                                                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                              Start time (UTC):01:12:57
                                                              Start date (UTC):19/01/2025
                                                              Path:/bin/sh
                                                              Arguments:/bin/sh -c "mkdir /uc1b3ie67v/ && >/uc1b3ie67v/uc1b3ie67v && cd /uc1b3ie67v/ >/dev/null"
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):01:12:57
                                                              Start date (UTC):19/01/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):01:12:57
                                                              Start date (UTC):19/01/2025
                                                              Path:/usr/bin/mkdir
                                                              Arguments:mkdir /uc1b3ie67v/
                                                              File size:88408 bytes
                                                              MD5 hash:088c9d1df5a28ed16c726eca15964cb7

                                                              Start time (UTC):01:12:57
                                                              Start date (UTC):19/01/2025
                                                              Path:/tmp/mips.elf
                                                              Arguments:-
                                                              File size:5777432 bytes
                                                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                              Start time (UTC):01:12:57
                                                              Start date (UTC):19/01/2025
                                                              Path:/bin/sh
                                                              Arguments:/bin/sh -c "mv /tmp/mips.elf /uc1b3ie67v/uc1b3ie67v && chmod 777 /uc1b3ie67v/uc1b3ie67v >/dev/null"
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):01:12:57
                                                              Start date (UTC):19/01/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):01:12:57
                                                              Start date (UTC):19/01/2025
                                                              Path:/usr/bin/mv
                                                              Arguments:mv /tmp/mips.elf /uc1b3ie67v/uc1b3ie67v
                                                              File size:149888 bytes
                                                              MD5 hash:504f0590fa482d4da070a702260e3716

                                                              Start time (UTC):01:12:57
                                                              Start date (UTC):19/01/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):01:12:57
                                                              Start date (UTC):19/01/2025
                                                              Path:/usr/bin/chmod
                                                              Arguments:chmod 777 /uc1b3ie67v/uc1b3ie67v
                                                              File size:63864 bytes
                                                              MD5 hash:739483b900c045ae1374d6f53a86a279