Edit tour

Linux Analysis Report
phantom.arm.elf

Overview

General Information

Sample name:phantom.arm.elf
Analysis ID:1622366
MD5:c21712b381f9a30c8b76e8226f75f881
SHA1:f33d84ad0dd0c9de63009fca412865e1c664f577
SHA256:edf1fa8d679b441c1abeb970dd95035de48d2af6b781c4e77de718b1f3772670
Tags:elfuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1622366
Start date and time:2025-02-23 20:33:17 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 6m 19s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:phantom.arm.elf
Detection:MAL
Classification:mal56.linELF@0/0@2/0
Command:/tmp/phantom.arm.elf
PID:5539
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
OWARI09123id9i123xd912
Standard Error:
  • system is lnxubuntu20
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: phantom.arm.elfAvira: detected
Source: phantom.arm.elfVirustotal: Detection: 55%Perma Link
Source: phantom.arm.elfReversingLabs: Detection: 65%
Source: global trafficTCP traffic: 192.168.2.15:40118 -> 194.85.251.76:1999
Source: /tmp/phantom.arm.elf (PID: 5541)Socket: 0.0.0.0:0Jump to behavior
Source: /tmp/phantom.arm.elf (PID: 5547)Socket: 0.0.0.0:0Jump to behavior
Source: /tmp/phantom.arm.elf (PID: 5547)Socket: 0.0.0.0:53413Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: unknownTCP traffic detected without corresponding DNS query: 194.85.251.76
Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal56.linELF@0/0@2/0
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/5541/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3241/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3483/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1732/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1730/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1333/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1695/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3235/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3234/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1617/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1615/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/917/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3890/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/5551/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3255/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3253/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1591/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3252/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3251/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3250/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1623/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1588/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3249/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/764/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3368/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1585/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3246/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3488/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/766/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/800/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/888/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/5544/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/802/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1509/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/803/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/5547/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/804/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1867/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3407/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1484/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/490/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1514/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1634/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1479/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3379/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/931/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/777/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1595/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/658/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/779/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/812/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/933/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3419/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3310/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3275/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3274/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3273/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3394/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3272/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/782/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3303/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1762/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3027/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1486/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/789/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1806/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1660/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3044/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3440/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/793/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/794/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3316/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/796/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1498/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1497/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3157/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1496/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3278/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3399/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1659/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3332/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3210/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3298/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3055/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3052/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3292/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1701/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1666/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3205/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3047/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3201/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/723/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/724/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1704/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1669/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3060/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/1440/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3222/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3188/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3220/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3461/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3064/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3062/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5541)File opened: /proc/3183/fdJump to behavior
Source: /tmp/phantom.arm.elf (PID: 5539)Queries kernel information via 'uname': Jump to behavior
Source: phantom.arm.elf, 5539.1.00005632a532f000.00005632a545d000.rw-.sdmp, phantom.arm.elf, 5541.1.00005632a532f000.00005632a545d000.rw-.sdmp, phantom.arm.elf, 5652.1.00005632a532f000.00005632a545d000.rw-.sdmp, phantom.arm.elf, 5677.1.00005632a532f000.00005632a545d000.rw-.sdmp, phantom.arm.elf, 5660.1.00005632a532f000.00005632a545d000.rw-.sdmp, phantom.arm.elf, 5542.1.00005632a532f000.00005632a545d000.rw-.sdmp, phantom.arm.elf, 5651.1.00005632a532f000.00005632a545d000.rw-.sdmp, phantom.arm.elf, 5548.1.00005632a532f000.00005632a545d000.rw-.sdmpBinary or memory string: 2V!/etc/qemu-binfmt/arm
Source: phantom.arm.elf, 5539.1.00007ffebe221000.00007ffebe242000.rw-.sdmp, phantom.arm.elf, 5541.1.00007ffebe221000.00007ffebe242000.rw-.sdmp, phantom.arm.elf, 5652.1.00007ffebe221000.00007ffebe242000.rw-.sdmp, phantom.arm.elf, 5677.1.00007ffebe221000.00007ffebe242000.rw-.sdmp, phantom.arm.elf, 5660.1.00007ffebe221000.00007ffebe242000.rw-.sdmp, phantom.arm.elf, 5542.1.00007ffebe221000.00007ffebe242000.rw-.sdmp, phantom.arm.elf, 5651.1.00007ffebe221000.00007ffebe242000.rw-.sdmp, phantom.arm.elf, 5548.1.00007ffebe221000.00007ffebe242000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/phantom.arm.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/phantom.arm.elf
Source: phantom.arm.elf, 5539.1.00005632a532f000.00005632a545d000.rw-.sdmp, phantom.arm.elf, 5541.1.00005632a532f000.00005632a545d000.rw-.sdmp, phantom.arm.elf, 5652.1.00005632a532f000.00005632a545d000.rw-.sdmp, phantom.arm.elf, 5677.1.00005632a532f000.00005632a545d000.rw-.sdmp, phantom.arm.elf, 5660.1.00005632a532f000.00005632a545d000.rw-.sdmp, phantom.arm.elf, 5542.1.00005632a532f000.00005632a545d000.rw-.sdmp, phantom.arm.elf, 5651.1.00005632a532f000.00005632a545d000.rw-.sdmp, phantom.arm.elf, 5548.1.00005632a532f000.00005632a545d000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: phantom.arm.elf, 5539.1.00007ffebe221000.00007ffebe242000.rw-.sdmp, phantom.arm.elf, 5541.1.00007ffebe221000.00007ffebe242000.rw-.sdmp, phantom.arm.elf, 5652.1.00007ffebe221000.00007ffebe242000.rw-.sdmp, phantom.arm.elf, 5677.1.00007ffebe221000.00007ffebe242000.rw-.sdmp, phantom.arm.elf, 5660.1.00007ffebe221000.00007ffebe242000.rw-.sdmp, phantom.arm.elf, 5542.1.00007ffebe221000.00007ffebe242000.rw-.sdmp, phantom.arm.elf, 5651.1.00007ffebe221000.00007ffebe242000.rw-.sdmp, phantom.arm.elf, 5548.1.00007ffebe221000.00007ffebe242000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume Access1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1622366 Sample: phantom.arm.elf Startdate: 23/02/2025 Architecture: LINUX Score: 56 42 194.85.251.76, 1999, 40118, 40120 DATACENTERRO Russian Federation 2->42 44 daisy.ubuntu.com 2->44 46 Antivirus / Scanner detection for submitted sample 2->46 48 Multi AV Scanner detection for submitted file 2->48 10 phantom.arm.elf 2->10         started        signatures3 process4 process5 12 phantom.arm.elf 10->12         started        14 phantom.arm.elf 10->14         started        16 phantom.arm.elf 10->16         started        process6 18 phantom.arm.elf 12->18         started        20 phantom.arm.elf 12->20         started        22 phantom.arm.elf 14->22         started        24 phantom.arm.elf 14->24         started        26 phantom.arm.elf 14->26         started        process7 28 phantom.arm.elf 18->28         started        30 phantom.arm.elf 18->30         started        32 phantom.arm.elf 18->32         started        34 phantom.arm.elf 22->34         started        36 phantom.arm.elf 22->36         started        process8 38 phantom.arm.elf 28->38         started        40 phantom.arm.elf 28->40         started       
SourceDetectionScannerLabelLink
phantom.arm.elf56%VirustotalBrowse
phantom.arm.elf66%ReversingLabsLinux.Trojan.Mirai
phantom.arm.elf100%AviraEXP/ELF.Mirai.Bootnet.o
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
daisy.ubuntu.com
162.213.35.25
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    194.85.251.76
    unknownRussian Federation
    35478DATACENTERROfalse
    No context
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    daisy.ubuntu.com3atoNational.mpsl7.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.25
    3atoNational.arm67.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.24
    tftp.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.24
    sshd.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.25
    ftp.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.25
    wget.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.25
    pftp.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.25
    cron.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.24
    ntpd.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.24
    sh.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.24
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    DATACENTERROboatnet.x86.elfGet hashmaliciousMiraiBrowse
    • 193.32.162.38
    boatnet.sh4.elfGet hashmaliciousMiraiBrowse
    • 193.32.162.38
    boatnet.ppc.elfGet hashmaliciousMiraiBrowse
    • 193.32.162.38
    boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
    • 193.32.162.38
    boatnet.m68k.elfGet hashmaliciousMiraiBrowse
    • 193.32.162.38
    boatnet.arm.elfGet hashmaliciousMiraiBrowse
    • 193.32.162.38
    boatnet.mips.elfGet hashmaliciousMiraiBrowse
    • 193.32.162.38
    boatnet.spc.elfGet hashmaliciousMiraiBrowse
    • 193.32.162.38
    193.32.162.38-boatnet.arm7-2025-02-18T00_55_21.elfGet hashmaliciousMiraiBrowse
    • 193.32.162.38
    dd.elfGet hashmaliciousUnknownBrowse
    • 2.57.122.74
    No context
    No context
    No created / dropped files found
    File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
    Entropy (8bit):5.948391309176981
    TrID:
    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
    File name:phantom.arm.elf
    File size:55'580 bytes
    MD5:c21712b381f9a30c8b76e8226f75f881
    SHA1:f33d84ad0dd0c9de63009fca412865e1c664f577
    SHA256:edf1fa8d679b441c1abeb970dd95035de48d2af6b781c4e77de718b1f3772670
    SHA512:d83528751de608237f482b6547f3c3d6bda99df0fdce8d38c3a94ccdaa6e811fe6c76c82d95fdaed075d01385159db424b0e2ff4483ddc4fe1a90d43c9745da0
    SSDEEP:768:drfLVUPQD0EeabOtM2dHy5F2QKbtIvdEhx/kR8cWiov6dC8jpERC+CSUgPN+Nq9l:RVpBeGXKbg0OGiov8WRCo582
    TLSH:E9430AC27881A622C7D05377FE5F018E33165798E1EA33538D291FA47B8AD1F0DAB652
    File Content Preview:.ELF...a..........(.........4...........4. ...(.....................................................t...t...........Q.td..................................-...L."....3..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

    ELF header

    Class:ELF32
    Data:2's complement, little endian
    Version:1 (current)
    Machine:ARM
    Version Number:0x1
    Type:EXEC (Executable file)
    OS/ABI:ARM - ABI
    ABI Version:0
    Entry Point Address:0x8190
    Flags:0x202
    ELF Header Size:52
    Program Header Offset:52
    Program Header Size:32
    Number of Program Headers:3
    Section Header Offset:55180
    Section Header Size:40
    Number of Section Headers:10
    Header String Table Index:9
    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
    NULL0x00x00x00x00x0000
    .initPROGBITS0x80940x940x180x00x6AX004
    .textPROGBITS0x80b00xb00xd00c0x00x6AX0016
    .finiPROGBITS0x150bc0xd0bc0x140x00x6AX004
    .rodataPROGBITS0x150d00xd0d00x5040x00x2A004
    .ctorsPROGBITS0x1d5d80xd5d80x80x00x3WA004
    .dtorsPROGBITS0x1d5e00xd5e00x80x00x3WA004
    .dataPROGBITS0x1d5ec0xd5ec0x1600x00x3WA004
    .bssNOBITS0x1d74c0xd74c0x2000x00x3WA004
    .shstrtabSTRTAB0x00xd74c0x3e0x00x0001
    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
    LOAD0x00x80000x80000xd5d40xd5d45.97950x5R E0x8000.init .text .fini .rodata
    LOAD0xd5d80x1d5d80x1d5d80x1740x3740.82620x6RW 0x8000.ctors .dtors .data .bss
    GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

    Download Network PCAP: filteredfull

    • Total Packets: 314
    • 1999 undefined
    • 53 (DNS)
    TimestampSource PortDest PortSource IPDest IP
    Feb 23, 2025 20:34:09.449187994 CET401181999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:09.454374075 CET199940118194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:09.454432011 CET401181999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:09.490417004 CET401181999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:09.495537996 CET199940118194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:09.495588064 CET401181999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:09.500581026 CET199940118194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:10.082026005 CET199940118194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:10.082304955 CET401181999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:10.082304955 CET401181999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:10.083044052 CET401201999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:10.090046883 CET199940120194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:10.090127945 CET401201999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:10.091063023 CET401201999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:10.097188950 CET199940120194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:10.097240925 CET401201999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:10.102229118 CET199940120194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:10.720901012 CET199940120194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:10.721039057 CET401201999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:10.721039057 CET401201999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:10.721767902 CET401221999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:10.726788998 CET199940122194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:10.726840973 CET401221999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:10.727598906 CET401221999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:10.732598066 CET199940122194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:10.732650995 CET401221999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:10.737586975 CET199940122194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:11.349334955 CET199940122194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:11.349536896 CET401221999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:11.349536896 CET401221999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:11.350079060 CET401241999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:11.355103016 CET199940124194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:11.355148077 CET401241999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:11.356029034 CET401241999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:11.361094952 CET199940124194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:11.361205101 CET401241999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:11.366281986 CET199940124194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:11.981746912 CET199940124194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:11.981928110 CET401241999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:11.981987953 CET401241999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:11.982784986 CET401261999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:11.990123034 CET199940126194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:11.990210056 CET401261999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:11.991353989 CET401261999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:11.998286009 CET199940126194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:11.998352051 CET401261999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:12.005665064 CET199940126194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:12.638410091 CET199940126194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:12.638653994 CET401261999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:12.638653994 CET401261999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:12.639513016 CET401281999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:12.644603968 CET199940128194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:12.644656897 CET401281999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:12.645556927 CET401281999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:12.650576115 CET199940128194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:12.650691986 CET401281999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:12.655692101 CET199940128194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:13.269463062 CET199940128194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:13.269886971 CET401281999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:13.269886971 CET401281999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:13.270643950 CET401301999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:13.275697947 CET199940130194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:13.275762081 CET401301999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:13.276736021 CET401301999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:13.281747103 CET199940130194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:13.281817913 CET401301999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:13.286851883 CET199940130194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:13.899657965 CET199940130194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:13.899950027 CET401301999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:13.899950027 CET401301999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:13.900685072 CET401321999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:13.905812979 CET199940132194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:13.905874014 CET401321999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:13.906891108 CET401321999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:13.911951065 CET199940132194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:13.912034988 CET401321999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:13.917099953 CET199940132194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:14.530342102 CET199940132194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:14.530405045 CET401321999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:14.530464888 CET401321999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:14.531454086 CET401341999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:14.536576986 CET199940134194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:14.536638975 CET401341999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:14.538970947 CET401341999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:14.544003010 CET199940134194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:14.544054985 CET401341999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:14.549115896 CET199940134194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:15.189958096 CET199940134194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:15.190033913 CET401341999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:15.190097094 CET401341999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:15.191023111 CET401361999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:15.196386099 CET199940136194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:15.196441889 CET401361999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:15.198501110 CET401361999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:15.204034090 CET199940136194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:15.204082012 CET401361999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:15.209378958 CET199940136194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:15.840718985 CET199940136194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:15.840787888 CET401361999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:15.840898991 CET401361999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:15.842611074 CET401381999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:15.847667933 CET199940138194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:15.847786903 CET401381999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:15.853136063 CET401381999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:15.858225107 CET199940138194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:15.858279943 CET401381999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:15.863334894 CET199940138194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:16.472511053 CET199940138194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:16.472652912 CET401381999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:16.472652912 CET401381999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:16.473762989 CET401401999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:16.479734898 CET199940140194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:16.479792118 CET401401999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:16.482146978 CET401401999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:16.487246037 CET199940140194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:16.487298012 CET401401999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:16.493577957 CET199940140194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:17.105575085 CET199940140194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:17.105652094 CET401401999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:17.105701923 CET401401999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:17.107108116 CET401421999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:17.113414049 CET199940142194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:17.113473892 CET401421999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:17.116436005 CET401421999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:17.121514082 CET199940142194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:17.121565104 CET401421999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:17.127578020 CET199940142194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:17.802015066 CET199940142194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:17.802161932 CET401421999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:17.802206993 CET401421999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:17.863666058 CET401441999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:17.868885994 CET199940144194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:17.868940115 CET401441999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:17.873476982 CET401441999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:17.879642963 CET199940144194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:17.879714966 CET401441999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:17.885389090 CET199940144194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:18.581186056 CET199940144194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:18.581254959 CET401441999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:18.581310034 CET401441999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:18.582480907 CET401461999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:18.587548018 CET199940146194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:18.587621927 CET401461999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:18.590197086 CET401461999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:18.595242977 CET199940146194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:18.595294952 CET401461999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:18.600342989 CET199940146194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:19.240434885 CET199940146194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:19.240539074 CET401461999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:19.240539074 CET401461999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:19.242340088 CET401481999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:19.247823954 CET199940148194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:19.247881889 CET401481999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:19.251182079 CET401481999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:19.256614923 CET199940148194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:19.256664991 CET401481999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:19.263124943 CET199940148194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:19.882883072 CET199940148194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:19.883133888 CET401481999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:19.883240938 CET401481999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:19.928102970 CET401501999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:19.933264971 CET199940150194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:19.933593988 CET401501999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:20.072336912 CET401501999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:20.078960896 CET199940150194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:20.079013109 CET401501999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:20.084156990 CET199940150194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:20.558558941 CET199940150194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:20.558661938 CET401501999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:20.558662891 CET401501999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:20.559997082 CET401521999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:20.565017939 CET199940152194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:20.565084934 CET401521999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:20.567579031 CET401521999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:20.572593927 CET199940152194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:20.572640896 CET401521999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:20.578658104 CET199940152194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:21.219288111 CET199940152194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:21.219527006 CET401521999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:21.219527006 CET401521999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:21.220204115 CET401541999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:21.225265026 CET199940154194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:21.225343943 CET401541999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:21.226370096 CET401541999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:21.231401920 CET199940154194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:21.231458902 CET401541999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:21.236483097 CET199940154194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:31.232646942 CET401541999192.168.2.15194.85.251.76
    Feb 23, 2025 20:34:31.237890959 CET199940154194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:31.416434050 CET199940154194.85.251.76192.168.2.15
    Feb 23, 2025 20:34:31.417161942 CET401541999192.168.2.15194.85.251.76
    Feb 23, 2025 20:35:31.467401028 CET401541999192.168.2.15194.85.251.76
    Feb 23, 2025 20:35:31.472537041 CET199940154194.85.251.76192.168.2.15
    Feb 23, 2025 20:35:31.650995016 CET199940154194.85.251.76192.168.2.15
    Feb 23, 2025 20:35:31.651153088 CET401541999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:31.699788094 CET401541999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:31.705043077 CET199940154194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:31.883287907 CET199940154194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:31.883430958 CET401541999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:52.680030107 CET401561999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:52.687431097 CET199940156194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:52.687503099 CET401561999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:52.828129053 CET401561999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:52.833241940 CET199940156194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:52.833358049 CET401561999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:52.840043068 CET199940156194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:52.928754091 CET401581999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:52.933927059 CET199940158194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:52.934050083 CET401581999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:52.986161947 CET401581999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:52.993017912 CET199940158194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:52.993186951 CET401581999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:52.998225927 CET199940158194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:53.765712023 CET199940158194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:53.765923977 CET401581999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:53.766117096 CET401581999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:53.768135071 CET401601999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:53.773293018 CET199940160194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:53.773405075 CET401601999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:53.777867079 CET401601999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:53.782959938 CET199940160194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:53.783020020 CET401601999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:53.788141012 CET199940160194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:54.432668924 CET199940160194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:54.432732105 CET401601999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:54.432775021 CET401601999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:54.434541941 CET401621999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:54.439697981 CET199940162194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:54.439785004 CET401621999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:54.443303108 CET401621999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:54.448458910 CET199940162194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:54.448513031 CET401621999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:54.453620911 CET199940162194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:55.064423084 CET199940162194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:55.064546108 CET401621999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:55.064546108 CET401621999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:55.065695047 CET401641999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:55.070861101 CET199940164194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:55.070946932 CET401641999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:55.073156118 CET401641999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:55.078171015 CET199940164194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:55.078269958 CET401641999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:55.083309889 CET199940164194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:55.751415014 CET199940164194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:55.751521111 CET401641999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:55.751585960 CET401641999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:55.752783060 CET401661999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:55.757890940 CET199940166194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:55.757955074 CET401661999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:55.760258913 CET401661999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:55.765425920 CET199940166194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:55.766206980 CET401661999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:55.772486925 CET199940166194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:56.417148113 CET199940166194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:56.417274952 CET401661999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:56.417274952 CET401661999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:56.418791056 CET401681999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:56.423835039 CET199940168194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:56.423903942 CET401681999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:56.426875114 CET401681999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:56.431936026 CET199940168194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:56.431994915 CET401681999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:56.437067032 CET199940168194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:57.056402922 CET199940168194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:57.056639910 CET401681999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:57.056641102 CET401681999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:57.057275057 CET401701999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:57.062448978 CET199940170194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:57.062530041 CET401701999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:57.063467979 CET401701999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:57.068517923 CET199940170194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:57.068577051 CET401701999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:57.073721886 CET199940170194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:57.696772099 CET199940170194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:57.699176073 CET401701999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:57.699177027 CET401701999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:57.714986086 CET401721999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:57.720060110 CET199940172194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:57.720271111 CET401721999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:57.835021019 CET401721999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:57.840080023 CET199940172194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:57.840138912 CET401721999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:57.845114946 CET199940172194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:57.846155882 CET401741999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:57.851180077 CET199940174194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:57.851244926 CET401741999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:57.857101917 CET401741999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:57.862144947 CET199940174194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:57.862366915 CET401741999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:57.867435932 CET199940174194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:58.345895052 CET199940172194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:58.346000910 CET401721999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:58.346040010 CET401721999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:58.346602917 CET401761999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:58.351708889 CET199940176194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:58.351804972 CET401761999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:58.352559090 CET401761999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:58.357543945 CET199940176194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:58.357600927 CET401761999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:58.362622976 CET199940176194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:58.495109081 CET199940174194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:58.495222092 CET401741999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:58.495439053 CET401741999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:58.496093035 CET401781999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:58.501132965 CET199940178194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:58.501220942 CET401781999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:58.502110004 CET401781999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:58.507081985 CET199940178194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:58.507148981 CET401781999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:58.512171984 CET199940178194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:58.974369049 CET199940176194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:58.974621058 CET401761999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:58.974621058 CET401761999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:58.975331068 CET401801999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:58.982304096 CET199940180194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:58.982403994 CET401801999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:58.983285904 CET401801999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:58.988265991 CET199940180194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:58.988332033 CET401801999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:58.993375063 CET199940180194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:59.126491070 CET199940178194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:59.126631975 CET401781999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:59.126631975 CET401781999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:59.127429008 CET401821999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:59.132471085 CET199940182194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:59.132571936 CET401821999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:59.133404016 CET401821999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:59.138381958 CET199940182194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:59.138448000 CET401821999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:59.143459082 CET199940182194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:59.607254028 CET199940180194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:59.607367992 CET401801999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:59.607402086 CET401801999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:59.608068943 CET401841999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:59.613121033 CET199940184194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:59.613188982 CET401841999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:59.614054918 CET401841999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:59.619085073 CET199940184194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:59.619183064 CET401841999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:59.624172926 CET199940184194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:59.786181927 CET199940182194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:59.786271095 CET401821999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:59.786298037 CET401821999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:59.786858082 CET401861999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:59.791814089 CET199940186194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:59.791894913 CET401861999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:59.792748928 CET401861999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:59.797736883 CET199940186194.85.251.76192.168.2.15
    Feb 23, 2025 20:36:59.797846079 CET401861999192.168.2.15194.85.251.76
    Feb 23, 2025 20:36:59.802931070 CET199940186194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:00.237982035 CET199940184194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:00.238284111 CET401841999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:00.238284111 CET401841999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:00.238873959 CET401881999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:00.243918896 CET199940188194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:00.244185925 CET401881999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:00.245063066 CET401881999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:00.250107050 CET199940188194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:00.250195026 CET401881999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:00.255153894 CET199940188194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:00.444386005 CET199940186194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:00.444607019 CET401861999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:00.444644928 CET401861999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:00.445149899 CET401901999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:00.450141907 CET199940190194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:00.450243950 CET401901999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:00.451021910 CET401901999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:00.456020117 CET199940190194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:00.456134081 CET401901999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:00.461137056 CET199940190194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:00.877316952 CET199940188194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:00.877413034 CET401881999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:00.877435923 CET401881999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:00.877960920 CET401921999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:00.883063078 CET199940192194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:00.883124113 CET401921999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:00.883829117 CET401921999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:00.888804913 CET199940192194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:00.888865948 CET401921999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:00.893846989 CET199940192194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:01.074985027 CET199940190194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:01.075052023 CET401901999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:01.075086117 CET401901999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:01.075551033 CET401941999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:01.080688000 CET199940194194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:01.080745935 CET401941999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:01.081459045 CET401941999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:01.086450100 CET199940194194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:01.086502075 CET401941999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:01.091581106 CET199940194194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:01.523488045 CET199940192194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:01.523607016 CET401921999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:01.523658991 CET401921999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:01.524194002 CET401961999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:01.529262066 CET199940196194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:01.529329062 CET401961999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:01.530067921 CET401961999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:01.535088062 CET199940196194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:01.535140991 CET401961999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:01.540128946 CET199940196194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:01.745894909 CET199940194194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:01.745969057 CET401941999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:01.746011019 CET401941999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:01.746594906 CET401981999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:01.751615047 CET199940198194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:01.751677036 CET401981999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:01.752382040 CET401981999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:01.757389069 CET199940198194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:01.757441998 CET401981999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:01.762398958 CET199940198194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:02.173782110 CET199940196194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:02.174017906 CET401961999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:02.174041033 CET401961999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:02.174555063 CET402001999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:02.179568052 CET199940200194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:02.179621935 CET402001999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:02.180334091 CET402001999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:02.185446024 CET199940200194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:02.185507059 CET402001999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:02.190577030 CET199940200194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:02.396428108 CET199940198194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:02.396646023 CET401981999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:02.396687984 CET401981999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:02.397172928 CET402021999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:02.402262926 CET199940202194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:02.402328014 CET402021999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:02.403037071 CET402021999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:02.408107042 CET199940202194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:02.408154011 CET402021999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:02.413232088 CET199940202194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:02.838578939 CET401561999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:02.843672991 CET199940156194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:03.026040077 CET199940156194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:03.026145935 CET401561999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:03.036664963 CET199940202194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:03.036758900 CET402021999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:03.036794901 CET402021999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:03.037347078 CET402041999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:03.042387962 CET199940204194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:03.042521954 CET402041999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:03.043239117 CET402041999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:03.048247099 CET199940204194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:03.048296928 CET402041999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:03.053328991 CET199940204194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:03.733258963 CET199940204194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:03.733392000 CET402041999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:03.733433008 CET402041999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:03.733936071 CET402061999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:03.738922119 CET199940206194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:03.738982916 CET402061999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:03.739717007 CET402061999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:03.744687080 CET199940206194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:03.744744062 CET402061999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:03.749716043 CET199940206194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:04.364372969 CET199940206194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:04.364479065 CET402061999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:04.364595890 CET402061999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:04.365175962 CET402081999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:04.370237112 CET199940208194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:04.370325089 CET402081999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:04.371149063 CET402081999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:04.376177073 CET199940208194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:04.376266003 CET402081999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:04.381238937 CET199940208194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:05.011168957 CET199940208194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:05.011352062 CET402081999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:05.011441946 CET402081999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:05.012128115 CET402101999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:05.017268896 CET199940210194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:05.017333031 CET402101999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:05.018270969 CET402101999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:05.024003983 CET199940210194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:05.024092913 CET402101999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:05.030024052 CET199940210194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:05.672382116 CET199940210194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:05.672559977 CET402101999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:05.672611952 CET402101999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:05.673371077 CET402121999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:05.678419113 CET199940212194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:05.678483963 CET402121999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:05.679608107 CET402121999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:05.684653044 CET199940212194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:05.684700012 CET402121999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:05.689774990 CET199940212194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:06.304003954 CET199940212194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:06.304114103 CET402121999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:06.304176092 CET402121999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:06.304831982 CET402141999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:06.309916019 CET199940214194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:06.309972048 CET402141999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:06.310667992 CET402141999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:06.315740108 CET199940214194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:06.315788031 CET402141999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:06.320796013 CET199940214194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:06.942960978 CET199940214194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:06.943079948 CET402141999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:06.943121910 CET402141999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:06.943617105 CET402161999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:06.949696064 CET199940216194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:06.949760914 CET402161999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:06.950509071 CET402161999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:06.955595970 CET199940216194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:06.955672026 CET402161999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:06.965183020 CET199940216194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:07.600438118 CET199940216194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:07.600547075 CET402161999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:07.600605011 CET402161999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:07.601214886 CET402181999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:07.606314898 CET199940218194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:07.606369972 CET402181999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:07.607075930 CET402181999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:07.612090111 CET199940218194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:07.612145901 CET402181999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:07.617176056 CET199940218194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:12.190612078 CET402001999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:12.195882082 CET199940200194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:12.374747992 CET199940200194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:12.374967098 CET402001999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:17.617202997 CET402181999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:17.622241020 CET199940218194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:17.802870989 CET199940218194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:17.803033113 CET402181999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:31.938891888 CET401541999192.168.2.15194.85.251.76
    Feb 23, 2025 20:37:31.944081068 CET199940154194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:32.176989079 CET199940154194.85.251.76192.168.2.15
    Feb 23, 2025 20:37:32.177153111 CET401541999192.168.2.15194.85.251.76
    TimestampSource PortDest PortSource IPDest IP
    Feb 23, 2025 20:36:54.785360098 CET3853253192.168.2.158.8.8.8
    Feb 23, 2025 20:36:54.785444021 CET5528453192.168.2.158.8.8.8
    Feb 23, 2025 20:36:54.795674086 CET53552848.8.8.8192.168.2.15
    Feb 23, 2025 20:36:54.795792103 CET53385328.8.8.8192.168.2.15
    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
    Feb 23, 2025 20:36:54.785360098 CET192.168.2.158.8.8.80x1f15Standard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
    Feb 23, 2025 20:36:54.785444021 CET192.168.2.158.8.8.80x77efStandard query (0)daisy.ubuntu.com28IN (0x0001)false
    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
    Feb 23, 2025 20:36:54.795792103 CET8.8.8.8192.168.2.150x1f15No error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
    Feb 23, 2025 20:36:54.795792103 CET8.8.8.8192.168.2.150x1f15No error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false

    System Behavior

    Start time (UTC):19:34:08
    Start date (UTC):23/02/2025
    Path:/tmp/phantom.arm.elf
    Arguments:/tmp/phantom.arm.elf
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):19:34:08
    Start date (UTC):23/02/2025
    Path:/tmp/phantom.arm.elf
    Arguments:-
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):19:36:52
    Start date (UTC):23/02/2025
    Path:/tmp/phantom.arm.elf
    Arguments:-
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):19:36:52
    Start date (UTC):23/02/2025
    Path:/tmp/phantom.arm.elf
    Arguments:-
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):19:36:52
    Start date (UTC):23/02/2025
    Path:/tmp/phantom.arm.elf
    Arguments:-
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):19:36:57
    Start date (UTC):23/02/2025
    Path:/tmp/phantom.arm.elf
    Arguments:-
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):19:36:57
    Start date (UTC):23/02/2025
    Path:/tmp/phantom.arm.elf
    Arguments:-
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):19:36:52
    Start date (UTC):23/02/2025
    Path:/tmp/phantom.arm.elf
    Arguments:-
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):19:36:52
    Start date (UTC):23/02/2025
    Path:/tmp/phantom.arm.elf
    Arguments:-
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):19:34:08
    Start date (UTC):23/02/2025
    Path:/tmp/phantom.arm.elf
    Arguments:-
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):19:34:08
    Start date (UTC):23/02/2025
    Path:/tmp/phantom.arm.elf
    Arguments:-
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):19:34:08
    Start date (UTC):23/02/2025
    Path:/tmp/phantom.arm.elf
    Arguments:-
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):19:36:52
    Start date (UTC):23/02/2025
    Path:/tmp/phantom.arm.elf
    Arguments:-
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):19:36:52
    Start date (UTC):23/02/2025
    Path:/tmp/phantom.arm.elf
    Arguments:-
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):19:34:08
    Start date (UTC):23/02/2025
    Path:/tmp/phantom.arm.elf
    Arguments:-
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):19:34:08
    Start date (UTC):23/02/2025
    Path:/tmp/phantom.arm.elf
    Arguments:-
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1