Edit tour

Linux Analysis Report
ub8ehJSePAfc9FYqZIT6.mpsl.elf

Overview

General Information

Sample name:ub8ehJSePAfc9FYqZIT6.mpsl.elf
Analysis ID:1631566
MD5:37e3f1e3faf28800d5d6e75a7ab8c39a
SHA1:c3e2b8841298415d70333c2ef1351c5b27afc45e
SHA256:90d543a1027b33b457f943571be902751cdc9b60a86ac9eacde19843e34ca8c2
Tags:elfuser-abuse_ch
Infos:

Detection

Score:68
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Sample contains only a LOAD segment without any section mappings
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1631566
Start date and time:2025-03-07 10:52:33 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 47s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:ub8ehJSePAfc9FYqZIT6.mpsl.elf
Detection:MAL
Classification:mal68.evad.linELF@0/0@0/0
Command:/tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf
PID:6236
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
6250.1.00007ffb5c400000.00007ffb5c42a000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x2739c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27400:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27414:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27428:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2743c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27450:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27464:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27478:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2748c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27504:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27518:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2752c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
6240.1.00007ffb5c400000.00007ffb5c42a000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x2739c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27400:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27414:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27428:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2743c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27450:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27464:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27478:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2748c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27504:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27518:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2752c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
6236.1.00007ffb5c400000.00007ffb5c42a000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x2739c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27400:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27414:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27428:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2743c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27450:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27464:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27478:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2748c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27504:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27518:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2752c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
6238.1.00007ffb5c400000.00007ffb5c42a000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x2739c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27400:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27414:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27428:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2743c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27450:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27464:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27478:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2748c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27504:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27518:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2752c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: ub8ehJSePAfc9FYqZIT6.mpsl.elf PID: 6236Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x775c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x7770:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x7784:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x7798:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x77ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x77c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x77d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x77e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x77fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x7810:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x7824:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x7838:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x784c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x7860:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x7874:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x7888:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x789c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x78b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x78c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x78d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x78ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Click to see the 3 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: ub8ehJSePAfc9FYqZIT6.mpsl.elfAvira: detected
Source: ub8ehJSePAfc9FYqZIT6.mpsl.elfReversingLabs: Detection: 44%
Source: global trafficTCP traffic: 192.168.2.23:34666 -> 61.7.209.115:3778
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: unknownTCP traffic detected without corresponding DNS query: 61.7.209.115
Source: ub8ehJSePAfc9FYqZIT6.mpsl.elfString found in binary or memory: http://upx.sf.net
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: 6250.1.00007ffb5c400000.00007ffb5c42a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6240.1.00007ffb5c400000.00007ffb5c42a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6236.1.00007ffb5c400000.00007ffb5c42a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6238.1.00007ffb5c400000.00007ffb5c42a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.mpsl.elf PID: 6236, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.mpsl.elf PID: 6238, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.mpsl.elf PID: 6240, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.mpsl.elf PID: 6250, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: LOAD without section mappingsProgram segment: 0x100000
Source: 6250.1.00007ffb5c400000.00007ffb5c42a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6240.1.00007ffb5c400000.00007ffb5c42a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6236.1.00007ffb5c400000.00007ffb5c42a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6238.1.00007ffb5c400000.00007ffb5c42a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.mpsl.elf PID: 6236, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.mpsl.elf PID: 6238, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.mpsl.elf PID: 6240, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.mpsl.elf PID: 6250, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal68.evad.linELF@0/0@0/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/6236/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/1582/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/3088/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/230/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/110/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/231/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/111/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/232/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/1579/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/112/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/233/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/1699/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/113/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/234/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/1335/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/1698/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/114/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/235/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/1334/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/1576/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/2302/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/115/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/236/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/116/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/237/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/117/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/118/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/910/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/119/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/912/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/10/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/2307/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/11/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/918/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/12/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/13/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/14/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/6242/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/15/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/16/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/17/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/18/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/1594/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/120/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/121/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/1349/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/1/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/122/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/243/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/123/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/2/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/124/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/3/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/4/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/125/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/126/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/1344/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/1465/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/1586/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/127/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/6/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/248/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/128/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/249/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/1463/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/800/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/9/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/801/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/20/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/21/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/1900/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/22/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/23/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/24/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/25/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/26/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/27/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/28/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/29/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/491/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/250/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/130/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/251/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/252/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/132/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/253/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/254/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/255/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/4509/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/256/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/1599/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/257/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/1477/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/379/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/258/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/1476/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/259/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/1475/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/936/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/30/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/2208/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/35/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/1809/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/1494/statusJump to behavior
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)File opened: /proc/260/statusJump to behavior
Source: ub8ehJSePAfc9FYqZIT6.mpsl.elfSubmission file: segment LOAD with 7.9469 entropy (max. 8.0)
Source: /tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf (PID: 6236)Queries kernel information via 'uname': Jump to behavior
Source: ub8ehJSePAfc9FYqZIT6.mpsl.elf, 6236.1.0000558fbcd8f000.0000558fbce37000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.mpsl.elf, 6238.1.0000558fbcd8f000.0000558fbce37000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.mpsl.elf, 6240.1.0000558fbcd8f000.0000558fbce37000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.mpsl.elf, 6250.1.0000558fbcd8f000.0000558fbce37000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mipsel
Source: ub8ehJSePAfc9FYqZIT6.mpsl.elf, 6236.1.0000558fbcd8f000.0000558fbce37000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.mpsl.elf, 6238.1.0000558fbcd8f000.0000558fbce37000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.mpsl.elf, 6240.1.0000558fbcd8f000.0000558fbce37000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.mpsl.elf, 6250.1.0000558fbcd8f000.0000558fbce37000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mipsel
Source: ub8ehJSePAfc9FYqZIT6.mpsl.elf, 6236.1.00007fff9efe4000.00007fff9f005000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.mpsl.elf, 6238.1.00007fff9efe4000.00007fff9f005000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.mpsl.elf, 6240.1.00007fff9efe4000.00007fff9f005000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.mpsl.elf, 6250.1.00007fff9efe4000.00007fff9f005000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsel
Source: ub8ehJSePAfc9FYqZIT6.mpsl.elf, 6236.1.00007fff9efe4000.00007fff9f005000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.mpsl.elf, 6238.1.00007fff9efe4000.00007fff9f005000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.mpsl.elf, 6240.1.00007fff9efe4000.00007fff9f005000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.mpsl.elf, 6250.1.00007fff9efe4000.00007fff9f005000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mipsel/tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1631566 Sample: ub8ehJSePAfc9FYqZIT6.mpsl.elf Startdate: 07/03/2025 Architecture: LINUX Score: 68 20 109.202.202.202, 80 INIT7CH Switzerland 2->20 22 61.7.209.115, 34666, 34668, 34670 CAT-APTheCommunicationAuthoityofThailandCATTH Thailand 2->22 24 2 other IPs or domains 2->24 26 Malicious sample detected (through community Yara rule) 2->26 28 Antivirus / Scanner detection for submitted sample 2->28 30 Multi AV Scanner detection for submitted file 2->30 32 Sample is packed with UPX 2->32 8 ub8ehJSePAfc9FYqZIT6.mpsl.elf 2->8         started        signatures3 process4 process5 10 ub8ehJSePAfc9FYqZIT6.mpsl.elf 8->10         started        12 ub8ehJSePAfc9FYqZIT6.mpsl.elf 8->12         started        14 ub8ehJSePAfc9FYqZIT6.mpsl.elf 8->14         started        process6 16 ub8ehJSePAfc9FYqZIT6.mpsl.elf 10->16         started        18 ub8ehJSePAfc9FYqZIT6.mpsl.elf 10->18         started       
SourceDetectionScannerLabelLink
ub8ehJSePAfc9FYqZIT6.mpsl.elf45%ReversingLabsLinux.Trojan.Mirai
ub8ehJSePAfc9FYqZIT6.mpsl.elf100%AviraEXP/ELF.Agent.M.28
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netub8ehJSePAfc9FYqZIT6.mpsl.elffalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    61.7.209.115
    unknownThailand
    9931CAT-APTheCommunicationAuthoityofThailandCATTHfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
    • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
    61.7.209.115ub8ehJSePAfc9FYqZIT6.mips.elfGet hashmaliciousUnknownBrowse
      ub8ehJSePAfc9FYqZIT6.arm7.elfGet hashmaliciousMiraiBrowse
        ub8ehJSePAfc9FYqZIT6.arm7.elfGet hashmaliciousMiraiBrowse
          ub8ehJSePAfc9FYqZIT6.ppc.elfGet hashmaliciousUnknownBrowse
            ub8ehJSePAfc9FYqZIT6.mpsl.elfGet hashmaliciousUnknownBrowse
              ub8ehJSePAfc9FYqZIT6.sh4.elfGet hashmaliciousUnknownBrowse
                ub8ehJSePAfc9FYqZIT6.arm.elfGet hashmaliciousMiraiBrowse
                  ub8ehJSePAfc9FYqZIT6.x86.elfGet hashmaliciousUnknownBrowse
                    91.189.91.43ub8ehJSePAfc9FYqZIT6.arm5.elfGet hashmaliciousUnknownBrowse
                      na.elfGet hashmaliciousPrometeiBrowse
                        ub8ehJSePAfc9FYqZIT6.mips.elfGet hashmaliciousUnknownBrowse
                          na.elfGet hashmaliciousPrometeiBrowse
                            ub8ehJSePAfc9FYqZIT6.arm7.elfGet hashmaliciousMiraiBrowse
                              na.elfGet hashmaliciousPrometeiBrowse
                                na.elfGet hashmaliciousPrometeiBrowse
                                  na.elfGet hashmaliciousPrometeiBrowse
                                    na.elfGet hashmaliciousPrometeiBrowse
                                      na.elfGet hashmaliciousPrometeiBrowse
                                        91.189.91.42ub8ehJSePAfc9FYqZIT6.arm5.elfGet hashmaliciousUnknownBrowse
                                          na.elfGet hashmaliciousPrometeiBrowse
                                            ub8ehJSePAfc9FYqZIT6.mips.elfGet hashmaliciousUnknownBrowse
                                              na.elfGet hashmaliciousPrometeiBrowse
                                                ub8ehJSePAfc9FYqZIT6.arm7.elfGet hashmaliciousMiraiBrowse
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                            No context
                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                            CANONICAL-ASGBub8ehJSePAfc9FYqZIT6.arm5.elfGet hashmaliciousUnknownBrowse
                                                            • 91.189.91.42
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 91.189.91.42
                                                            ub8ehJSePAfc9FYqZIT6.mips.elfGet hashmaliciousUnknownBrowse
                                                            • 91.189.91.42
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 91.189.91.42
                                                            ub8ehJSePAfc9FYqZIT6.arm7.elfGet hashmaliciousMiraiBrowse
                                                            • 91.189.91.42
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 91.189.91.42
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 91.189.91.42
                                                            sshd.elfGet hashmaliciousUnknownBrowse
                                                            • 185.125.190.26
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 91.189.91.42
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 91.189.91.42
                                                            CANONICAL-ASGBub8ehJSePAfc9FYqZIT6.arm5.elfGet hashmaliciousUnknownBrowse
                                                            • 91.189.91.42
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 91.189.91.42
                                                            ub8ehJSePAfc9FYqZIT6.mips.elfGet hashmaliciousUnknownBrowse
                                                            • 91.189.91.42
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 91.189.91.42
                                                            ub8ehJSePAfc9FYqZIT6.arm7.elfGet hashmaliciousMiraiBrowse
                                                            • 91.189.91.42
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 91.189.91.42
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 91.189.91.42
                                                            sshd.elfGet hashmaliciousUnknownBrowse
                                                            • 185.125.190.26
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 91.189.91.42
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 91.189.91.42
                                                            CAT-APTheCommunicationAuthoityofThailandCATTHub8ehJSePAfc9FYqZIT6.mips.elfGet hashmaliciousUnknownBrowse
                                                            • 61.7.209.115
                                                            ub8ehJSePAfc9FYqZIT6.arm7.elfGet hashmaliciousMiraiBrowse
                                                            • 61.7.209.115
                                                            splmpsl.elfGet hashmaliciousUnknownBrowse
                                                            • 110.78.78.218
                                                            sys.x86_64.elfGet hashmaliciousXmrigBrowse
                                                            • 61.7.203.9
                                                            ub8ehJSePAfc9FYqZIT6.arm7.elfGet hashmaliciousMiraiBrowse
                                                            • 61.7.209.115
                                                            ub8ehJSePAfc9FYqZIT6.ppc.elfGet hashmaliciousUnknownBrowse
                                                            • 61.7.209.115
                                                            ub8ehJSePAfc9FYqZIT6.mpsl.elfGet hashmaliciousUnknownBrowse
                                                            • 61.7.209.115
                                                            ub8ehJSePAfc9FYqZIT6.sh4.elfGet hashmaliciousUnknownBrowse
                                                            • 61.7.209.115
                                                            ub8ehJSePAfc9FYqZIT6.arm.elfGet hashmaliciousMiraiBrowse
                                                            • 61.7.209.115
                                                            ub8ehJSePAfc9FYqZIT6.x86.elfGet hashmaliciousUnknownBrowse
                                                            • 61.7.209.115
                                                            INIT7CHub8ehJSePAfc9FYqZIT6.arm5.elfGet hashmaliciousUnknownBrowse
                                                            • 109.202.202.202
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 109.202.202.202
                                                            ub8ehJSePAfc9FYqZIT6.mips.elfGet hashmaliciousUnknownBrowse
                                                            • 109.202.202.202
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 109.202.202.202
                                                            ub8ehJSePAfc9FYqZIT6.arm7.elfGet hashmaliciousMiraiBrowse
                                                            • 109.202.202.202
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 109.202.202.202
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 109.202.202.202
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 109.202.202.202
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 109.202.202.202
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                            • 109.202.202.202
                                                            No context
                                                            No context
                                                            No created / dropped files found
                                                            File type:ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, no section header
                                                            Entropy (8bit):7.94414745953277
                                                            TrID:
                                                            • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                            File name:ub8ehJSePAfc9FYqZIT6.mpsl.elf
                                                            File size:44'332 bytes
                                                            MD5:37e3f1e3faf28800d5d6e75a7ab8c39a
                                                            SHA1:c3e2b8841298415d70333c2ef1351c5b27afc45e
                                                            SHA256:90d543a1027b33b457f943571be902751cdc9b60a86ac9eacde19843e34ca8c2
                                                            SHA512:ab1397c7bd0ebe4ee76e16177adbc3ce5b2437b7f4ff68911cf1d07b7f11cb7556ab5dffe51e761169ec91df767d766360b376051afdfc7a46c8fd25850d6164
                                                            SSDEEP:768:E1jRTSWuPUdOfcVy3t9g44uuyBDmzii5HaPSkIx9RIXvtTPsAb3bqOWS:E1dTSlYvVMt9gtuSNaKBx9RYdbrN
                                                            TLSH:8C13E12DF48EEF4ACE9D0AB7139FC6D2828CB453738D4B84077E5614BD5698AA84C474
                                                            File Content Preview:.ELF........................4...........4. ...(...............................................C...C.....................UPX!`...................T..........?.E.h;....#......b.L.1-......./5.....U....A...?....3M $Ie.K9..M.C...D-.......\...l..............p?.

                                                            ELF header

                                                            Class:ELF32
                                                            Data:2's complement, little endian
                                                            Version:1 (current)
                                                            Machine:MIPS R3000
                                                            Version Number:0x1
                                                            Type:EXEC (Executable file)
                                                            OS/ABI:UNIX - System V
                                                            ABI Version:0
                                                            Entry Point Address:0x1098c8
                                                            Flags:0x1007
                                                            ELF Header Size:52
                                                            Program Header Offset:52
                                                            Program Header Size:32
                                                            Number of Program Headers:2
                                                            Section Header Offset:0
                                                            Section Header Size:40
                                                            Number of Section Headers:0
                                                            Header String Table Index:0
                                                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                            LOAD0x00x1000000x1000000xac050xac057.94690x5R E0x10000
                                                            LOAD0xac0c0x43ac0c0x43ac0c0x00x00.00000x6RW 0x10000

                                                            Download Network PCAP: filteredfull

                                                            • Total Packets: 404
                                                            • 3778 undefined
                                                            • 443 (HTTPS)
                                                            • 80 (HTTP)
                                                            TimestampSource PortDest PortSource IPDest IP
                                                            Mar 7, 2025 10:53:18.955796003 CET43928443192.168.2.2391.189.91.42
                                                            Mar 7, 2025 10:53:18.976324081 CET346663778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:18.981426001 CET37783466661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:18.981489897 CET346663778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:19.007011890 CET346663778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:19.012147903 CET37783466661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:19.012196064 CET346663778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:19.017266989 CET37783466661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:19.996681929 CET37783466661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:19.996798038 CET346663778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:19.997134924 CET346663778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:19.998090029 CET346683778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:20.003129959 CET37783466861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:20.003432035 CET346683778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:20.004419088 CET346683778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:20.009381056 CET37783466861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:20.009434938 CET346683778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:20.014458895 CET37783466861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:20.997338057 CET37783466861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:20.997642040 CET346683778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:20.997642040 CET346683778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:20.998191118 CET346703778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:21.003366947 CET37783467061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:21.003426075 CET346703778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:21.004125118 CET346703778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:21.009319067 CET37783467061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:21.009371996 CET346703778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:21.014466047 CET37783467061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:21.994898081 CET37783467061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:21.995187998 CET346703778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:21.995187998 CET346703778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:21.995825052 CET346723778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:22.001014948 CET37783467261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:22.001087904 CET346723778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:22.001844883 CET346723778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:22.006948948 CET37783467261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:22.007009029 CET346723778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:22.012090921 CET37783467261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:22.996124029 CET37783467261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:22.996414900 CET346723778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:22.996414900 CET346723778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:22.996937990 CET346743778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:23.002796888 CET37783467461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:23.002865076 CET346743778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:23.003586054 CET346743778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:23.008688927 CET37783467461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:23.008759975 CET346743778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:23.013828039 CET37783467461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:23.987354040 CET37783467461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:23.987508059 CET346743778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:23.987601042 CET346743778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:23.988207102 CET346763778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:23.993244886 CET37783467661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:23.993313074 CET346763778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:23.993995905 CET346763778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:23.999011993 CET37783467661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:23.999080896 CET346763778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:24.004126072 CET37783467661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:24.587105036 CET42836443192.168.2.2391.189.91.43
                                                            Mar 7, 2025 10:53:24.655097008 CET346783778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:24.660268068 CET37783467861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:24.660378933 CET346783778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:24.676636934 CET346783778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:24.682374954 CET37783467861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:24.682444096 CET346783778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:24.687954903 CET37783467861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:25.008297920 CET37783467661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:25.008503914 CET346763778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:25.008584976 CET346763778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:25.009185076 CET346803778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:25.014312983 CET37783468061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:25.014374971 CET346803778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:25.015845060 CET346803778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:25.020978928 CET37783468061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:25.021027088 CET346803778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:25.026130915 CET37783468061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:25.637306929 CET37783467861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:25.637435913 CET346783778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:25.637826920 CET346783778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:25.638520002 CET346823778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:25.643598080 CET37783468261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:25.643662930 CET346823778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:25.644505978 CET346823778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:25.649542093 CET37783468261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:25.649594069 CET346823778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:25.654613018 CET37783468261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:25.866863012 CET4251680192.168.2.23109.202.202.202
                                                            Mar 7, 2025 10:53:26.007895947 CET37783468061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:26.008088112 CET346803778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:26.008147001 CET346803778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:26.009012938 CET346843778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:26.014141083 CET37783468461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:26.014223099 CET346843778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:26.016006947 CET346843778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:26.021612883 CET37783468461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:26.021657944 CET346843778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:26.027707100 CET37783468461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:26.636938095 CET37783468261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:26.637201071 CET346823778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:26.637202024 CET346823778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:26.637676001 CET346863778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:26.645258904 CET37783468661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:26.645329952 CET346863778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:26.646750927 CET346863778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:26.651941061 CET37783468661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:26.651999950 CET346863778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:26.657114029 CET37783468661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:27.002763987 CET37783468461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:27.002863884 CET346843778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:27.002912998 CET346843778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:27.003420115 CET346883778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:27.008518934 CET37783468861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:27.008594036 CET346883778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:27.009356976 CET346883778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:27.014395952 CET37783468861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:27.014451981 CET346883778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:27.019509077 CET37783468861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:27.626508951 CET37783468661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:27.626704931 CET346863778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:27.626836061 CET346863778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:27.627404928 CET346903778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:27.632447004 CET37783469061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:27.632529020 CET346903778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:27.633167028 CET346903778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:27.638231993 CET37783469061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:27.638293028 CET346903778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:27.643315077 CET37783469061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:27.995414019 CET37783468861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:27.995592117 CET346883778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:27.995637894 CET346883778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:27.996285915 CET346923778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:28.001581907 CET37783469261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:28.001643896 CET346923778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:28.002440929 CET346923778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:28.007599115 CET37783469261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:28.007658958 CET346923778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:28.012752056 CET37783469261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:28.624300957 CET37783469061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:28.624469042 CET346903778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:28.624510050 CET346903778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:28.625233889 CET346943778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:28.630436897 CET37783469461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:28.630542994 CET346943778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:28.631274939 CET346943778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:28.636379957 CET37783469461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:28.636588097 CET346943778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:28.641652107 CET37783469461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:28.992516994 CET37783469261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:28.992661953 CET346923778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:28.992722988 CET346923778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:28.993632078 CET346963778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:28.998706102 CET37783469661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:28.998774052 CET346963778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:28.999522924 CET346963778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:29.004612923 CET37783469661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:29.004687071 CET346963778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:29.009774923 CET37783469661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:29.614178896 CET37783469461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:29.614312887 CET346943778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:29.614398003 CET346943778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:29.614953041 CET346983778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:29.620342016 CET37783469861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:29.620430946 CET346983778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:29.621085882 CET346983778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:29.626455069 CET37783469861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:29.626522064 CET346983778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:29.631599903 CET37783469861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:29.987086058 CET37783469661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:29.987340927 CET346963778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:29.987426996 CET346963778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:29.988080978 CET347003778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:29.993213892 CET37783470061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:29.993280888 CET347003778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:29.994080067 CET347003778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:29.999135971 CET37783470061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:29.999213934 CET347003778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:30.004286051 CET37783470061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:30.629051924 CET37783469861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:30.629151106 CET346983778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:30.629343033 CET346983778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:30.629862070 CET347023778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:30.634975910 CET37783470261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:30.635072947 CET347023778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:30.635790110 CET347023778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:30.640925884 CET37783470261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:30.641005993 CET347023778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:30.646105051 CET37783470261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:30.977386951 CET37783470061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:30.977555990 CET347003778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:30.977642059 CET347003778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:30.978564024 CET347043778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:30.983628035 CET37783470461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:30.983716965 CET347043778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:30.984868050 CET347043778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:30.989943981 CET37783470461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:30.990005970 CET347043778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:30.995016098 CET37783470461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:31.644443989 CET37783470261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:31.644690037 CET347023778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:31.644790888 CET347023778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:31.645567894 CET347063778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:31.650719881 CET37783470661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:31.650823116 CET347063778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:31.652321100 CET347063778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:31.657370090 CET37783470661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:31.657758951 CET347063778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:31.662916899 CET37783470661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:31.986066103 CET37783470461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:31.986296892 CET347043778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:31.986392021 CET347043778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:31.987175941 CET347083778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:31.992278099 CET37783470861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:31.992348909 CET347083778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:31.993159056 CET347083778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:31.998260021 CET37783470861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:31.998312950 CET347083778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:32.003396988 CET37783470861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:32.640386105 CET37783470661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:32.640687943 CET347063778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:32.640748978 CET347063778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:32.641480923 CET347103778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:32.646625042 CET37783471061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:32.646687031 CET347103778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:32.647428036 CET347103778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:32.652559996 CET37783471061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:32.652609110 CET347103778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:32.657670021 CET37783471061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:32.987246037 CET37783470861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:32.987504005 CET347083778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:32.987643957 CET347083778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:32.988498926 CET347123778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:32.993561029 CET37783471261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:32.993643999 CET347123778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:32.994611025 CET347123778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:32.999664068 CET37783471261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:32.999716043 CET347123778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:33.005171061 CET37783471261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:33.641941071 CET37783471061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:33.642332077 CET347103778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:33.642432928 CET347103778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:33.643295050 CET347143778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:33.648442984 CET37783471461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:33.648511887 CET347143778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:33.649210930 CET347143778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:33.654416084 CET37783471461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:33.654465914 CET347143778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:33.659533978 CET37783471461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:33.983355045 CET37783471261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:33.983519077 CET347123778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:33.983550072 CET347123778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:33.984155893 CET347163778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:33.989280939 CET37783471661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:33.989358902 CET347163778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:33.990273952 CET347163778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:33.995404959 CET37783471661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:33.995465040 CET347163778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:34.000579119 CET37783471661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:34.653565884 CET37783471461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:34.653835058 CET347143778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:34.653867960 CET347143778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:34.654460907 CET347183778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:34.660490990 CET37783471861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:34.660559893 CET347183778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:34.661892891 CET347183778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:34.667315960 CET37783471861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:34.667401075 CET347183778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:34.672462940 CET37783471861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:34.976114988 CET37783471661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:34.976263046 CET347163778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:34.976320982 CET347163778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:34.976973057 CET347203778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:34.982096910 CET37783472061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:34.982213020 CET347203778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:34.983064890 CET347203778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:34.988122940 CET37783472061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:34.988187075 CET347203778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:34.993285894 CET37783472061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:35.672148943 CET37783471861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:35.672431946 CET347183778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:35.672463894 CET347183778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:35.673059940 CET347223778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:35.678205013 CET37783472261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:35.678333044 CET347223778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:35.678961039 CET347223778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:35.684004068 CET37783472261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:35.684091091 CET347223778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:35.689157009 CET37783472261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:35.978673935 CET37783472061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:35.978799105 CET347203778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:35.978847027 CET347203778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:35.979495049 CET347243778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:35.984646082 CET37783472461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:35.984719038 CET347243778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:35.985685110 CET347243778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:35.990783930 CET37783472461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:35.990865946 CET347243778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:35.995920897 CET37783472461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:36.675856113 CET37783472261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:36.676239014 CET347223778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:36.676239014 CET347223778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:36.677022934 CET347263778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:36.682090998 CET37783472661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:36.682199955 CET347263778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:36.683146000 CET347263778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:36.688155890 CET37783472661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:36.688262939 CET347263778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:36.693300962 CET37783472661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:37.009639978 CET37783472461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:37.009882927 CET347243778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:37.009953976 CET347243778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:37.010966063 CET347283778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:37.016036987 CET37783472861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:37.016120911 CET347283778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:37.018493891 CET347283778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:37.023638964 CET37783472861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:37.023716927 CET347283778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:37.028784037 CET37783472861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:37.685239077 CET37783472661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:37.685456991 CET347263778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:37.685661077 CET347263778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:37.686500072 CET347303778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:37.691592932 CET37783473061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:37.691677094 CET347303778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:37.692353010 CET347303778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:37.697397947 CET37783473061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:37.697490931 CET347303778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:37.702529907 CET37783473061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:38.020143986 CET37783472861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:38.020339966 CET347283778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:38.020397902 CET347283778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:38.021209002 CET347323778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:38.026258945 CET37783473261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:38.026340008 CET347323778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:38.027257919 CET347323778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:38.032365084 CET37783473261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:38.032443047 CET347323778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:38.037543058 CET37783473261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:38.713596106 CET37783473061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:38.713773012 CET347303778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:38.713924885 CET347303778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:38.714459896 CET347343778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:38.719490051 CET37783473461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:38.719594955 CET347343778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:38.720264912 CET347343778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:38.725337029 CET37783473461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:38.725409031 CET347343778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:38.730498075 CET37783473461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:39.039762974 CET37783473261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:39.040107012 CET347323778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:39.040107012 CET347323778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:39.040847063 CET347363778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:39.045984030 CET37783473661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:39.046065092 CET347363778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:39.047319889 CET347363778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:39.052422047 CET37783473661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:39.052493095 CET347363778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:39.057610989 CET37783473661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:39.725826979 CET37783473461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:39.726037979 CET347343778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:39.726140022 CET347343778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:39.726907015 CET347383778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:39.733011961 CET37783473861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:39.733149052 CET347383778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:39.734181881 CET347383778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:39.739181042 CET37783473861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:39.739238024 CET347383778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:39.744251013 CET37783473861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:40.055788040 CET37783473661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:40.055948019 CET347363778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:40.056221962 CET347363778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:40.056945086 CET347403778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:40.061984062 CET37783474061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:40.062068939 CET347403778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:40.062885046 CET347403778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:40.067938089 CET37783474061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:40.068006039 CET347403778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:40.073097944 CET37783474061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:40.701689959 CET37783473861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:40.701873064 CET347383778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:40.702119112 CET347383778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:40.702589989 CET347423778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:40.707678080 CET37783474261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:40.707734108 CET347423778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:40.708414078 CET347423778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:40.712826967 CET43928443192.168.2.2391.189.91.42
                                                            Mar 7, 2025 10:53:40.713453054 CET37783474261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:40.713516951 CET347423778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:40.718595982 CET37783474261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:41.240269899 CET37783474061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:41.240412951 CET347403778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:41.240530968 CET347403778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:41.240533113 CET37783474061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:41.240600109 CET347403778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:41.241489887 CET347443778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:41.243592978 CET37783474061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:41.243653059 CET347403778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:41.246696949 CET37783474461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:41.246810913 CET347443778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:41.248357058 CET347443778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:41.253443956 CET37783474461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:41.253501892 CET347443778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:41.258682013 CET37783474461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:41.720285892 CET37783474261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:41.720515013 CET347423778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:41.720515013 CET347423778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:41.721242905 CET347463778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:41.726845026 CET37783474661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:41.726995945 CET347463778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:41.728301048 CET347463778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:41.733400106 CET37783474661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:41.733475924 CET347463778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:41.738535881 CET37783474661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:42.390428066 CET37783474461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:42.390655041 CET347443778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:42.390686035 CET347443778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:42.391416073 CET347483778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:42.392065048 CET37783474461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:42.392190933 CET347443778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:42.396498919 CET37783474861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:42.396593094 CET347483778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:42.397808075 CET347483778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:42.403992891 CET37783474861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:42.404077053 CET347483778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:42.409177065 CET37783474861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:42.717312098 CET37783474661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:42.717495918 CET347463778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:42.717607975 CET347463778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:42.718405962 CET347503778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:42.723433018 CET37783475061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:42.723514080 CET347503778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:42.724606037 CET347503778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:42.729623079 CET37783475061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:42.729685068 CET347503778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:42.734741926 CET37783475061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:43.394934893 CET37783474861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:43.395241976 CET347483778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:43.395241976 CET347483778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:43.395880938 CET347523778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:43.401282072 CET37783475261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:43.401376009 CET347523778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:43.403095007 CET347523778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:43.408162117 CET37783475261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:43.408216000 CET347523778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:43.413336039 CET37783475261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:43.725100040 CET37783475061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:43.725454092 CET347503778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:43.725454092 CET347503778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:43.726617098 CET347543778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:43.731794119 CET37783475461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:43.731944084 CET347543778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:43.733248949 CET347543778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:43.738343000 CET37783475461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:43.738455057 CET347543778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:43.743527889 CET37783475461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:44.389946938 CET37783475261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:44.390290976 CET347523778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:44.390291929 CET347523778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:44.390913010 CET347563778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:44.396018028 CET37783475661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:44.396085978 CET347563778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:44.396893978 CET347563778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:44.402035952 CET37783475661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:44.402223110 CET347563778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:44.407383919 CET37783475661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:44.732413054 CET37783475461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:44.732656956 CET347543778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:44.732732058 CET347543778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:44.733393908 CET347583778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:44.738514900 CET37783475861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:44.738599062 CET347583778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:44.739413977 CET347583778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:44.744481087 CET37783475861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:44.744554996 CET347583778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:44.749797106 CET37783475861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:45.374541998 CET37783475661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:45.374748945 CET347563778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:45.374866009 CET347563778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:45.375761986 CET347603778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:45.380855083 CET37783476061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:45.380934000 CET347603778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:45.381885052 CET347603778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:45.386990070 CET37783476061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:45.387053967 CET347603778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:45.392225027 CET37783476061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:45.722652912 CET37783475861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:45.722800970 CET347583778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:45.723011017 CET347583778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:45.724015951 CET347623778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:45.729162931 CET37783476261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:45.729353905 CET347623778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:45.730132103 CET347623778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:45.735302925 CET37783476261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:45.735497952 CET347623778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:45.740586996 CET37783476261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:46.384733915 CET37783476061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:46.384891987 CET347603778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:46.385008097 CET347603778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:46.385886908 CET347643778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:46.390997887 CET37783476461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:46.391081095 CET347643778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:46.392268896 CET347643778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:46.397469997 CET37783476461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:46.397536993 CET347643778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:46.402614117 CET37783476461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:46.712954998 CET37783476261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:46.713190079 CET347623778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:46.713219881 CET347623778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:46.713939905 CET347663778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:46.718988895 CET37783476661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:46.719177008 CET347663778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:46.720321894 CET347663778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:46.725392103 CET37783476661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:46.725596905 CET347663778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:46.730679989 CET37783476661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:47.376846075 CET37783476461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:47.377007961 CET347643778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:47.377091885 CET347643778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:47.377954960 CET347683778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:47.383546114 CET37783476861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:47.383668900 CET347683778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:47.384860992 CET347683778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:47.390248060 CET37783476861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:47.390319109 CET347683778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:47.395382881 CET37783476861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:47.701360941 CET37783476661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:47.701565981 CET347663778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:47.701736927 CET347663778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:47.702405930 CET347703778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:47.707448006 CET37783477061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:47.707549095 CET347703778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:47.708564997 CET347703778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:47.713581085 CET37783477061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:47.713644981 CET347703778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:47.718687057 CET37783477061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:48.374325037 CET37783476861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:48.374769926 CET347683778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:48.374769926 CET347683778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:48.375540972 CET347723778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:48.380650997 CET37783477261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:48.380775928 CET347723778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:48.382117987 CET347723778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:48.387264967 CET37783477261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:48.387342930 CET347723778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:48.392402887 CET37783477261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:48.710768938 CET37783477061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:48.711098909 CET347703778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:48.711200953 CET347703778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:48.712171078 CET347743778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:48.717253923 CET37783477461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:48.717335939 CET347743778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:48.718966961 CET347743778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:48.724049091 CET37783477461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:48.724112988 CET347743778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:48.729163885 CET37783477461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:49.374142885 CET37783477261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:49.374294043 CET347723778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:49.374382019 CET347723778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:49.375037909 CET347763778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:49.380172014 CET37783477661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:49.380239010 CET347763778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:49.381066084 CET347763778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:49.386127949 CET37783477661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:49.386234045 CET347763778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:49.391318083 CET37783477661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:49.729317904 CET37783477461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:49.729597092 CET347743778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:49.729597092 CET347743778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:49.730173111 CET347783778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:49.736422062 CET37783477861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:49.736484051 CET347783778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:49.737302065 CET347783778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:49.743406057 CET37783477861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:49.743463993 CET347783778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:49.749531984 CET37783477861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:50.360372066 CET37783477661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:50.360615969 CET347763778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:50.360709906 CET347763778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:50.361465931 CET347803778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:50.366775036 CET37783478061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:50.366867065 CET347803778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:50.367928028 CET347803778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:50.373446941 CET37783478061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:50.373518944 CET347803778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:50.378968954 CET37783478061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:50.741486073 CET37783477861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:50.741861105 CET347783778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:50.741861105 CET347783778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:50.742330074 CET347823778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:50.747396946 CET37783478261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:50.747451067 CET347823778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:50.748095036 CET347823778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:50.753151894 CET37783478261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:50.753212929 CET347823778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:50.758315086 CET37783478261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:50.951471090 CET42836443192.168.2.2391.189.91.43
                                                            Mar 7, 2025 10:53:51.351095915 CET37783478061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:51.351406097 CET347803778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:51.351406097 CET347803778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:51.352164984 CET347843778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:51.357338905 CET37783478461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:51.357486963 CET347843778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:51.358773947 CET347843778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:51.363945961 CET37783478461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:51.364016056 CET347843778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:51.369083881 CET37783478461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:51.747699976 CET37783478261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:51.747991085 CET347823778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:51.748167038 CET347823778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:51.749145985 CET347863778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:51.754314899 CET37783478661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:51.754400015 CET347863778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:51.755611897 CET347863778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:51.760721922 CET37783478661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:51.760796070 CET347863778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:51.765898943 CET37783478661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:52.370589972 CET37783478461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:52.371190071 CET347843778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:52.371190071 CET347843778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:52.371655941 CET347883778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:52.376702070 CET37783478861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:52.376763105 CET347883778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:52.377841949 CET347883778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:52.383526087 CET37783478861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:52.384078026 CET347883778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:52.389086008 CET37783478861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:52.761214972 CET37783478661.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:52.761533022 CET347863778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:52.761533022 CET347863778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:52.762284994 CET347903778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:52.768379927 CET37783479061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:52.768487930 CET347903778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:52.769438028 CET347903778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:52.775593996 CET37783479061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:52.775667906 CET347903778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:52.783673048 CET37783479061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:53.388744116 CET37783478861.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:53.389065981 CET347883778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:53.389065981 CET347883778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:53.389991045 CET347923778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:53.395071983 CET37783479261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:53.395153999 CET347923778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:53.396439075 CET347923778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:53.401438951 CET37783479261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:53.401510954 CET347923778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:53.406605005 CET37783479261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:53.763272047 CET37783479061.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:53.763487101 CET347903778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:53.763525963 CET347903778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:53.764085054 CET347943778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:53.769131899 CET37783479461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:53.769231081 CET347943778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:53.769942999 CET347943778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:53.774940014 CET37783479461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:53.775012970 CET347943778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:53:53.780086040 CET37783479461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:53:57.094660044 CET4251680192.168.2.23109.202.202.202
                                                            Mar 7, 2025 10:54:03.410975933 CET347923778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:54:03.416102886 CET37783479261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:54:03.770221949 CET37783479261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:54:03.770405054 CET347923778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:54:03.779090881 CET347943778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:54:03.784198999 CET37783479461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:54:04.140964985 CET37783479461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:54:04.141300917 CET347943778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:54:21.667464972 CET43928443192.168.2.2391.189.91.42
                                                            Mar 7, 2025 10:55:03.823187113 CET347923778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:55:03.828349113 CET37783479261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:55:04.181854010 CET37783479261.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:55:04.182123899 CET347923778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:55:04.194456100 CET347943778192.168.2.2361.7.209.115
                                                            Mar 7, 2025 10:55:04.199608088 CET37783479461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:55:04.557054043 CET37783479461.7.209.115192.168.2.23
                                                            Mar 7, 2025 10:55:04.557477951 CET347943778192.168.2.2361.7.209.115

                                                            System Behavior

                                                            Start time (UTC):09:53:18
                                                            Start date (UTC):07/03/2025
                                                            Path:/tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf
                                                            Arguments:/tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf
                                                            File size:5773336 bytes
                                                            MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                            Start time (UTC):09:53:18
                                                            Start date (UTC):07/03/2025
                                                            Path:/tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf
                                                            Arguments:-
                                                            File size:5773336 bytes
                                                            MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                            Start time (UTC):09:53:18
                                                            Start date (UTC):07/03/2025
                                                            Path:/tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf
                                                            Arguments:-
                                                            File size:5773336 bytes
                                                            MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                            Start time (UTC):09:53:18
                                                            Start date (UTC):07/03/2025
                                                            Path:/tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf
                                                            Arguments:-
                                                            File size:5773336 bytes
                                                            MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                            Start time (UTC):09:53:24
                                                            Start date (UTC):07/03/2025
                                                            Path:/tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf
                                                            Arguments:-
                                                            File size:5773336 bytes
                                                            MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                            Start time (UTC):09:53:24
                                                            Start date (UTC):07/03/2025
                                                            Path:/tmp/ub8ehJSePAfc9FYqZIT6.mpsl.elf
                                                            Arguments:-
                                                            File size:5773336 bytes
                                                            MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9