Create Interactive Tour

Linux Analysis Report
xd.x86.elf

Overview

General Information

Sample name:xd.x86.elf
Analysis ID:1654972
MD5:a68aa2179d0db1bb9cf010a4949ea024
SHA1:702e982ff2347f14703fb12bfdc53e1946566510
SHA256:83ebd86adf2f88f83af9762d2bb64ac37c4a78c393351549892e2ebe914dbe52
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:88
Range:0 - 100

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Sample deletes itself
Sample is packed with UPX
Sample reads /proc/mounts (often used for finding a writable filesystem)
Sample tries to kill multiple processes (SIGKILL)
Deletes log files
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Executes the "grep" command used to find patterns in files or piped streams
Executes the "kill" or "pkill" command typically used to terminate processes
HTTP GET or POST without a user agent
Reads CPU information from /sys indicative of miner or evasive malware
Sample contains only a LOAD segment without any section mappings
Sample tries to kill a process (SIGKILL)
Sample tries to set the executable flag
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1654972
Start date and time:2025-04-02 20:52:38 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 30s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:xd.x86.elf
Detection:MAL
Classification:mal88.spre.troj.evad.linELF@0/16@3/0
  • Connection to analysis system has been lost, crash info: Unknown
  • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
  • VT rate limit hit for: http://213.209.129.92/d/xd.arm7;chmod
  • system is lnxubuntu20
  • xd.x86.elf (PID: 6239, Parent: 6162, MD5: a68aa2179d0db1bb9cf010a4949ea024) Arguments: /tmp/xd.x86.elf
  • systemd New Fork (PID: 6255, Parent: 1)
  • journalctl (PID: 6255, Parent: 1, MD5: bf3a987344f3bacafc44efd882abda8b) Arguments: /usr/bin/journalctl --smart-relinquish-var
  • systemd New Fork (PID: 6270, Parent: 1)
  • systemd New Fork (PID: 6272, Parent: 1)
  • systemd New Fork (PID: 6273, Parent: 1)
  • systemd New Fork (PID: 6274, Parent: 1)
  • systemd New Fork (PID: 6280, Parent: 1)
  • systemd New Fork (PID: 6313, Parent: 1)
  • systemd New Fork (PID: 6334, Parent: 1)
  • systemd New Fork (PID: 6338, Parent: 1)
  • systemd New Fork (PID: 6340, Parent: 1)
  • systemd New Fork (PID: 6342, Parent: 1)
  • systemd New Fork (PID: 6343, Parent: 1)
  • gdm3 New Fork (PID: 6346, Parent: 1320)
  • Default (PID: 6346, Parent: 1320, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • gdm3 New Fork (PID: 6347, Parent: 1320)
  • Default (PID: 6347, Parent: 1320, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • gdm3 New Fork (PID: 6348, Parent: 1320)
  • Default (PID: 6348, Parent: 1320, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • systemd New Fork (PID: 6349, Parent: 1860)
  • pulseaudio (PID: 6349, Parent: 1860, MD5: 0c3b4c789d8ffb12b25507f27e14c186) Arguments: /usr/bin/pulseaudio --daemonize=no --log-target=journal
  • systemd New Fork (PID: 6350, Parent: 1)
  • systemd New Fork (PID: 6352, Parent: 1)
  • systemd New Fork (PID: 6353, Parent: 1)
  • systemd New Fork (PID: 6355, Parent: 1)
  • systemd New Fork (PID: 6357, Parent: 1)
  • gpu-manager (PID: 6357, Parent: 1, MD5: 8fae9dd5dd67e1f33d873089c2fd8761) Arguments: /usr/bin/gpu-manager --log /var/log/gpu-manager.log
    • sh (PID: 6358, Parent: 6357, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
      • sh New Fork (PID: 6359, Parent: 6358)
      • grep (PID: 6359, Parent: 6358, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
    • sh (PID: 6360, Parent: 6357, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
      • sh New Fork (PID: 6361, Parent: 6360)
      • grep (PID: 6361, Parent: 6360, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
    • sh (PID: 6362, Parent: 6357, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
      • sh New Fork (PID: 6363, Parent: 6362)
      • grep (PID: 6363, Parent: 6362, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
    • sh (PID: 6364, Parent: 6357, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
      • sh New Fork (PID: 6365, Parent: 6364)
      • grep (PID: 6365, Parent: 6364, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
    • sh (PID: 6366, Parent: 6357, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
      • sh New Fork (PID: 6367, Parent: 6366)
      • grep (PID: 6367, Parent: 6366, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
    • sh (PID: 6368, Parent: 6357, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf"
      • sh New Fork (PID: 6369, Parent: 6368)
      • grep (PID: 6369, Parent: 6368, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
    • sh (PID: 6370, Parent: 6357, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /etc/modprobe.d/*.conf"
      • sh New Fork (PID: 6371, Parent: 6370)
      • grep (PID: 6371, Parent: 6370, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*nouveau[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
    • sh (PID: 6372, Parent: 6357, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /lib/modprobe.d/*.conf"
      • sh New Fork (PID: 6373, Parent: 6372)
      • grep (PID: 6373, Parent: 6372, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*nouveau[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
  • systemd New Fork (PID: 6374, Parent: 1)
  • systemd New Fork (PID: 6375, Parent: 1)
  • generate-config (PID: 6375, Parent: 1, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /usr/share/gdm/generate-config
    • pkill (PID: 6376, Parent: 6375, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pkill --signal HUP --uid gdm dconf-service
  • systemd New Fork (PID: 6377, Parent: 1)
  • gdm-wait-for-drm (PID: 6377, Parent: 1, MD5: 82043ba752c6930b4e6aaea2f7747545) Arguments: /usr/lib/gdm3/gdm-wait-for-drm
  • gdm3 (PID: 6378, Parent: 1, MD5: 2492e2d8d34f9377e3e530a61a15674f) Arguments: /usr/sbin/gdm3
  • fusermount (PID: 6398, Parent: 2038, MD5: 576a1b135c82bdcbc97a91acea900566) Arguments: fusermount -u -q -z -- /run/user/1000/gvfs
  • gpu-manager (PID: 6407, Parent: 1, MD5: 8fae9dd5dd67e1f33d873089c2fd8761) Arguments: /usr/bin/gpu-manager --log /var/log/gpu-manager.log
  • gpu-manager (PID: 6418, Parent: 1, MD5: 8fae9dd5dd67e1f33d873089c2fd8761) Arguments: /usr/bin/gpu-manager --log /var/log/gpu-manager.log
  • gpu-manager (PID: 6428, Parent: 1, MD5: 8fae9dd5dd67e1f33d873089c2fd8761) Arguments: /usr/bin/gpu-manager --log /var/log/gpu-manager.log
  • gpu-manager (PID: 6438, Parent: 1, MD5: 8fae9dd5dd67e1f33d873089c2fd8761) Arguments: /usr/bin/gpu-manager --log /var/log/gpu-manager.log
  • gpu-manager (PID: 6448, Parent: 1, MD5: 8fae9dd5dd67e1f33d873089c2fd8761) Arguments: /usr/bin/gpu-manager --log /var/log/gpu-manager.log
  • plymouth (PID: 6458, Parent: 1, MD5: 87003efd8dad470042f5e75360a8f49f) Arguments: /bin/plymouth quit
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
6247.1.0000000008048000.000000000805b000.r-x.sdmpJoeSecurity_Mirai_9Yara detected MiraiJoe Security
    6247.1.0000000008048000.000000000805b000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      6247.1.0000000008048000.000000000805b000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x10a04:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10a18:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10a2c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10a40:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10a54:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10a68:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10a7c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10a90:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10aa4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10ab8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10acc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10ae0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10af4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10b08:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10b1c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10b30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10b44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10b58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10b6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10b80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10b94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      6247.1.0000000008048000.000000000805b000.r-x.sdmpLinux_Trojan_Gafgyt_ea92cca8unknownunknown
      • 0x109b4:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
      6247.1.0000000008048000.000000000805b000.r-x.sdmpLinux_Trojan_Mirai_fa3ad9d0unknownunknown
      • 0x46a:$a: CB 08 C1 CB 10 66 C1 CB 08 31 C9 8A 4F 14 D3 E8 01 D8 66 C1
      Click to see the 142 entries
      No Suricata rule has matched

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: xd.x86.elfVirustotal: Detection: 44%Perma Link
      Source: xd.x86.elfReversingLabs: Detection: 44%
      Source: /usr/bin/pulseaudio (PID: 6349)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/bin/pkill (PID: 6376)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: global trafficTCP traffic: 192.168.2.23:52458 -> 213.209.129.92:5466
      Source: global trafficHTTP traffic detected: POST /9aadafe2051348cd32033e1cad68f0a5fe46fba3240ac1e6e42158f31b8a1371790c09baf3996b4979fe8e533446c7dedf30f654c68b25357334c66911dc6a9e HTTP/1.1Host: daisy.ubuntu.comAccept: */*Content-Type: application/octet-streamX-Whoopsie-Version: 0.2.69ubuntu0.3Content-Length: 164887Expect: 100-continue
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
      Source: unknownTCP traffic detected without corresponding DNS query: 213.209.129.92
      Source: unknownTCP traffic detected without corresponding DNS query: 169.215.144.10
      Source: unknownTCP traffic detected without corresponding DNS query: 47.87.11.30
      Source: unknownTCP traffic detected without corresponding DNS query: 4.28.41.149
      Source: unknownTCP traffic detected without corresponding DNS query: 158.61.178.139
      Source: unknownTCP traffic detected without corresponding DNS query: 255.63.145.10
      Source: unknownTCP traffic detected without corresponding DNS query: 107.123.90.207
      Source: unknownTCP traffic detected without corresponding DNS query: 9.197.239.158
      Source: unknownTCP traffic detected without corresponding DNS query: 156.21.135.156
      Source: unknownTCP traffic detected without corresponding DNS query: 40.163.239.10
      Source: unknownTCP traffic detected without corresponding DNS query: 70.11.84.139
      Source: unknownTCP traffic detected without corresponding DNS query: 100.20.8.101
      Source: unknownTCP traffic detected without corresponding DNS query: 253.127.82.33
      Source: unknownTCP traffic detected without corresponding DNS query: 48.30.219.11
      Source: unknownTCP traffic detected without corresponding DNS query: 12.44.125.253
      Source: unknownTCP traffic detected without corresponding DNS query: 39.76.17.251
      Source: unknownTCP traffic detected without corresponding DNS query: 120.245.117.68
      Source: unknownTCP traffic detected without corresponding DNS query: 41.30.204.182
      Source: unknownTCP traffic detected without corresponding DNS query: 119.27.204.69
      Source: unknownTCP traffic detected without corresponding DNS query: 167.18.52.210
      Source: unknownTCP traffic detected without corresponding DNS query: 172.253.65.27
      Source: unknownTCP traffic detected without corresponding DNS query: 167.214.104.35
      Source: unknownTCP traffic detected without corresponding DNS query: 201.95.4.5
      Source: unknownTCP traffic detected without corresponding DNS query: 246.247.43.151
      Source: unknownTCP traffic detected without corresponding DNS query: 54.61.204.205
      Source: unknownTCP traffic detected without corresponding DNS query: 241.176.87.166
      Source: unknownTCP traffic detected without corresponding DNS query: 44.85.147.86
      Source: unknownTCP traffic detected without corresponding DNS query: 206.74.75.34
      Source: unknownTCP traffic detected without corresponding DNS query: 122.97.211.231
      Source: unknownTCP traffic detected without corresponding DNS query: 152.17.14.139
      Source: unknownTCP traffic detected without corresponding DNS query: 19.85.55.235
      Source: unknownTCP traffic detected without corresponding DNS query: 184.65.234.252
      Source: unknownTCP traffic detected without corresponding DNS query: 207.155.231.56
      Source: unknownTCP traffic detected without corresponding DNS query: 209.197.66.88
      Source: unknownTCP traffic detected without corresponding DNS query: 106.228.163.98
      Source: unknownTCP traffic detected without corresponding DNS query: 182.36.33.221
      Source: unknownTCP traffic detected without corresponding DNS query: 213.164.164.92
      Source: unknownTCP traffic detected without corresponding DNS query: 93.89.77.200
      Source: unknownTCP traffic detected without corresponding DNS query: 118.204.41.47
      Source: unknownTCP traffic detected without corresponding DNS query: 200.225.68.75
      Source: unknownTCP traffic detected without corresponding DNS query: 247.142.152.39
      Source: unknownTCP traffic detected without corresponding DNS query: 116.0.199.232
      Source: unknownTCP traffic detected without corresponding DNS query: 240.217.248.41
      Source: unknownTCP traffic detected without corresponding DNS query: 95.228.158.200
      Source: unknownTCP traffic detected without corresponding DNS query: 165.34.166.8
      Source: unknownTCP traffic detected without corresponding DNS query: 116.119.70.122
      Source: unknownTCP traffic detected without corresponding DNS query: 213.13.6.26
      Source: unknownTCP traffic detected without corresponding DNS query: 223.20.71.83
      Source: unknownTCP traffic detected without corresponding DNS query: 12.191.72.123
      Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
      Source: unknownHTTP traffic detected: POST /9aadafe2051348cd32033e1cad68f0a5fe46fba3240ac1e6e42158f31b8a1371790c09baf3996b4979fe8e533446c7dedf30f654c68b25357334c66911dc6a9e HTTP/1.1Host: daisy.ubuntu.comAccept: */*Content-Type: application/octet-streamX-Whoopsie-Version: 0.2.69ubuntu0.3Content-Length: 164887Expect: 100-continue
      Source: xd.x86.elf, 6239.1.0000000008048000.000000000805b000.r-x.sdmp, xd.x86.elf, 6241.1.0000000008048000.000000000805b000.r-x.sdmp, xd.x86.elf, 6242.1.0000000008048000.000000000805b000.r-x.sdmp, xd.x86.elf, 6243.1.0000000008048000.000000000805b000.r-x.sdmp, xd.x86.elf, 6246.1.0000000008048000.000000000805b000.r-x.sdmp, xd.x86.elf, 6247.1.0000000008048000.000000000805b000.r-x.sdmp, xd.x86.elf, 6249.1.0000000008048000.000000000805b000.r-x.sdmpString found in binary or memory: http://213.209.129.92/d/xd.arm7;chmod
      Source: xd.x86.elfString found in binary or memory: http://upx.sf.net
      Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 37606 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 37606
      Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

      System Summary

      barindex
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 Author: unknown
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_93fc3657 Author: unknown
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_804f8e7c Author: unknown
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_99d78950 Author: unknown
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_aa39fb02 Author: unknown
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_a68e498c Author: unknown
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 Author: unknown
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_93fc3657 Author: unknown
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_804f8e7c Author: unknown
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_99d78950 Author: unknown
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_aa39fb02 Author: unknown
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_a68e498c Author: unknown
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 Author: unknown
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_93fc3657 Author: unknown
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 Author: unknown
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_93fc3657 Author: unknown
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_804f8e7c Author: unknown
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_99d78950 Author: unknown
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_aa39fb02 Author: unknown
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_a68e498c Author: unknown
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_804f8e7c Author: unknown
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_99d78950 Author: unknown
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_aa39fb02 Author: unknown
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_a68e498c Author: unknown
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 Author: unknown
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 Author: unknown
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_93fc3657 Author: unknown
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_804f8e7c Author: unknown
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_99d78950 Author: unknown
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_aa39fb02 Author: unknown
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_a68e498c Author: unknown
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 Author: unknown
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_93fc3657 Author: unknown
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_804f8e7c Author: unknown
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_99d78950 Author: unknown
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_aa39fb02 Author: unknown
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_a68e498c Author: unknown
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_93fc3657 Author: unknown
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_804f8e7c Author: unknown
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_99d78950 Author: unknown
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_aa39fb02 Author: unknown
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_a68e498c Author: unknown
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
      Source: Process Memory Space: xd.x86.elf PID: 6239, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: Process Memory Space: xd.x86.elf PID: 6239, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: Process Memory Space: xd.x86.elf PID: 6241, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: Process Memory Space: xd.x86.elf PID: 6241, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: Process Memory Space: xd.x86.elf PID: 6242, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: Process Memory Space: xd.x86.elf PID: 6242, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: Process Memory Space: xd.x86.elf PID: 6243, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: Process Memory Space: xd.x86.elf PID: 6243, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: Process Memory Space: xd.x86.elf PID: 6246, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: Process Memory Space: xd.x86.elf PID: 6246, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: Process Memory Space: xd.x86.elf PID: 6247, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: Process Memory Space: xd.x86.elf PID: 6247, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: Process Memory Space: xd.x86.elf PID: 6249, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: Process Memory Space: xd.x86.elf PID: 6249, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 936, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 491, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 720, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 721, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 759, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 761, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 772, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 774, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 777, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 785, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 788, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 789, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 793, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 797, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 1334, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 1335, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 1344, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 1860, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 1872, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 1886, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 2009, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 2048, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 6067, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 6222, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 6223, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 6341, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 6349, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 6378, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6242)SIGKILL sent: pid: -6242, result: unknownJump to behavior
      Source: LOAD without section mappingsProgram segment: 0xc01000
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 936, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 491, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 720, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 721, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 759, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 761, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 772, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 774, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 777, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 785, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 788, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 789, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 793, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 797, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 1334, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 1335, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 1344, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 1860, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 1872, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 1886, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 2009, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 2048, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 6067, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 6222, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 6223, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 6341, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 6349, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)SIGKILL sent: pid: 6378, result: successfulJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6242)SIGKILL sent: pid: -6242, result: unknownJump to behavior
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = fe93a3552b72b107f95cc5a7e59da64fe84d31df833bf36c81d8f31d8d79d7ca, id = fa3ad9d0-7c55-4621-90fc-6b154c44a67b, last_modified = 2021-09-16
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_93fc3657 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = d01a9e85a01fad913ca048b60bda1e5a2762f534e5308132c1d3098ac3f561ee, id = 93fc3657-fd21-4e93-a728-c084fc0a6a4a, last_modified = 2021-09-16
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_804f8e7c reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 1080d8502848d532a0b38861437485d98a41d945acaf3cb676a7a2a2f6793ac6, id = 804f8e7c-4786-42bc-92e4-c68c24ca530e, last_modified = 2021-09-16
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_99d78950 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3008edc4e7a099b64139a77d15ec0e2c3c1b55fc23ab156304571c4d14bc654c, id = 99d78950-ea23-4166-a85a-7a029209f5b1, last_modified = 2021-09-16
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_aa39fb02 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = b136ba6496816ba9737a3eb0e633c28a337511a97505f06e52f37b38599587cb, id = aa39fb02-ca7e-4809-ab5d-00e92763f7ec, last_modified = 2021-09-16
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_a68e498c reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 951c9dfcba531e5112c872395f6c144c4bc8b71c666d2c7d9d8574a23c163883, id = a68e498c-0768-4321-ab65-42dd6ef85323, last_modified = 2021-09-16
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = fe93a3552b72b107f95cc5a7e59da64fe84d31df833bf36c81d8f31d8d79d7ca, id = fa3ad9d0-7c55-4621-90fc-6b154c44a67b, last_modified = 2021-09-16
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_93fc3657 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = d01a9e85a01fad913ca048b60bda1e5a2762f534e5308132c1d3098ac3f561ee, id = 93fc3657-fd21-4e93-a728-c084fc0a6a4a, last_modified = 2021-09-16
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_804f8e7c reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 1080d8502848d532a0b38861437485d98a41d945acaf3cb676a7a2a2f6793ac6, id = 804f8e7c-4786-42bc-92e4-c68c24ca530e, last_modified = 2021-09-16
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_99d78950 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3008edc4e7a099b64139a77d15ec0e2c3c1b55fc23ab156304571c4d14bc654c, id = 99d78950-ea23-4166-a85a-7a029209f5b1, last_modified = 2021-09-16
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_aa39fb02 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = b136ba6496816ba9737a3eb0e633c28a337511a97505f06e52f37b38599587cb, id = aa39fb02-ca7e-4809-ab5d-00e92763f7ec, last_modified = 2021-09-16
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_a68e498c reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 951c9dfcba531e5112c872395f6c144c4bc8b71c666d2c7d9d8574a23c163883, id = a68e498c-0768-4321-ab65-42dd6ef85323, last_modified = 2021-09-16
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = fe93a3552b72b107f95cc5a7e59da64fe84d31df833bf36c81d8f31d8d79d7ca, id = fa3ad9d0-7c55-4621-90fc-6b154c44a67b, last_modified = 2021-09-16
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_93fc3657 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = d01a9e85a01fad913ca048b60bda1e5a2762f534e5308132c1d3098ac3f561ee, id = 93fc3657-fd21-4e93-a728-c084fc0a6a4a, last_modified = 2021-09-16
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = fe93a3552b72b107f95cc5a7e59da64fe84d31df833bf36c81d8f31d8d79d7ca, id = fa3ad9d0-7c55-4621-90fc-6b154c44a67b, last_modified = 2021-09-16
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_93fc3657 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = d01a9e85a01fad913ca048b60bda1e5a2762f534e5308132c1d3098ac3f561ee, id = 93fc3657-fd21-4e93-a728-c084fc0a6a4a, last_modified = 2021-09-16
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_804f8e7c reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 1080d8502848d532a0b38861437485d98a41d945acaf3cb676a7a2a2f6793ac6, id = 804f8e7c-4786-42bc-92e4-c68c24ca530e, last_modified = 2021-09-16
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_99d78950 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3008edc4e7a099b64139a77d15ec0e2c3c1b55fc23ab156304571c4d14bc654c, id = 99d78950-ea23-4166-a85a-7a029209f5b1, last_modified = 2021-09-16
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_aa39fb02 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = b136ba6496816ba9737a3eb0e633c28a337511a97505f06e52f37b38599587cb, id = aa39fb02-ca7e-4809-ab5d-00e92763f7ec, last_modified = 2021-09-16
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_a68e498c reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 951c9dfcba531e5112c872395f6c144c4bc8b71c666d2c7d9d8574a23c163883, id = a68e498c-0768-4321-ab65-42dd6ef85323, last_modified = 2021-09-16
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_804f8e7c reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 1080d8502848d532a0b38861437485d98a41d945acaf3cb676a7a2a2f6793ac6, id = 804f8e7c-4786-42bc-92e4-c68c24ca530e, last_modified = 2021-09-16
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_99d78950 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3008edc4e7a099b64139a77d15ec0e2c3c1b55fc23ab156304571c4d14bc654c, id = 99d78950-ea23-4166-a85a-7a029209f5b1, last_modified = 2021-09-16
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_aa39fb02 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = b136ba6496816ba9737a3eb0e633c28a337511a97505f06e52f37b38599587cb, id = aa39fb02-ca7e-4809-ab5d-00e92763f7ec, last_modified = 2021-09-16
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_a68e498c reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 951c9dfcba531e5112c872395f6c144c4bc8b71c666d2c7d9d8574a23c163883, id = a68e498c-0768-4321-ab65-42dd6ef85323, last_modified = 2021-09-16
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = fe93a3552b72b107f95cc5a7e59da64fe84d31df833bf36c81d8f31d8d79d7ca, id = fa3ad9d0-7c55-4621-90fc-6b154c44a67b, last_modified = 2021-09-16
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = fe93a3552b72b107f95cc5a7e59da64fe84d31df833bf36c81d8f31d8d79d7ca, id = fa3ad9d0-7c55-4621-90fc-6b154c44a67b, last_modified = 2021-09-16
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_93fc3657 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = d01a9e85a01fad913ca048b60bda1e5a2762f534e5308132c1d3098ac3f561ee, id = 93fc3657-fd21-4e93-a728-c084fc0a6a4a, last_modified = 2021-09-16
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_804f8e7c reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 1080d8502848d532a0b38861437485d98a41d945acaf3cb676a7a2a2f6793ac6, id = 804f8e7c-4786-42bc-92e4-c68c24ca530e, last_modified = 2021-09-16
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_99d78950 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3008edc4e7a099b64139a77d15ec0e2c3c1b55fc23ab156304571c4d14bc654c, id = 99d78950-ea23-4166-a85a-7a029209f5b1, last_modified = 2021-09-16
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_aa39fb02 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = b136ba6496816ba9737a3eb0e633c28a337511a97505f06e52f37b38599587cb, id = aa39fb02-ca7e-4809-ab5d-00e92763f7ec, last_modified = 2021-09-16
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_a68e498c reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 951c9dfcba531e5112c872395f6c144c4bc8b71c666d2c7d9d8574a23c163883, id = a68e498c-0768-4321-ab65-42dd6ef85323, last_modified = 2021-09-16
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = fe93a3552b72b107f95cc5a7e59da64fe84d31df833bf36c81d8f31d8d79d7ca, id = fa3ad9d0-7c55-4621-90fc-6b154c44a67b, last_modified = 2021-09-16
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_93fc3657 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = d01a9e85a01fad913ca048b60bda1e5a2762f534e5308132c1d3098ac3f561ee, id = 93fc3657-fd21-4e93-a728-c084fc0a6a4a, last_modified = 2021-09-16
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_804f8e7c reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 1080d8502848d532a0b38861437485d98a41d945acaf3cb676a7a2a2f6793ac6, id = 804f8e7c-4786-42bc-92e4-c68c24ca530e, last_modified = 2021-09-16
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_99d78950 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3008edc4e7a099b64139a77d15ec0e2c3c1b55fc23ab156304571c4d14bc654c, id = 99d78950-ea23-4166-a85a-7a029209f5b1, last_modified = 2021-09-16
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_aa39fb02 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = b136ba6496816ba9737a3eb0e633c28a337511a97505f06e52f37b38599587cb, id = aa39fb02-ca7e-4809-ab5d-00e92763f7ec, last_modified = 2021-09-16
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_a68e498c reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 951c9dfcba531e5112c872395f6c144c4bc8b71c666d2c7d9d8574a23c163883, id = a68e498c-0768-4321-ab65-42dd6ef85323, last_modified = 2021-09-16
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_93fc3657 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = d01a9e85a01fad913ca048b60bda1e5a2762f534e5308132c1d3098ac3f561ee, id = 93fc3657-fd21-4e93-a728-c084fc0a6a4a, last_modified = 2021-09-16
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_804f8e7c reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 1080d8502848d532a0b38861437485d98a41d945acaf3cb676a7a2a2f6793ac6, id = 804f8e7c-4786-42bc-92e4-c68c24ca530e, last_modified = 2021-09-16
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_99d78950 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3008edc4e7a099b64139a77d15ec0e2c3c1b55fc23ab156304571c4d14bc654c, id = 99d78950-ea23-4166-a85a-7a029209f5b1, last_modified = 2021-09-16
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_aa39fb02 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = b136ba6496816ba9737a3eb0e633c28a337511a97505f06e52f37b38599587cb, id = aa39fb02-ca7e-4809-ab5d-00e92763f7ec, last_modified = 2021-09-16
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_a68e498c reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 951c9dfcba531e5112c872395f6c144c4bc8b71c666d2c7d9d8574a23c163883, id = a68e498c-0768-4321-ab65-42dd6ef85323, last_modified = 2021-09-16
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
      Source: Process Memory Space: xd.x86.elf PID: 6239, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: Process Memory Space: xd.x86.elf PID: 6239, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: Process Memory Space: xd.x86.elf PID: 6241, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: Process Memory Space: xd.x86.elf PID: 6241, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: Process Memory Space: xd.x86.elf PID: 6242, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: Process Memory Space: xd.x86.elf PID: 6242, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: Process Memory Space: xd.x86.elf PID: 6243, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: Process Memory Space: xd.x86.elf PID: 6243, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: Process Memory Space: xd.x86.elf PID: 6246, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: Process Memory Space: xd.x86.elf PID: 6246, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: Process Memory Space: xd.x86.elf PID: 6247, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: Process Memory Space: xd.x86.elf PID: 6247, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: Process Memory Space: xd.x86.elf PID: 6249, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: Process Memory Space: xd.x86.elf PID: 6249, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: classification engineClassification label: mal88.spre.troj.evad.linELF@0/16@3/0

      Data Obfuscation

      barindex
      Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
      Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
      Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $

      Persistence and Installation Behavior

      barindex
      Source: /bin/fusermount (PID: 6398)File: /proc/6398/mountsJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/6196/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/1582/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/2033/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/3088/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/1579/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/1576/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/2302/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/910/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/4444/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/4445/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/912/fdJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/912/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/4446/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/759/fdJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/517/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/4447/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/2307/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/918/fdJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/918/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/6240/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/1594/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/2285/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/2281/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/1349/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/1/fdJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/761/fdJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/884/fdJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/884/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/2038/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/1465/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/1586/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/1463/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/800/fdJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/800/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/801/fdJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/801/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/3021/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/491/fdJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/2294/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/772/fdJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/1599/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/774/fdJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/1477/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/654/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/896/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/1476/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/655/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/1475/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/2289/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/656/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/777/fdJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/657/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/658/fdJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/658/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/936/fdJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/419/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/6407/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/2208/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/2180/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/4481/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/4486/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/1494/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/420/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/1489/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/785/fdJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/667/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/788/fdJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/789/fdJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/4477/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/670/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/4490/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/2746/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/793/fdJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/674/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/1532/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/675/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/796/fdJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/796/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/676/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/797/fdJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/677/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/799/fdJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/799/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/2749/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/1389/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/840/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/720/fdJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/721/fdJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/847/fdJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/847/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/6335/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/2128/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/2761/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/2882/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/6448/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/6460/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/6187/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/4442/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/4443/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/1601/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/2018/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/2014/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/1320/exeJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/904/fdJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File opened: /proc/904/exeJump to behavior
      Source: /usr/bin/gpu-manager (PID: 6358)Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"Jump to behavior
      Source: /usr/bin/gpu-manager (PID: 6360)Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"Jump to behavior
      Source: /usr/bin/gpu-manager (PID: 6362)Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"Jump to behavior
      Source: /usr/bin/gpu-manager (PID: 6364)Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"Jump to behavior
      Source: /usr/bin/gpu-manager (PID: 6366)Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"Jump to behavior
      Source: /usr/bin/gpu-manager (PID: 6368)Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf"Jump to behavior
      Source: /usr/bin/gpu-manager (PID: 6370)Shell command executed: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /etc/modprobe.d/*.conf"Jump to behavior
      Source: /usr/bin/gpu-manager (PID: 6372)Shell command executed: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /lib/modprobe.d/*.conf"Jump to behavior
      Source: /bin/sh (PID: 6359)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.confJump to behavior
      Source: /bin/sh (PID: 6361)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.confJump to behavior
      Source: /bin/sh (PID: 6363)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.confJump to behavior
      Source: /bin/sh (PID: 6365)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.confJump to behavior
      Source: /bin/sh (PID: 6367)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.confJump to behavior
      Source: /bin/sh (PID: 6369)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.confJump to behavior
      Source: /bin/sh (PID: 6371)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nouveau[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.confJump to behavior
      Source: /bin/sh (PID: 6373)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nouveau[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.confJump to behavior
      Source: /usr/share/gdm/generate-config (PID: 6376)Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-serviceJump to behavior
      Source: /usr/sbin/gdm3 (PID: 6378)File: /var/run/gdm3 (bits: - usr: -x grp: x all: rwx)Jump to behavior
      Source: /usr/sbin/gdm3 (PID: 6378)File: /var/log/gdm3 (bits: - usr: -x grp: x all: rwx)Jump to behavior
      Source: /usr/bin/gpu-manager (PID: 6357)Log file created: /var/log/gpu-manager.log
      Source: /usr/bin/gpu-manager (PID: 6407)Log file created: /var/log/gpu-manager.log
      Source: /usr/bin/gpu-manager (PID: 6418)Log file created: /var/log/gpu-manager.log
      Source: /usr/bin/gpu-manager (PID: 6428)Log file created: /var/log/gpu-manager.log
      Source: /usr/bin/gpu-manager (PID: 6438)Log file created: /var/log/gpu-manager.log
      Source: /usr/bin/gpu-manager (PID: 6448)Log file created: /var/log/gpu-manager.logJump to dropped file

      Hooking and other Techniques for Hiding and Protection

      barindex
      Source: /tmp/xd.x86.elf (PID: 6240)File: /usr/lib/systemd/systemdJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File: /usr/lib/systemd/systemd (deleted)Jump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File: /usr/bin/pulseaudioJump to behavior
      Source: /tmp/xd.x86.elf (PID: 6240)File: /usr/sbin/gdm3Jump to behavior
      Source: xd.x86.elfSubmission file: segment LOAD with 7.9601 entropy (max. 8.0)
      Source: /usr/bin/gpu-manager (PID: 6357)Truncated file: /var/log/gpu-manager.logJump to behavior
      Source: /usr/bin/gpu-manager (PID: 6407)Truncated file: /var/log/gpu-manager.logJump to behavior
      Source: /usr/bin/gpu-manager (PID: 6418)Truncated file: /var/log/gpu-manager.logJump to behavior
      Source: /usr/bin/gpu-manager (PID: 6428)Truncated file: /var/log/gpu-manager.logJump to behavior
      Source: /usr/bin/gpu-manager (PID: 6438)Truncated file: /var/log/gpu-manager.logJump to behavior
      Source: /usr/bin/gpu-manager (PID: 6448)Truncated file: /var/log/gpu-manager.logJump to behavior
      Source: /usr/bin/pulseaudio (PID: 6349)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/bin/pkill (PID: 6376)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
      Source: /usr/bin/pulseaudio (PID: 6349)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/bin/gpu-manager (PID: 6357)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/bin/gpu-manager (PID: 6407)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/bin/gpu-manager (PID: 6418)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/bin/gpu-manager (PID: 6428)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/bin/gpu-manager (PID: 6438)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/bin/gpu-manager (PID: 6448)Queries kernel information via 'uname': Jump to behavior

      Stealing of Sensitive Information

      barindex
      Source: Yara matchFile source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: xd.x86.elf PID: 6239, type: MEMORYSTR
      Source: Yara matchFile source: Process Memory Space: xd.x86.elf PID: 6241, type: MEMORYSTR
      Source: Yara matchFile source: Process Memory Space: xd.x86.elf PID: 6242, type: MEMORYSTR
      Source: Yara matchFile source: Process Memory Space: xd.x86.elf PID: 6243, type: MEMORYSTR
      Source: Yara matchFile source: Process Memory Space: xd.x86.elf PID: 6246, type: MEMORYSTR
      Source: Yara matchFile source: Process Memory Space: xd.x86.elf PID: 6247, type: MEMORYSTR
      Source: Yara matchFile source: Process Memory Space: xd.x86.elf PID: 6249, type: MEMORYSTR

      Remote Access Functionality

      barindex
      Source: Yara matchFile source: 6247.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6249.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6239.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6243.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6242.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6241.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6246.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: xd.x86.elf PID: 6239, type: MEMORYSTR
      Source: Yara matchFile source: Process Memory Space: xd.x86.elf PID: 6241, type: MEMORYSTR
      Source: Yara matchFile source: Process Memory Space: xd.x86.elf PID: 6242, type: MEMORYSTR
      Source: Yara matchFile source: Process Memory Space: xd.x86.elf PID: 6243, type: MEMORYSTR
      Source: Yara matchFile source: Process Memory Space: xd.x86.elf PID: 6246, type: MEMORYSTR
      Source: Yara matchFile source: Process Memory Space: xd.x86.elf PID: 6247, type: MEMORYSTR
      Source: Yara matchFile source: Process Memory Space: xd.x86.elf PID: 6249, type: MEMORYSTR
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity Information1
      Scripting
      Valid AccountsWindows Management Instrumentation1
      Scripting
      Path Interception1
      File and Directory Permissions Modification
      1
      OS Credential Dumping
      1
      Security Software Discovery
      Remote ServicesData from Local System1
      Encrypted Channel
      Exfiltration Over Other Network Medium1
      Service Stop
      CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
      Disable or Modify Tools
      LSASS Memory1
      File and Directory Discovery
      Remote Desktop ProtocolData from Removable Media1
      Non-Standard Port
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)11
      Obfuscated Files or Information
      Security Account Manager1
      System Information Discovery
      SMB/Windows Admin SharesData from Network Shared Drive2
      Non-Application Layer Protocol
      Automated ExfiltrationData Encrypted for Impact
      Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
      Indicator Removal
      NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
      Application Layer Protocol
      Traffic DuplicationData Destruction
      Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
      File Deletion
      LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
      No configs have been found
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Number of created Files
      • Is malicious
      • Internet
      behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1654972 Sample: xd.x86.elf Startdate: 02/04/2025 Architecture: LINUX Score: 88 54 82.71.126.99, 80 ZEN-ASZenInternet-UKGB United Kingdom 2->54 56 80.101.145.38, 80 XS4ALL-NLAmsterdamNL Netherlands 2->56 58 99 other IPs or domains 2->58 64 Malicious sample detected (through community Yara rule) 2->64 66 Multi AV Scanner detection for submitted file 2->66 68 Yara detected Mirai 2->68 70 Sample is packed with UPX 2->70 8 xd.x86.elf 2->8         started        10 systemd gpu-manager 2->10         started        12 gvfsd-fuse fusermount 2->12         started        15 46 other processes 2->15 signatures3 process4 signatures5 17 xd.x86.elf 8->17         started        20 xd.x86.elf 8->20         started        22 xd.x86.elf 8->22         started        24 gpu-manager sh 10->24         started        26 gpu-manager sh 10->26         started        28 gpu-manager sh 10->28         started        32 5 other processes 10->32 72 Sample reads /proc/mounts (often used for finding a writable filesystem) 12->72 30 generate-config pkill 15->30         started        34 40 other processes 15->34 process6 signatures7 60 Sample tries to kill multiple processes (SIGKILL) 17->60 62 Sample deletes itself 17->62 36 xd.x86.elf 20->36         started        50 3 other processes 20->50 38 sh grep 24->38         started        40 sh grep 26->40         started        42 sh grep 28->42         started        44 sh grep 32->44         started        46 sh grep 32->46         started        48 sh grep 32->48         started        52 2 other processes 32->52 process8
      SourceDetectionScannerLabelLink
      xd.x86.elf45%VirustotalBrowse
      xd.x86.elf44%ReversingLabsLinux.Backdoor.Mirai
      No Antivirus matches
      No Antivirus matches
      SourceDetectionScannerLabelLink
      http://213.209.129.92/d/xd.arm7;chmod0%Avira URL Cloudsafe

      Download Network PCAP: filteredfull

      NameIPActiveMaliciousAntivirus DetectionReputation
      daisy.ubuntu.com
      162.213.35.25
      truefalse
        high
        NameMaliciousAntivirus DetectionReputation
        https://daisy.ubuntu.com/9aadafe2051348cd32033e1cad68f0a5fe46fba3240ac1e6e42158f31b8a1371790c09baf3996b4979fe8e533446c7dedf30f654c68b25357334c66911dc6a9efalse
          high
          NameSourceMaliciousAntivirus DetectionReputation
          http://213.209.129.92/d/xd.arm7;chmodxd.x86.elf, 6239.1.0000000008048000.000000000805b000.r-x.sdmp, xd.x86.elf, 6241.1.0000000008048000.000000000805b000.r-x.sdmp, xd.x86.elf, 6242.1.0000000008048000.000000000805b000.r-x.sdmp, xd.x86.elf, 6243.1.0000000008048000.000000000805b000.r-x.sdmp, xd.x86.elf, 6246.1.0000000008048000.000000000805b000.r-x.sdmp, xd.x86.elf, 6247.1.0000000008048000.000000000805b000.r-x.sdmp, xd.x86.elf, 6249.1.0000000008048000.000000000805b000.r-x.sdmpfalse
          • Avira URL Cloud: safe
          unknown
          http://upx.sf.netxd.x86.elffalse
            high
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            206.101.207.91
            unknownUnited States
            7991CENTURYLINK-LEGACY-SAVVIS-ASIA-TRANSITUSfalse
            169.237.160.237
            unknownUnited States
            6192UCDAVIS-COREUSfalse
            213.217.82.126
            unknownGermany
            20676PLUSNETDEfalse
            181.158.241.99
            unknownColombia
            26611COMCELSACOfalse
            80.228.156.254
            unknownGermany
            9145EWETELCloppenburgerStrasse310DEfalse
            86.67.119.95
            unknownFrance
            15557LDCOMNETFRfalse
            113.7.118.19
            unknownChina
            4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
            181.20.184.199
            unknownArgentina
            22927TelefonicadeArgentinaARfalse
            86.59.69.139
            unknownAustria
            8437UTA-ASATfalse
            169.175.68.33
            unknownUnited States
            37611AfrihostZAfalse
            181.45.150.248
            unknownArgentina
            27747TelecentroSAARfalse
            206.187.0.14
            unknownUnited States
            3602AS3602-ROGERS-COMCAfalse
            83.160.194.110
            unknownNetherlands
            3265XS4ALL-NLAmsterdamNLfalse
            82.57.85.63
            unknownItaly
            3269ASN-IBSNAZITfalse
            83.227.3.102
            unknownSweden
            2119TELENOR-NEXTELTelenorNorgeASNOfalse
            80.11.161.194
            unknownFrance
            3215FranceTelecom-OrangeFRfalse
            200.214.152.243
            unknownBrazil
            4230CLAROSABRfalse
            178.140.112.236
            unknownRussian Federation
            42610NCNET-ASRUfalse
            86.97.78.117
            unknownUnited Arab Emirates
            5384EMIRATES-INTERNETEmiratesInternetAEfalse
            86.93.133.29
            unknownNetherlands
            1136KPNKPNNationalEUfalse
            200.53.178.42
            unknownMexico
            22011SixsigmaNetworksMexicoSAdeCVMXfalse
            86.142.163.126
            unknownUnited Kingdom
            2856BT-UK-ASBTnetUKRegionalnetworkGBfalse
            83.92.228.104
            unknownDenmark
            3292TDCTDCASDKfalse
            200.142.228.12
            unknownunknown
            26607IBMBrasilIndustriaMaquinaseServicosLTDABRfalse
            80.71.52.194
            unknownMalta
            34410VANILLA-TELECOMS-LTD-MALTA-ASMTfalse
            213.138.4.112
            unknownFrance
            12684SES-LUX-ASLUfalse
            200.86.64.20
            unknownChile
            22047VTRBANDAANCHASACLfalse
            86.220.89.56
            unknownFrance
            3215FranceTelecom-OrangeFRfalse
            181.215.136.220
            unknownChile
            61317ASDETUKhttpwwwheficedcomGBfalse
            181.236.2.28
            unknownColombia
            3816COLOMBIATELECOMUNICACIONESSAESPCOfalse
            200.124.103.107
            unknownArgentina
            22080BroadbandtechSAARfalse
            213.79.252.4
            unknownSweden
            12501NORRNODITSSEfalse
            68.83.210.121
            unknownUnited States
            7922COMCAST-7922USfalse
            86.77.25.0
            unknownFrance
            15557LDCOMNETFRfalse
            82.71.126.99
            unknownUnited Kingdom
            13037ZEN-ASZenInternet-UKGBfalse
            41.30.204.182
            unknownSouth Africa
            29975VODACOM-ZAfalse
            206.243.46.192
            unknownUnited States
            3356LEVEL3USfalse
            82.15.18.196
            unknownUnited Kingdom
            5089NTLGBfalse
            83.27.225.42
            unknownPoland
            5617TPNETPLfalse
            86.37.4.168
            unknownQatar
            29384QATAR-FOUNDATIONQAfalse
            86.97.156.4
            unknownUnited Arab Emirates
            5384EMIRATES-INTERNETEmiratesInternetAEfalse
            86.211.10.107
            unknownFrance
            3215FranceTelecom-OrangeFRfalse
            83.82.161.209
            unknownNetherlands
            33915TNF-ASNLfalse
            181.124.169.247
            unknownParaguay
            23201TelecelSAPYfalse
            181.187.147.207
            unknownVenezuela
            262210VIETTELPERUSACPEfalse
            83.240.30.140
            unknownCzech Republic
            31246NETBOX-ASNETBOXAutonomoussystemCZfalse
            80.176.234.5
            unknownUnited Kingdom
            2529DEMON-INTERNETNowmaintainedbyCableWirelessWorldwidefalse
            181.205.145.188
            unknownColombia
            27831ColombiaMovilCOfalse
            80.73.75.83
            unknownRussian Federation
            21487SAKHATELECOM-ASRUfalse
            86.174.178.78
            unknownUnited Kingdom
            2856BT-UK-ASBTnetUKRegionalnetworkGBfalse
            178.101.143.188
            unknownUnited Kingdom
            12576EELtdGBfalse
            83.38.141.170
            unknownSpain
            3352TELEFONICA_DE_ESPANAESfalse
            63.70.133.211
            unknownUnited States
            701UUNETUSfalse
            169.21.184.194
            unknownUnited States
            37611AfrihostZAfalse
            200.72.96.137
            unknownChile
            6471ENTELCHILESACLfalse
            169.199.219.198
            unknownUnited States
            23309CCCOE-NETUSfalse
            169.87.170.157
            unknownUnited States
            37611AfrihostZAfalse
            169.199.123.38
            unknownUnited States
            23309CCCOE-NETUSfalse
            82.111.254.33
            unknownUnited Kingdom
            4589EASYNETEasynetGlobalServicesEUfalse
            200.186.34.200
            unknownBrazil
            3549LVLT-3549USfalse
            48.197.226.22
            unknownUnited States
            2686ATGS-MMD-ASUSfalse
            200.194.248.82
            unknownBrazil
            11432TeliumTelecomunicacoesLtdaBRfalse
            83.180.191.8
            unknownSweden
            1257TELE2EUfalse
            82.203.65.131
            unknownUnited Kingdom
            51551CAPITA-ASGBfalse
            80.101.145.38
            unknownNetherlands
            3265XS4ALL-NLAmsterdamNLfalse
            181.99.93.35
            unknownArgentina
            7303TelecomArgentinaSAARfalse
            169.124.100.178
            unknownUnited States
            37611AfrihostZAfalse
            178.240.238.30
            unknownTurkey
            16135TURKCELL-ASTurkcellASTRfalse
            119.27.204.69
            unknownChina
            17819ASN-EQUINIX-APEquinixAsiaPacificSGfalse
            191.145.80.99
            unknownColombia
            26611COMCELSACOfalse
            181.18.98.194
            unknownVenezuela
            27889TelecomunicacionesMOVILNETVEfalse
            169.25.129.27
            unknownUnited States
            37611AfrihostZAfalse
            181.6.53.227
            unknownArgentina
            7303TelecomArgentinaSAARfalse
            213.3.147.108
            unknownSwitzerland
            3303SWISSCOMSwisscomSwitzerlandLtdCHfalse
            82.134.18.248
            unknownNorway
            8542BKK-DIGITEK-AS8542NorwayNOfalse
            213.73.200.238
            unknownNetherlands
            33915TNF-ASNLfalse
            206.218.55.123
            unknownUnited States
            31966CSAA-INSURANCE-EXCHANGEUSfalse
            206.201.135.185
            unknownUnited States
            7029WINDSTREAMUSfalse
            165.39.88.166
            unknownUnited States
            37053RSAWEB-ASZAfalse
            213.171.167.97
            unknownItaly
            12637SEEWEBWebhostingcolocationandcloudservicesITfalse
            206.178.238.56
            unknownCanada
            808GONET-ASN-1CAfalse
            83.89.163.11
            unknownDenmark
            3292TDCTDCASDKfalse
            181.127.64.229
            unknownParaguay
            23201TelecelSAPYfalse
            178.163.136.2
            unknownBelarus
            42772A1-BY-ASBYfalse
            82.216.84.132
            unknownFrance
            21502ASN-NUMERICABLEFRfalse
            86.121.135.28
            unknownRomania
            8708RCS-RDS73-75DrStaicoviciROfalse
            82.52.176.223
            unknownItaly
            3269ASN-IBSNAZITfalse
            80.13.5.183
            unknownFrance
            3215FranceTelecom-OrangeFRfalse
            206.247.190.121
            unknownUnited States
            27258KAMOPOWERUSfalse
            169.46.68.90
            unknownUnited States
            36351SOFTLAYERUSfalse
            181.210.214.131
            unknownHonduras
            7727HondutelHNfalse
            93.89.77.200
            unknownTurkey
            196733ESOESNETTRfalse
            12.44.125.253
            unknownUnited States
            7018ATT-INTERNET4USfalse
            206.121.192.0
            unknownUnited States
            7018ATT-INTERNET4USfalse
            178.211.47.67
            unknownTurkey
            197328INETLTDTRfalse
            169.225.255.4
            unknownUnited States
            37611AfrihostZAfalse
            86.155.5.132
            unknownUnited Kingdom
            2856BT-UK-ASBTnetUKRegionalnetworkGBfalse
            213.93.146.195
            unknownNetherlands
            6830LIBERTYGLOBALLibertyGlobalformerlyUPCBroadbandHoldingfalse
            200.126.146.136
            unknownArgentina
            10318TelecomArgentinaSAARfalse
            86.176.6.43
            unknownUnited Kingdom
            2856BT-UK-ASBTnetUKRegionalnetworkGBfalse
            No context
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            daisy.ubuntu.comxd.x86_64.elfGet hashmaliciousMiraiBrowse
            • 162.213.35.25
            boatnet.x86.elfGet hashmaliciousMiraiBrowse
            • 162.213.35.25
            boatnet.arm.elfGet hashmaliciousMiraiBrowse
            • 162.213.35.25
            boatnet.arm6.elfGet hashmaliciousMiraiBrowse
            • 162.213.35.25
            bejv86.elfGet hashmaliciousUnknownBrowse
            • 162.213.35.24
            arm7.elfGet hashmaliciousMiraiBrowse
            • 162.213.35.24
            aarch64.elfGet hashmaliciousMiraiBrowse
            • 162.213.35.24
            arm6.elfGet hashmaliciousUnknownBrowse
            • 162.213.35.24
            arm5.elfGet hashmaliciousUnknownBrowse
            • 162.213.35.24
            efea6.elfGet hashmaliciousUnknownBrowse
            • 162.213.35.25
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            PLUSNETDExd.sh4.elfGet hashmaliciousMiraiBrowse
            • 84.245.129.125
            k03ldc.x86_64.elfGet hashmaliciousUnknownBrowse
            • 92.197.8.86
            hgfs.mips.elfGet hashmaliciousUnknownBrowse
            • 212.202.178.243
            splsh4.elfGet hashmaliciousUnknownBrowse
            • 62.206.192.250
            x.elfGet hashmaliciousUnknownBrowse
            • 92.201.203.214
            jaws.elfGet hashmaliciousUnknownBrowse
            • 92.199.212.80
            apep.sh4.elfGet hashmaliciousUnknownBrowse
            • 92.193.186.41
            apep.x86.elfGet hashmaliciousUnknownBrowse
            • 92.201.251.126
            a.elfGet hashmaliciousUnknownBrowse
            • 92.201.203.218
            jaws.elfGet hashmaliciousUnknownBrowse
            • 87.234.232.103
            UCDAVIS-COREUSmips.elfGet hashmaliciousGafgyt, OkiruBrowse
            • 168.150.126.98
            Nyx4r.sh4.elfGet hashmaliciousOkiruBrowse
            • 168.150.41.3
            apep.mips.elfGet hashmaliciousUnknownBrowse
            • 169.237.143.234
            sora.arm.elfGet hashmaliciousMiraiBrowse
            • 169.237.191.130
            res.arm.elfGet hashmaliciousUnknownBrowse
            • 168.150.96.210
            XB6SkLK7Al.dllGet hashmaliciousWannacryBrowse
            • 169.237.19.1
            i686.elfGet hashmaliciousMiraiBrowse
            • 152.79.195.238
            x86.elfGet hashmaliciousMiraiBrowse
            • 168.150.169.168
            x86_64.nn.elfGet hashmaliciousMirai, OkiruBrowse
            • 169.237.185.94
            arm5.elfGet hashmaliciousUnknownBrowse
            • 168.150.41.2
            CENTURYLINK-LEGACY-SAVVIS-ASIA-TRANSITUSmips.elfGet hashmaliciousUnknownBrowse
            • 206.142.39.25
            nklsh4.elfGet hashmaliciousUnknownBrowse
            • 207.82.133.64
            x86.elfGet hashmaliciousMiraiBrowse
            • 206.100.157.235
            i686.elfGet hashmaliciousUnknownBrowse
            • 206.143.110.168
            cbr.arm.elfGet hashmaliciousMiraiBrowse
            • 205.138.191.179
            Owari.spc.elfGet hashmaliciousUnknownBrowse
            • 206.142.15.77
            res.arm5.elfGet hashmaliciousUnknownBrowse
            • 206.100.86.253
            sh4.elfGet hashmaliciousUnknownBrowse
            • 206.101.147.172
            Hgf.m68k.elfGet hashmaliciousMiraiBrowse
            • 206.100.157.239
            nklarm5.elfGet hashmaliciousUnknownBrowse
            • 206.100.86.236
            COMCELSACOx86_64.elfGet hashmaliciousUnknownBrowse
            • 191.65.185.125
            bimbo-arm.elfGet hashmaliciousUnknownBrowse
            • 181.159.235.255
            k03ldc.arm.elfGet hashmaliciousUnknownBrowse
            • 181.243.146.83
            sh4.elfGet hashmaliciousUnknownBrowse
            • 181.151.53.173
            vjwe68k.elfGet hashmaliciousGafgyt, MiraiBrowse
            • 181.245.68.59
            mips.elfGet hashmaliciousUnknownBrowse
            • 181.251.166.69
            ppc.elfGet hashmaliciousUnknownBrowse
            • 181.148.139.252
            resgod.sh4.elfGet hashmaliciousMiraiBrowse
            • 181.244.20.1
            weje64.elfGet hashmaliciousGafgyt, MiraiBrowse
            • 191.73.76.178
            resgod.arm.elfGet hashmaliciousMiraiBrowse
            • 181.154.238.232
            No context
            No context
            Process:/usr/bin/pulseaudio
            File Type:ASCII text
            Category:dropped
            Size (bytes):10
            Entropy (8bit):2.9219280948873623
            Encrypted:false
            SSDEEP:3:5bkPn:pkP
            MD5:FF001A15CE15CF062A3704CEA2991B5F
            SHA1:B06F6855F376C3245B82212AC73ADED55DFE5DEF
            SHA-256:C54830B41ECFA1B6FBDC30397188DDA86B7B200E62AEAC21AE694A6192DCC38A
            SHA-512:65EBF7C31F6F65713CE01B38A112E97D0AE64A6BD1DA40CE4C1B998F10CD3912EE1A48BB2B279B24493062118AAB3B8753742E2AF28E56A31A7AAB27DE80E7BF
            Malicious:false
            Reputation:moderate, very likely benign file
            Preview:auto_null.
            Process:/usr/bin/pulseaudio
            File Type:ASCII text
            Category:dropped
            Size (bytes):18
            Entropy (8bit):3.4613201402110088
            Encrypted:false
            SSDEEP:3:5bkrIZsXvn:pkckv
            MD5:28FE6435F34B3367707BB1C5D5F6B430
            SHA1:EB8FE2D16BD6BBCCE106C94E4D284543B2573CF6
            SHA-256:721A37C69E555799B41D308849E8F8125441883AB021B723FED90A9B744F36C0
            SHA-512:6B6AB7C0979629D0FEF6BE47C5C6BCC367EDD0AAE3FC973F4DE2FD5F0A819C89E7656DB65D453B1B5398E54012B27EDFE02894AD87A7E0AF3A9C5F2EB24A9919
            Malicious:false
            Reputation:moderate, very likely benign file
            Preview:auto_null.monitor.
            Process:/usr/sbin/gdm3
            File Type:ASCII text
            Category:dropped
            Size (bytes):5
            Entropy (8bit):2.321928094887362
            Encrypted:false
            SSDEEP:3:Zt:T
            MD5:CCEA5795BEFB8E6738312413CAE59466
            SHA1:C3B3BBD016FFDFAD383FB15F7911C11DBBB053DC
            SHA-256:E021DA1479D92153AE2428B08F692669186E2A6A13C4ACB086668B16E9406388
            SHA-512:173061CB8EA14C2FBE8A4AF753404C555DB5E1C7E037CAD6FC04C4793481821D691FFAD6F34E652453E6CA60DA5A160A2E78589803B8CB5C959580F3E2A8DC0F
            Malicious:false
            Reputation:low
            Preview:6378.
            Process:/usr/bin/pulseaudio
            File Type:ASCII text
            Category:dropped
            Size (bytes):5
            Entropy (8bit):2.321928094887362
            Encrypted:false
            SSDEEP:3:ae:ae
            MD5:BDC10D2760A8BD03E0199D850FA421CC
            SHA1:EAC57C30C012949C0BE25A2B0864033942EB2A92
            SHA-256:A9FA2C933D51F0A8DDE67645C7CB5851BBADCEA57BE52C6A543FA5F12AF9058B
            SHA-512:E4C2A6CF4AAA0B2FF68732AE80BD75C37178D6D3932E2D23CE0F645699D30D85F5CEF9D3CCFDE50E311EFE65E8DFF357064CEB742122B6EB111476A1477C78C7
            Malicious:false
            Reputation:low
            Preview:6349.
            Process:/usr/bin/gpu-manager
            File Type:ASCII text
            Category:dropped
            Size (bytes):25
            Entropy (8bit):2.7550849518197795
            Encrypted:false
            SSDEEP:3:JoT/V9fDVbn:M/V3n
            MD5:078760523943E160756979906B85FB5E
            SHA1:0962643266F4C5537F7D125046F28F21D6DD0C89
            SHA-256:048416AC7A9A99690B8B53718CD39F32F637B55CC8DD8E67E58E5AEF060DD41C
            SHA-512:DEFAAE8F8B54C61A716A0B0B4884358FEB8EB44DFEA01AAA5A687FDA7182792B7DEBB34AA840672EB3B40EB59FD0186749E08E47D181786C7FAA8C8F73F0104D
            Malicious:false
            Reputation:moderate, very likely benign file
            Preview:15ad:0405;0000:00:0f:0;1.
            Process:/usr/bin/gpu-manager
            File Type:ASCII text
            Category:dropped
            Size (bytes):1371
            Entropy (8bit):4.8296848499188485
            Encrypted:false
            SSDEEP:24:wPXXX9uV6BNu3WDF3GF3XFFxFFed2uk2HUvJlfWkpPpx7uvvAdow9555cJz:wPXXXe6vejpeC2HUR5WkpPpcvAdow95O
            MD5:3AF77E630DA00B3BE24F4E8AA5D78B13
            SHA1:BCF2D99E002F6DE2413A183227B011CFBEF5673D
            SHA-256:EB1CBBA20845237B4409274D693FEAE13F835274DA3337B7A9D14F4D7FDF9DEA
            SHA-512:8524B1E8A761F962B32F396812099B9B0B2DCF3C9FCA8605424753CFCFF4DC67EDC5EE1D8C91B9C0ED7FAE6BB1E752898B8D514B7C421D1839D6FEDA609C593C
            Malicious:false
            Reputation:moderate, very likely benign file
            Preview:log_file: /var/log/gpu-manager.log.last_boot_file: /var/lib/ubuntu-drivers-common/last_gfx_boot.new_boot_file: /var/lib/ubuntu-drivers-common/last_gfx_boot.can't access /run/u-d-c-nvidia-was-loaded file.can't get module info via kmodcan't access /opt/amdgpu-pro/bin/amdgpu-pro-px.Looking for nvidia modules in /lib/modules/5.4.0-72-generic/kernel.Looking for nvidia modules in /lib/modules/5.4.0-72-generic/updates/dkms.Looking for amdgpu modules in /lib/modules/5.4.0-72-generic/kernel.Looking for amdgpu modules in /lib/modules/5.4.0-72-generic/updates/dkms.Is nvidia loaded? no.Was nvidia unloaded? no.Is nvidia blacklisted? no.Is intel loaded? no.Is radeon loaded? no.Is radeon blacklisted? no.Is amdgpu loaded? no.Is amdgpu blacklisted? no.Is amdgpu versioned? no.Is amdgpu pro stack? no.Is nouveau loaded? no.Is nouveau blacklisted? no.Is nvidia kernel module available? no.Is amdgpu kernel module available? no.Vendor/Device Id: 15ad:405.BusID "PCI:0@0:15:0".Is boot vga? yes.Error: can't acce
            File type:ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, no section header
            Entropy (8bit):7.95785422368574
            TrID:
            • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
            • ELF Executable and Linkable format (generic) (4004/1) 49.84%
            File name:xd.x86.elf
            File size:37'268 bytes
            MD5:a68aa2179d0db1bb9cf010a4949ea024
            SHA1:702e982ff2347f14703fb12bfdc53e1946566510
            SHA256:83ebd86adf2f88f83af9762d2bb64ac37c4a78c393351549892e2ebe914dbe52
            SHA512:64475ba3ebdc96bbd7fdd95698d2e342cd0e40dbff6cabf40e8e9d07598ccb7bfccd2747da676aaed8ddcbece6b7a3faca80214e924515ced20e7a63c05320ae
            SSDEEP:768:h0UXs5VHqxlKy0pKO99E+ESgRqDFJQdX2xDAwekNknbcuyD7URQRjC:hPqC0pK0ERSgRqDFJH53Nknouy8Rym
            TLSH:36F2E092C2FD0A6EF4AB033741BF76452A34B0192261E893CBC5E23B4D59F1C395E6D6
            File Content Preview:.ELF........................4...........4. ...(......................................... ... ... ...................Q.td.............................-].UPX!........P4..P4......U..........?..k.I/.j....\.d*nlz.e..H.....4.0.N..9..y.....W.x.G..n.y.'.yY..C.(.S

            ELF header

            Class:ELF32
            Data:2's complement, little endian
            Version:1 (current)
            Machine:Intel 80386
            Version Number:0x1
            Type:EXEC (Executable file)
            OS/ABI:UNIX - Linux
            ABI Version:0
            Entry Point Address:0xc08ea8
            Flags:0x0
            ELF Header Size:52
            Program Header Offset:52
            Program Header Size:32
            Number of Program Headers:3
            Section Header Offset:0
            Section Header Size:40
            Number of Section Headers:0
            Header String Table Index:0
            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
            LOAD0x00xc010000xc010000x909c0x909c7.96010x5R E0x1000
            LOAD0xb200x805db200x805db200x00x00.00000x6RW 0x1000
            GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

            Download Network PCAP: filteredfull

            • Total Packets: 1221
            • 5466 undefined
            • 443 (HTTPS)
            • 80 (HTTP)
            • 53 (DNS)
            • 23 (Telnet)
            TimestampSource PortDest PortSource IPDest IP
            Apr 2, 2025 20:53:26.715262890 CEST43928443192.168.2.2391.189.91.42
            Apr 2, 2025 20:53:30.658046961 CEST524585466192.168.2.23213.209.129.92
            Apr 2, 2025 20:53:30.658646107 CEST2537523192.168.2.23169.215.144.10
            Apr 2, 2025 20:53:30.658646107 CEST2537523192.168.2.2347.87.11.30
            Apr 2, 2025 20:53:30.658673048 CEST2537523192.168.2.234.28.41.149
            Apr 2, 2025 20:53:30.658677101 CEST2537523192.168.2.23158.61.178.139
            Apr 2, 2025 20:53:30.658679008 CEST2537523192.168.2.23255.63.145.10
            Apr 2, 2025 20:53:30.658694983 CEST2537523192.168.2.23107.123.90.207
            Apr 2, 2025 20:53:30.658694983 CEST2537523192.168.2.239.197.239.158
            Apr 2, 2025 20:53:30.658704996 CEST2537523192.168.2.23156.21.135.156
            Apr 2, 2025 20:53:30.658704996 CEST2537523192.168.2.2340.163.239.10
            Apr 2, 2025 20:53:30.658711910 CEST2537523192.168.2.2370.11.84.139
            Apr 2, 2025 20:53:30.658711910 CEST2537523192.168.2.23210.229.203.181
            Apr 2, 2025 20:53:30.658720016 CEST2537523192.168.2.23100.20.8.101
            Apr 2, 2025 20:53:30.658720016 CEST2537523192.168.2.23253.127.82.33
            Apr 2, 2025 20:53:30.658724070 CEST2537523192.168.2.2348.30.219.11
            Apr 2, 2025 20:53:30.658724070 CEST2537523192.168.2.2312.44.125.253
            Apr 2, 2025 20:53:30.658725977 CEST2537523192.168.2.2339.76.17.251
            Apr 2, 2025 20:53:30.658731937 CEST2537523192.168.2.23120.245.117.68
            Apr 2, 2025 20:53:30.658736944 CEST2537523192.168.2.2341.30.204.182
            Apr 2, 2025 20:53:30.658749104 CEST2537523192.168.2.23119.27.204.69
            Apr 2, 2025 20:53:30.658762932 CEST2537523192.168.2.23167.18.52.210
            Apr 2, 2025 20:53:30.658765078 CEST2537523192.168.2.23172.253.65.27
            Apr 2, 2025 20:53:30.659038067 CEST2537523192.168.2.23167.214.104.35
            Apr 2, 2025 20:53:30.659038067 CEST2537523192.168.2.23201.95.4.5
            Apr 2, 2025 20:53:30.659039021 CEST2537523192.168.2.23246.247.43.151
            Apr 2, 2025 20:53:30.659045935 CEST2537523192.168.2.2354.61.204.205
            Apr 2, 2025 20:53:30.659070969 CEST2537523192.168.2.23241.176.87.166
            Apr 2, 2025 20:53:30.659133911 CEST2537523192.168.2.2344.85.147.86
            Apr 2, 2025 20:53:30.659133911 CEST2537523192.168.2.23206.74.75.34
            Apr 2, 2025 20:53:30.659135103 CEST2537523192.168.2.23122.97.211.231
            Apr 2, 2025 20:53:30.659133911 CEST2537523192.168.2.23152.17.14.139
            Apr 2, 2025 20:53:30.659135103 CEST2537523192.168.2.2319.85.55.235
            Apr 2, 2025 20:53:30.659133911 CEST2537523192.168.2.23184.65.234.252
            Apr 2, 2025 20:53:30.659135103 CEST2537523192.168.2.23207.155.231.56
            Apr 2, 2025 20:53:30.659133911 CEST2537523192.168.2.23209.197.66.88
            Apr 2, 2025 20:53:30.659135103 CEST2537523192.168.2.23106.228.163.98
            Apr 2, 2025 20:53:30.659133911 CEST2537523192.168.2.23182.36.33.221
            Apr 2, 2025 20:53:30.659140110 CEST2537523192.168.2.23213.164.164.92
            Apr 2, 2025 20:53:30.659135103 CEST2537523192.168.2.2393.89.77.200
            Apr 2, 2025 20:53:30.659138918 CEST2537523192.168.2.23118.204.41.47
            Apr 2, 2025 20:53:30.659135103 CEST2537523192.168.2.23200.225.68.75
            Apr 2, 2025 20:53:30.659140110 CEST2537523192.168.2.23247.142.152.39
            Apr 2, 2025 20:53:30.659133911 CEST2537523192.168.2.23116.0.199.232
            Apr 2, 2025 20:53:30.659135103 CEST2537523192.168.2.23240.90.110.76
            Apr 2, 2025 20:53:30.659142017 CEST2537523192.168.2.23240.217.248.41
            Apr 2, 2025 20:53:30.659140110 CEST2537523192.168.2.2395.228.158.200
            Apr 2, 2025 20:53:30.659138918 CEST2537523192.168.2.23165.34.166.8
            Apr 2, 2025 20:53:30.659135103 CEST2537523192.168.2.23116.119.70.122
            Apr 2, 2025 20:53:30.659140110 CEST2537523192.168.2.23213.13.6.26
            Apr 2, 2025 20:53:30.659135103 CEST2537523192.168.2.23223.20.71.83
            Apr 2, 2025 20:53:30.659140110 CEST2537523192.168.2.2312.191.72.123
            Apr 2, 2025 20:53:30.659135103 CEST2537523192.168.2.2316.125.54.234
            Apr 2, 2025 20:53:30.659142971 CEST2537523192.168.2.23146.196.255.107
            Apr 2, 2025 20:53:30.659135103 CEST2537523192.168.2.23206.141.167.10
            Apr 2, 2025 20:53:30.659140110 CEST2537523192.168.2.2341.249.194.179
            Apr 2, 2025 20:53:30.659142017 CEST2537523192.168.2.23135.191.180.122
            Apr 2, 2025 20:53:30.659142971 CEST2537523192.168.2.2348.197.226.22
            Apr 2, 2025 20:53:30.659142017 CEST2537523192.168.2.2360.122.15.40
            Apr 2, 2025 20:53:30.659140110 CEST2537523192.168.2.2358.105.44.57
            Apr 2, 2025 20:53:30.659135103 CEST2537523192.168.2.23172.123.10.36
            Apr 2, 2025 20:53:30.659140110 CEST2537523192.168.2.23184.18.157.114
            Apr 2, 2025 20:53:30.659136057 CEST2537523192.168.2.23171.168.154.250
            Apr 2, 2025 20:53:30.659140110 CEST2537523192.168.2.2382.187.234.195
            Apr 2, 2025 20:53:30.659136057 CEST2537523192.168.2.23125.236.248.7
            Apr 2, 2025 20:53:30.659140110 CEST2537523192.168.2.23144.78.105.196
            Apr 2, 2025 20:53:30.659142971 CEST2537523192.168.2.2339.99.123.110
            Apr 2, 2025 20:53:30.659140110 CEST2537523192.168.2.2399.121.236.154
            Apr 2, 2025 20:53:30.659142971 CEST2537523192.168.2.23151.77.184.95
            Apr 2, 2025 20:53:30.659140110 CEST2537523192.168.2.23200.186.34.200
            Apr 2, 2025 20:53:30.659142971 CEST2537523192.168.2.2390.195.126.32
            Apr 2, 2025 20:53:30.659140110 CEST2537523192.168.2.23241.65.74.139
            Apr 2, 2025 20:53:30.659142971 CEST2537523192.168.2.23200.76.247.221
            Apr 2, 2025 20:53:30.659142971 CEST2537523192.168.2.23216.17.180.152
            Apr 2, 2025 20:53:30.659230947 CEST2537523192.168.2.23188.58.148.136
            Apr 2, 2025 20:53:30.659230947 CEST2537523192.168.2.23195.6.123.253
            Apr 2, 2025 20:53:30.659230947 CEST2537523192.168.2.2378.26.213.115
            Apr 2, 2025 20:53:30.659230947 CEST2537523192.168.2.23195.147.218.112
            Apr 2, 2025 20:53:30.659230947 CEST2537523192.168.2.23255.176.46.73
            Apr 2, 2025 20:53:30.659230947 CEST2537523192.168.2.234.78.115.193
            Apr 2, 2025 20:53:30.659230947 CEST2537523192.168.2.23252.248.37.173
            Apr 2, 2025 20:53:30.659230947 CEST2537523192.168.2.2361.152.81.31
            Apr 2, 2025 20:53:30.659235954 CEST2537523192.168.2.23114.159.137.3
            Apr 2, 2025 20:53:30.659235954 CEST2537523192.168.2.2343.185.47.233
            Apr 2, 2025 20:53:30.659235954 CEST2537523192.168.2.2395.120.28.235
            Apr 2, 2025 20:53:30.659235954 CEST2537523192.168.2.2396.100.155.207
            Apr 2, 2025 20:53:30.659235954 CEST2537523192.168.2.23195.209.138.134
            Apr 2, 2025 20:53:30.659235954 CEST2537523192.168.2.2386.246.39.186
            Apr 2, 2025 20:53:30.659235954 CEST2537523192.168.2.23133.146.253.55
            Apr 2, 2025 20:53:30.659235954 CEST2537523192.168.2.23171.24.107.179
            Apr 2, 2025 20:53:30.659239054 CEST2537523192.168.2.23188.90.247.49
            Apr 2, 2025 20:53:30.659239054 CEST2537523192.168.2.23152.172.133.63
            Apr 2, 2025 20:53:30.659239054 CEST2537523192.168.2.23188.98.254.46
            Apr 2, 2025 20:53:30.659239054 CEST2537523192.168.2.23254.73.213.52
            Apr 2, 2025 20:53:30.659239054 CEST2537523192.168.2.23178.198.70.58
            Apr 2, 2025 20:53:30.659240007 CEST2537523192.168.2.2341.156.136.80
            Apr 2, 2025 20:53:30.659249067 CEST2537523192.168.2.23165.39.88.166
            Apr 2, 2025 20:53:30.659249067 CEST2537523192.168.2.23138.253.152.144
            Apr 2, 2025 20:53:30.659249067 CEST2537523192.168.2.23188.151.213.110
            Apr 2, 2025 20:53:30.659255028 CEST2537523192.168.2.2343.38.146.44
            Apr 2, 2025 20:53:30.659255028 CEST2537523192.168.2.23122.227.126.151
            Apr 2, 2025 20:53:30.659255028 CEST2537523192.168.2.23191.145.80.99
            Apr 2, 2025 20:53:30.659255028 CEST2537523192.168.2.2363.70.133.211
            Apr 2, 2025 20:53:30.659255028 CEST2537523192.168.2.23218.141.44.122
            Apr 2, 2025 20:53:30.659255028 CEST2537523192.168.2.23249.221.177.133
            Apr 2, 2025 20:53:30.659255028 CEST2537523192.168.2.23189.57.18.76
            Apr 2, 2025 20:53:30.659255028 CEST2537523192.168.2.23116.4.196.118
            Apr 2, 2025 20:53:30.659257889 CEST2537523192.168.2.23121.128.240.235
            Apr 2, 2025 20:53:30.659259081 CEST2537523192.168.2.2381.224.51.186
            Apr 2, 2025 20:53:30.659257889 CEST2537523192.168.2.23171.104.114.122
            Apr 2, 2025 20:53:30.659259081 CEST2537523192.168.2.2372.27.55.89
            Apr 2, 2025 20:53:30.659257889 CEST2537523192.168.2.23153.145.27.129
            Apr 2, 2025 20:53:30.659259081 CEST2537523192.168.2.23113.7.118.19
            Apr 2, 2025 20:53:30.659257889 CEST2537523192.168.2.23159.59.177.75
            Apr 2, 2025 20:53:30.659259081 CEST2537523192.168.2.2368.83.210.121
            Apr 2, 2025 20:53:30.659257889 CEST2537523192.168.2.23141.50.17.109
            Apr 2, 2025 20:53:30.659259081 CEST2537523192.168.2.23192.119.58.220
            Apr 2, 2025 20:53:30.659257889 CEST2537523192.168.2.23219.192.137.11
            Apr 2, 2025 20:53:30.659265041 CEST2537523192.168.2.235.106.239.150
            Apr 2, 2025 20:53:30.659259081 CEST2537523192.168.2.23151.175.98.199
            Apr 2, 2025 20:53:30.659257889 CEST2537523192.168.2.2387.16.78.74
            Apr 2, 2025 20:53:30.659259081 CEST2537523192.168.2.23213.120.30.69
            Apr 2, 2025 20:53:30.659265041 CEST2537523192.168.2.2393.46.129.183
            Apr 2, 2025 20:53:30.659259081 CEST2537523192.168.2.23246.1.57.229
            Apr 2, 2025 20:53:30.659265041 CEST2537523192.168.2.2387.79.80.136
            Apr 2, 2025 20:53:30.659271955 CEST2537523192.168.2.2387.185.230.114
            Apr 2, 2025 20:53:30.659265041 CEST2537523192.168.2.2378.207.88.52
            Apr 2, 2025 20:53:30.659271955 CEST2537523192.168.2.2338.72.125.238
            Apr 2, 2025 20:53:30.659265041 CEST2537523192.168.2.23181.212.213.29
            Apr 2, 2025 20:53:30.659271955 CEST2537523192.168.2.23240.116.198.216
            Apr 2, 2025 20:53:30.659265041 CEST2537523192.168.2.2392.120.80.113
            Apr 2, 2025 20:53:30.659271955 CEST2537523192.168.2.2339.180.168.197
            Apr 2, 2025 20:53:30.659265041 CEST2537523192.168.2.23197.48.72.57
            Apr 2, 2025 20:53:30.659265041 CEST2537523192.168.2.2362.180.57.255
            Apr 2, 2025 20:53:30.659339905 CEST2537523192.168.2.23246.224.187.158
            Apr 2, 2025 20:53:30.659358025 CEST2537523192.168.2.2390.92.171.38
            Apr 2, 2025 20:53:30.659358025 CEST2537523192.168.2.2346.225.99.53
            Apr 2, 2025 20:53:30.659358025 CEST2537523192.168.2.2324.140.210.112
            Apr 2, 2025 20:53:30.659373045 CEST2537523192.168.2.2371.100.54.142
            Apr 2, 2025 20:53:30.659373045 CEST2537523192.168.2.23178.119.202.250
            Apr 2, 2025 20:53:30.659373045 CEST2537523192.168.2.2337.96.211.249
            Apr 2, 2025 20:53:30.659401894 CEST2537523192.168.2.23254.90.135.175
            Apr 2, 2025 20:53:30.659401894 CEST2537523192.168.2.23206.196.109.220
            Apr 2, 2025 20:53:30.659401894 CEST2537523192.168.2.23217.50.249.216
            Apr 2, 2025 20:53:30.659401894 CEST2537523192.168.2.23145.176.206.133
            Apr 2, 2025 20:53:30.659401894 CEST2537523192.168.2.2358.28.6.185
            Apr 2, 2025 20:53:30.659403086 CEST2537523192.168.2.23203.15.95.244
            Apr 2, 2025 20:53:30.659403086 CEST2537523192.168.2.2378.123.43.27
            Apr 2, 2025 20:53:30.659403086 CEST2537523192.168.2.2358.212.116.39
            Apr 2, 2025 20:53:30.659436941 CEST2537523192.168.2.23166.241.164.249
            Apr 2, 2025 20:53:30.659436941 CEST2537523192.168.2.23158.193.158.157
            Apr 2, 2025 20:53:30.659436941 CEST2537523192.168.2.23121.85.197.41
            Apr 2, 2025 20:53:30.659436941 CEST2537523192.168.2.2379.175.26.248
            Apr 2, 2025 20:53:30.887109995 CEST546652458213.209.129.92192.168.2.23
            Apr 2, 2025 20:53:30.895462036 CEST2793580192.168.2.23178.72.40.216
            Apr 2, 2025 20:53:30.895467043 CEST2793580192.168.2.2383.83.13.9
            Apr 2, 2025 20:53:30.895476103 CEST2793580192.168.2.23178.144.169.106
            Apr 2, 2025 20:53:30.895476103 CEST2793580192.168.2.2383.143.204.126
            Apr 2, 2025 20:53:30.895503998 CEST2793580192.168.2.2386.27.174.142
            Apr 2, 2025 20:53:30.895503998 CEST2793580192.168.2.23206.149.24.204
            Apr 2, 2025 20:53:30.895503998 CEST2793580192.168.2.23181.236.52.225
            Apr 2, 2025 20:53:30.895504951 CEST2793580192.168.2.23181.56.23.30
            Apr 2, 2025 20:53:30.895508051 CEST2793580192.168.2.23200.30.219.11
            Apr 2, 2025 20:53:30.895518064 CEST2793580192.168.2.23200.120.212.136
            Apr 2, 2025 20:53:30.895518064 CEST2793580192.168.2.23206.64.226.176
            Apr 2, 2025 20:53:30.895518064 CEST2793580192.168.2.23200.124.154.220
            Apr 2, 2025 20:53:30.895519972 CEST2793580192.168.2.23169.225.150.67
            Apr 2, 2025 20:53:30.895525932 CEST2793580192.168.2.23169.87.170.157
            Apr 2, 2025 20:53:30.895520926 CEST2793580192.168.2.2380.62.85.169
            Apr 2, 2025 20:53:30.895524979 CEST2793580192.168.2.2386.37.190.82
            Apr 2, 2025 20:53:30.895524979 CEST2793580192.168.2.23178.209.182.250
            Apr 2, 2025 20:53:30.895539045 CEST2793580192.168.2.23181.77.208.145
            Apr 2, 2025 20:53:30.895543098 CEST2793580192.168.2.23200.176.185.96
            Apr 2, 2025 20:53:30.895544052 CEST2793580192.168.2.23200.38.104.9
            Apr 2, 2025 20:53:30.895544052 CEST2793580192.168.2.2382.110.234.58
            Apr 2, 2025 20:53:30.895554066 CEST2793580192.168.2.23206.59.46.23
            Apr 2, 2025 20:53:30.895561934 CEST2793580192.168.2.2380.111.201.137
            Apr 2, 2025 20:53:30.895561934 CEST2793580192.168.2.2386.96.125.201
            Apr 2, 2025 20:53:30.895564079 CEST2793580192.168.2.23169.58.46.154
            Apr 2, 2025 20:53:30.895564079 CEST2793580192.168.2.23178.129.32.119
            Apr 2, 2025 20:53:30.895569086 CEST2793580192.168.2.2383.148.129.144
            Apr 2, 2025 20:53:30.895570040 CEST2793580192.168.2.2386.205.154.8
            Apr 2, 2025 20:53:30.895570040 CEST2793580192.168.2.23181.117.189.194
            Apr 2, 2025 20:53:30.895570040 CEST2793580192.168.2.2382.218.113.113
            Apr 2, 2025 20:53:30.895570040 CEST2793580192.168.2.23181.99.93.35
            Apr 2, 2025 20:53:30.895584106 CEST2793580192.168.2.23206.24.158.78
            Apr 2, 2025 20:53:30.895584106 CEST2793580192.168.2.23178.247.82.53
            Apr 2, 2025 20:53:30.895596981 CEST2793580192.168.2.2386.59.69.139
            Apr 2, 2025 20:53:30.895597935 CEST2793580192.168.2.23206.90.187.60
            Apr 2, 2025 20:53:30.895597935 CEST2793580192.168.2.23178.194.237.181
            Apr 2, 2025 20:53:30.895605087 CEST2793580192.168.2.2380.203.24.225
            Apr 2, 2025 20:53:30.895622015 CEST2793580192.168.2.2386.68.75.129
            Apr 2, 2025 20:53:30.895622015 CEST2793580192.168.2.23206.107.160.188
            Apr 2, 2025 20:53:30.895622969 CEST2793580192.168.2.2380.160.87.144
            Apr 2, 2025 20:53:30.895622015 CEST2793580192.168.2.23200.43.169.247
            Apr 2, 2025 20:53:30.895631075 CEST2793580192.168.2.2386.0.234.255
            Apr 2, 2025 20:53:30.895631075 CEST2793580192.168.2.2386.181.54.108
            Apr 2, 2025 20:53:30.895631075 CEST2793580192.168.2.23213.153.210.32
            Apr 2, 2025 20:53:30.895631075 CEST2793580192.168.2.23200.85.166.5
            Apr 2, 2025 20:53:30.895647049 CEST2793580192.168.2.23213.14.144.184
            Apr 2, 2025 20:53:30.895647049 CEST2793580192.168.2.2383.150.1.196
            Apr 2, 2025 20:53:30.895649910 CEST2793580192.168.2.23206.208.59.205
            Apr 2, 2025 20:53:30.895649910 CEST2793580192.168.2.23169.191.145.155
            Apr 2, 2025 20:53:30.895649910 CEST2793580192.168.2.23178.223.126.197
            Apr 2, 2025 20:53:30.895649910 CEST2793580192.168.2.23181.141.75.81
            Apr 2, 2025 20:53:30.895649910 CEST2793580192.168.2.2386.109.35.214
            Apr 2, 2025 20:53:30.895654917 CEST2793580192.168.2.2382.41.182.124
            Apr 2, 2025 20:53:30.895669937 CEST2793580192.168.2.23169.23.94.253
            Apr 2, 2025 20:53:30.895669937 CEST2793580192.168.2.2380.174.249.73
            Apr 2, 2025 20:53:30.895670891 CEST2793580192.168.2.2383.109.75.215
            Apr 2, 2025 20:53:30.895670891 CEST2793580192.168.2.23178.244.245.172
            Apr 2, 2025 20:53:30.895670891 CEST2793580192.168.2.23213.12.194.233
            Apr 2, 2025 20:53:30.895670891 CEST2793580192.168.2.23181.22.233.68
            Apr 2, 2025 20:53:30.895680904 CEST2793580192.168.2.23200.148.115.12
            Apr 2, 2025 20:53:30.895680904 CEST2793580192.168.2.23181.208.66.3
            Apr 2, 2025 20:53:30.895680904 CEST2793580192.168.2.23200.34.126.68
            Apr 2, 2025 20:53:30.895689011 CEST2793580192.168.2.23178.140.187.54
            Apr 2, 2025 20:53:30.895689964 CEST2793580192.168.2.23213.252.203.167
            Apr 2, 2025 20:53:30.895689011 CEST2793580192.168.2.2383.56.162.187
            Apr 2, 2025 20:53:30.895689964 CEST2793580192.168.2.23200.238.50.132
            Apr 2, 2025 20:53:30.895692110 CEST2793580192.168.2.2383.193.124.143
            Apr 2, 2025 20:53:30.895689964 CEST2793580192.168.2.2383.66.107.187
            Apr 2, 2025 20:53:30.895693064 CEST2793580192.168.2.23206.158.140.233
            Apr 2, 2025 20:53:30.895692110 CEST2793580192.168.2.23213.171.167.97
            Apr 2, 2025 20:53:30.895693064 CEST2793580192.168.2.23213.43.63.201
            Apr 2, 2025 20:53:30.895692110 CEST2793580192.168.2.23213.57.88.60
            Apr 2, 2025 20:53:30.895701885 CEST2793580192.168.2.23169.198.37.26
            Apr 2, 2025 20:53:30.895701885 CEST2793580192.168.2.23200.154.201.193
            Apr 2, 2025 20:53:30.895701885 CEST2793580192.168.2.2380.95.133.13
            Apr 2, 2025 20:53:30.895701885 CEST2793580192.168.2.2383.199.132.230
            Apr 2, 2025 20:53:30.895701885 CEST2793580192.168.2.2386.82.41.30
            Apr 2, 2025 20:53:30.895719051 CEST2793580192.168.2.23178.146.151.251
            Apr 2, 2025 20:53:30.895724058 CEST2793580192.168.2.23169.11.61.27
            Apr 2, 2025 20:53:30.895730019 CEST2793580192.168.2.23181.20.12.93
            Apr 2, 2025 20:53:30.895741940 CEST2793580192.168.2.23181.99.145.199
            Apr 2, 2025 20:53:30.895741940 CEST2793580192.168.2.2382.231.127.61
            Apr 2, 2025 20:53:30.895747900 CEST2793580192.168.2.23200.146.245.35
            Apr 2, 2025 20:53:30.895747900 CEST2793580192.168.2.2380.222.44.188
            Apr 2, 2025 20:53:30.895750999 CEST2793580192.168.2.2382.95.162.210
            Apr 2, 2025 20:53:30.895750999 CEST2793580192.168.2.23178.140.112.236
            Apr 2, 2025 20:53:30.895750999 CEST2793580192.168.2.23213.113.32.128
            Apr 2, 2025 20:53:30.895754099 CEST2793580192.168.2.2382.96.221.110
            Apr 2, 2025 20:53:30.895754099 CEST2793580192.168.2.23213.190.163.42
            Apr 2, 2025 20:53:30.895756006 CEST2793580192.168.2.23206.159.242.161
            Apr 2, 2025 20:53:30.895781994 CEST2793580192.168.2.2386.103.23.200
            Apr 2, 2025 20:53:30.895792961 CEST2793580192.168.2.2383.227.3.102
            Apr 2, 2025 20:53:30.895802021 CEST2793580192.168.2.23200.214.175.93
            Apr 2, 2025 20:53:30.895802021 CEST2793580192.168.2.23181.201.119.247
            Apr 2, 2025 20:53:30.895802975 CEST2793580192.168.2.2382.7.246.61
            Apr 2, 2025 20:53:30.895802975 CEST2793580192.168.2.2382.236.229.251
            Apr 2, 2025 20:53:30.895806074 CEST2793580192.168.2.23206.50.165.231
            Apr 2, 2025 20:53:30.895806074 CEST2793580192.168.2.23213.29.108.187
            Apr 2, 2025 20:53:30.895806074 CEST2793580192.168.2.23206.11.88.108
            Apr 2, 2025 20:53:30.895817041 CEST2793580192.168.2.23200.139.3.179
            Apr 2, 2025 20:53:30.895817041 CEST2793580192.168.2.23169.46.68.90
            Apr 2, 2025 20:53:30.895833969 CEST2793580192.168.2.2383.36.185.49
            Apr 2, 2025 20:53:30.895848989 CEST2793580192.168.2.23181.166.93.138
            Apr 2, 2025 20:53:30.895848989 CEST2793580192.168.2.23200.14.232.109
            Apr 2, 2025 20:53:30.895848989 CEST2793580192.168.2.2383.27.225.42
            Apr 2, 2025 20:53:30.895850897 CEST2793580192.168.2.23200.166.55.81
            Apr 2, 2025 20:53:30.895850897 CEST2793580192.168.2.23206.161.255.215
            Apr 2, 2025 20:53:30.895852089 CEST2793580192.168.2.2386.95.17.219
            Apr 2, 2025 20:53:30.895850897 CEST2793580192.168.2.23206.126.121.38
            Apr 2, 2025 20:53:30.895850897 CEST2793580192.168.2.2380.179.247.228
            Apr 2, 2025 20:53:30.895853996 CEST2793580192.168.2.23206.54.254.146
            Apr 2, 2025 20:53:30.895854950 CEST2793580192.168.2.2380.254.109.156
            Apr 2, 2025 20:53:30.895858049 CEST2793580192.168.2.23181.222.236.102
            Apr 2, 2025 20:53:30.895859957 CEST2793580192.168.2.2380.34.228.192
            Apr 2, 2025 20:53:30.895859957 CEST2793580192.168.2.23169.248.41.205
            Apr 2, 2025 20:53:30.895859957 CEST2793580192.168.2.23181.153.124.37
            Apr 2, 2025 20:53:30.895860910 CEST2793580192.168.2.23200.78.218.61
            Apr 2, 2025 20:53:30.895860910 CEST2793580192.168.2.23169.83.235.109
            Apr 2, 2025 20:53:30.895860910 CEST2793580192.168.2.2380.149.172.179
            Apr 2, 2025 20:53:30.895860910 CEST2793580192.168.2.23213.195.168.210
            Apr 2, 2025 20:53:30.895865917 CEST2793580192.168.2.2386.239.104.140
            Apr 2, 2025 20:53:30.895865917 CEST2793580192.168.2.23213.178.153.138
            Apr 2, 2025 20:53:30.895884037 CEST2793580192.168.2.23169.175.68.33
            Apr 2, 2025 20:53:30.895884037 CEST2793580192.168.2.2382.57.85.63
            Apr 2, 2025 20:53:30.895884037 CEST2793580192.168.2.2382.174.210.251
            Apr 2, 2025 20:53:30.895884037 CEST2793580192.168.2.23200.76.73.132
            Apr 2, 2025 20:53:30.895884037 CEST2793580192.168.2.2383.93.205.16
            Apr 2, 2025 20:53:30.895886898 CEST2793580192.168.2.2386.23.53.32
            Apr 2, 2025 20:53:30.895886898 CEST2793580192.168.2.2386.114.177.92
            Apr 2, 2025 20:53:30.895886898 CEST2793580192.168.2.2380.39.178.166
            Apr 2, 2025 20:53:30.895886898 CEST2793580192.168.2.23200.146.190.255
            Apr 2, 2025 20:53:30.895888090 CEST2793580192.168.2.23181.7.51.8
            Apr 2, 2025 20:53:30.895886898 CEST2793580192.168.2.23169.153.205.236
            Apr 2, 2025 20:53:30.895889044 CEST2793580192.168.2.23181.20.184.199
            Apr 2, 2025 20:53:30.895889044 CEST2793580192.168.2.2380.203.42.173
            Apr 2, 2025 20:53:30.895894051 CEST2793580192.168.2.23181.233.12.166
            Apr 2, 2025 20:53:30.895894051 CEST2793580192.168.2.23206.134.235.49
            Apr 2, 2025 20:53:30.895895004 CEST2793580192.168.2.23200.34.26.1
            Apr 2, 2025 20:53:30.895894051 CEST2793580192.168.2.23178.84.98.108
            Apr 2, 2025 20:53:30.895894051 CEST2793580192.168.2.23206.117.119.208
            Apr 2, 2025 20:53:30.895894051 CEST2793580192.168.2.23200.131.108.23
            Apr 2, 2025 20:53:30.895899057 CEST2793580192.168.2.23178.229.72.95
            Apr 2, 2025 20:53:30.895899057 CEST2793580192.168.2.2382.56.80.121
            Apr 2, 2025 20:53:30.895910025 CEST2793580192.168.2.23213.204.206.133
            Apr 2, 2025 20:53:30.895910025 CEST2793580192.168.2.23200.4.156.229
            Apr 2, 2025 20:53:30.895917892 CEST2793580192.168.2.23213.128.199.28
            Apr 2, 2025 20:53:30.895917892 CEST2793580192.168.2.23213.96.228.48
            Apr 2, 2025 20:53:30.895922899 CEST2793580192.168.2.2386.58.240.172
            Apr 2, 2025 20:53:30.895922899 CEST2793580192.168.2.2383.156.183.53
            Apr 2, 2025 20:53:30.895922899 CEST2793580192.168.2.2380.123.253.159
            Apr 2, 2025 20:53:30.895922899 CEST2793580192.168.2.23213.199.67.109
            Apr 2, 2025 20:53:30.895922899 CEST2793580192.168.2.2380.172.121.254
            Apr 2, 2025 20:53:30.895932913 CEST2793580192.168.2.23178.180.218.195
            Apr 2, 2025 20:53:30.895932913 CEST2793580192.168.2.2380.164.93.33
            Apr 2, 2025 20:53:30.895932913 CEST2793580192.168.2.2383.132.79.42
            Apr 2, 2025 20:53:30.895932913 CEST2793580192.168.2.2382.67.214.107
            Apr 2, 2025 20:53:30.895932913 CEST2793580192.168.2.23178.90.72.68
            Apr 2, 2025 20:53:30.895932913 CEST2793580192.168.2.23181.147.160.178
            Apr 2, 2025 20:53:30.895936966 CEST2793580192.168.2.23213.64.179.208
            Apr 2, 2025 20:53:30.895939112 CEST2793580192.168.2.23200.223.63.215
            Apr 2, 2025 20:53:30.895939112 CEST2793580192.168.2.23206.145.127.235
            Apr 2, 2025 20:53:30.895939112 CEST2793580192.168.2.23169.137.133.53
            Apr 2, 2025 20:53:30.895939112 CEST2793580192.168.2.23206.148.161.212
            Apr 2, 2025 20:53:30.895939112 CEST2793580192.168.2.23181.176.19.20
            Apr 2, 2025 20:53:30.895939112 CEST2793580192.168.2.2383.82.161.209
            Apr 2, 2025 20:53:30.895962000 CEST2793580192.168.2.2380.163.30.190
            Apr 2, 2025 20:53:30.895962000 CEST2793580192.168.2.2382.7.66.27
            Apr 2, 2025 20:53:30.895962000 CEST2793580192.168.2.23181.218.169.54
            Apr 2, 2025 20:53:30.895963907 CEST2793580192.168.2.23206.101.228.39
            Apr 2, 2025 20:53:30.895967960 CEST2793580192.168.2.2380.123.19.26
            Apr 2, 2025 20:53:30.895967960 CEST2793580192.168.2.23178.114.200.27
            Apr 2, 2025 20:53:30.895970106 CEST2793580192.168.2.23206.137.216.104
            Apr 2, 2025 20:53:30.895970106 CEST2793580192.168.2.23206.70.212.25
            Apr 2, 2025 20:53:30.895970106 CEST2793580192.168.2.23169.178.28.144
            Apr 2, 2025 20:53:30.895973921 CEST2793580192.168.2.23213.190.190.185
            Apr 2, 2025 20:53:30.895973921 CEST2793580192.168.2.2380.124.209.131
            Apr 2, 2025 20:53:30.895977020 CEST2793580192.168.2.23181.21.207.222
            Apr 2, 2025 20:53:30.895979881 CEST2793580192.168.2.2383.77.191.13
            Apr 2, 2025 20:53:30.895979881 CEST2793580192.168.2.23206.162.231.99
            Apr 2, 2025 20:53:30.895979881 CEST2793580192.168.2.2382.71.126.99
            Apr 2, 2025 20:53:30.895979881 CEST2793580192.168.2.2383.167.23.151
            Apr 2, 2025 20:53:30.896003008 CEST2793580192.168.2.2382.133.227.133
            Apr 2, 2025 20:53:30.896003008 CEST2793580192.168.2.2382.145.197.181
            Apr 2, 2025 20:53:30.896008015 CEST2793580192.168.2.2380.200.188.80
            Apr 2, 2025 20:53:30.896008015 CEST2793580192.168.2.23206.243.46.192
            Apr 2, 2025 20:53:30.896008015 CEST2793580192.168.2.23181.239.104.170
            Apr 2, 2025 20:53:30.896008015 CEST2793580192.168.2.23178.247.193.96
            Apr 2, 2025 20:53:30.896014929 CEST2793580192.168.2.23200.53.178.42
            Apr 2, 2025 20:53:30.896017075 CEST2793580192.168.2.2382.255.89.242
            Apr 2, 2025 20:53:30.896024942 CEST2793580192.168.2.23178.66.186.216
            Apr 2, 2025 20:53:30.896025896 CEST2793580192.168.2.2383.223.110.133
            Apr 2, 2025 20:53:30.896027088 CEST2793580192.168.2.23200.54.103.150
            Apr 2, 2025 20:53:30.896027088 CEST2793580192.168.2.23169.30.136.137
            Apr 2, 2025 20:53:30.896033049 CEST2793580192.168.2.23213.138.251.216
            Apr 2, 2025 20:53:30.896042109 CEST2793580192.168.2.2382.85.72.42
            Apr 2, 2025 20:53:30.896042109 CEST2793580192.168.2.2382.49.24.138
            Apr 2, 2025 20:53:30.896042109 CEST2793580192.168.2.2382.132.68.70
            Apr 2, 2025 20:53:30.896042109 CEST2793580192.168.2.23213.247.134.6
            Apr 2, 2025 20:53:30.896054983 CEST2793580192.168.2.2382.99.245.109
            Apr 2, 2025 20:53:30.896059036 CEST2793580192.168.2.23181.210.159.95
            Apr 2, 2025 20:53:30.896063089 CEST2793580192.168.2.23206.45.33.1
            Apr 2, 2025 20:53:30.896064997 CEST2793580192.168.2.23181.42.57.125
            Apr 2, 2025 20:53:30.896064997 CEST2793580192.168.2.23200.149.166.245
            Apr 2, 2025 20:53:30.896084070 CEST2793580192.168.2.23178.172.9.153
            Apr 2, 2025 20:53:30.896084070 CEST2793580192.168.2.23206.251.21.196
            Apr 2, 2025 20:53:30.896085024 CEST2793580192.168.2.23169.195.60.106
            Apr 2, 2025 20:53:30.896085024 CEST2793580192.168.2.23178.105.202.195
            Apr 2, 2025 20:53:30.896085024 CEST2793580192.168.2.23169.189.168.253
            Apr 2, 2025 20:53:30.896092892 CEST2793580192.168.2.2383.107.37.198
            Apr 2, 2025 20:53:30.896092892 CEST2793580192.168.2.2386.248.57.20
            Apr 2, 2025 20:53:30.896092892 CEST2793580192.168.2.23181.190.31.251
            Apr 2, 2025 20:53:30.896092892 CEST2793580192.168.2.23169.16.113.163
            Apr 2, 2025 20:53:30.896095991 CEST2793580192.168.2.2383.89.163.11
            Apr 2, 2025 20:53:30.896095991 CEST2793580192.168.2.23169.157.78.29
            Apr 2, 2025 20:53:30.896095991 CEST2793580192.168.2.23206.76.129.27
            Apr 2, 2025 20:53:30.896092892 CEST2793580192.168.2.2383.48.184.111
            Apr 2, 2025 20:53:30.896092892 CEST2793580192.168.2.23178.6.232.131
            Apr 2, 2025 20:53:30.896092892 CEST2793580192.168.2.2382.41.67.53
            Apr 2, 2025 20:53:30.896092892 CEST2793580192.168.2.23213.79.81.246
            Apr 2, 2025 20:53:30.896092892 CEST2793580192.168.2.2382.91.25.33
            Apr 2, 2025 20:53:30.896092892 CEST2793580192.168.2.2380.139.25.89
            Apr 2, 2025 20:53:30.896106958 CEST2793580192.168.2.23206.108.164.35
            Apr 2, 2025 20:53:30.896112919 CEST2793580192.168.2.23213.22.165.86
            Apr 2, 2025 20:53:30.896112919 CEST2793580192.168.2.2386.208.102.19
            Apr 2, 2025 20:53:30.896112919 CEST2793580192.168.2.23213.203.184.189
            Apr 2, 2025 20:53:30.896126986 CEST2793580192.168.2.23213.98.108.45
            Apr 2, 2025 20:53:30.896126986 CEST2793580192.168.2.23181.23.83.125
            Apr 2, 2025 20:53:30.896131039 CEST2793580192.168.2.2382.212.160.123
            Apr 2, 2025 20:53:30.896131992 CEST2793580192.168.2.2383.5.237.101
            Apr 2, 2025 20:53:30.896131992 CEST2793580192.168.2.23200.187.157.16
            Apr 2, 2025 20:53:30.896151066 CEST2793580192.168.2.2386.113.169.153
            Apr 2, 2025 20:53:30.896152020 CEST2793580192.168.2.23206.128.60.49
            Apr 2, 2025 20:53:30.896152973 CEST2793580192.168.2.2382.35.80.142
            Apr 2, 2025 20:53:30.896169901 CEST2793580192.168.2.23178.194.111.7
            Apr 2, 2025 20:53:30.896169901 CEST2793580192.168.2.23169.240.216.117
            Apr 2, 2025 20:53:30.896176100 CEST2793580192.168.2.23200.99.116.98
            Apr 2, 2025 20:53:30.896177053 CEST2793580192.168.2.2386.194.125.179
            Apr 2, 2025 20:53:30.896177053 CEST2793580192.168.2.23169.207.50.58
            Apr 2, 2025 20:53:30.896178961 CEST2793580192.168.2.2382.143.26.37
            Apr 2, 2025 20:53:30.896182060 CEST2793580192.168.2.23200.124.103.107
            Apr 2, 2025 20:53:30.896182060 CEST2793580192.168.2.2386.180.86.23
            Apr 2, 2025 20:53:30.896182060 CEST2793580192.168.2.23178.194.40.139
            Apr 2, 2025 20:53:30.896183014 CEST2793580192.168.2.23178.194.99.96
            Apr 2, 2025 20:53:30.896183014 CEST2793580192.168.2.23178.4.192.145
            Apr 2, 2025 20:53:30.896183014 CEST2793580192.168.2.23213.93.146.195
            Apr 2, 2025 20:53:30.896183014 CEST2793580192.168.2.2386.178.78.226
            Apr 2, 2025 20:53:30.896183014 CEST2793580192.168.2.23181.63.137.146
            Apr 2, 2025 20:53:30.896193981 CEST2793580192.168.2.2380.61.104.189
            Apr 2, 2025 20:53:30.896194935 CEST2793580192.168.2.23169.237.160.237
            Apr 2, 2025 20:53:30.896194935 CEST2793580192.168.2.2383.110.134.149
            Apr 2, 2025 20:53:30.896194935 CEST2793580192.168.2.2380.22.191.125
            Apr 2, 2025 20:53:30.896208048 CEST2793580192.168.2.23169.52.241.1
            Apr 2, 2025 20:53:30.896215916 CEST2793580192.168.2.2383.38.141.170
            Apr 2, 2025 20:53:30.896219015 CEST2793580192.168.2.23200.117.134.226
            Apr 2, 2025 20:53:30.896219015 CEST2793580192.168.2.2386.20.93.108
            Apr 2, 2025 20:53:30.896224022 CEST2793580192.168.2.2382.84.144.229
            Apr 2, 2025 20:53:30.896224022 CEST2793580192.168.2.2386.109.15.23
            Apr 2, 2025 20:53:30.896226883 CEST2793580192.168.2.23213.42.106.245
            Apr 2, 2025 20:53:30.896226883 CEST2793580192.168.2.23200.39.243.206
            Apr 2, 2025 20:53:30.896246910 CEST2793580192.168.2.23181.91.235.125
            Apr 2, 2025 20:53:30.896246910 CEST2793580192.168.2.2386.82.185.68
            Apr 2, 2025 20:53:30.896262884 CEST2793580192.168.2.23213.70.139.210
            Apr 2, 2025 20:53:30.896262884 CEST2793580192.168.2.23169.99.216.75
            Apr 2, 2025 20:53:30.896269083 CEST2793580192.168.2.2382.181.16.74
            Apr 2, 2025 20:53:30.896269083 CEST2793580192.168.2.23200.8.125.202
            Apr 2, 2025 20:53:30.896282911 CEST2793580192.168.2.2386.78.18.136
            Apr 2, 2025 20:53:30.896282911 CEST2793580192.168.2.23169.148.75.24
            Apr 2, 2025 20:53:30.896286011 CEST2793580192.168.2.2380.90.92.207
            Apr 2, 2025 20:53:30.896286011 CEST2793580192.168.2.23213.87.12.229
            Apr 2, 2025 20:53:30.896286011 CEST2793580192.168.2.2380.108.232.222
            Apr 2, 2025 20:53:30.896286011 CEST2793580192.168.2.2383.125.66.61
            Apr 2, 2025 20:53:30.896286011 CEST2793580192.168.2.2382.243.210.58
            Apr 2, 2025 20:53:30.896286964 CEST2793580192.168.2.23213.165.145.254
            Apr 2, 2025 20:53:30.896286964 CEST2793580192.168.2.23206.13.240.241
            Apr 2, 2025 20:53:30.896294117 CEST2793580192.168.2.23200.218.144.227
            Apr 2, 2025 20:53:30.896296024 CEST2793580192.168.2.23206.214.138.79
            Apr 2, 2025 20:53:30.896315098 CEST2793580192.168.2.2382.62.134.30
            Apr 2, 2025 20:53:30.896316051 CEST2793580192.168.2.23178.219.56.12
            Apr 2, 2025 20:53:30.896315098 CEST2793580192.168.2.2380.42.45.56
            Apr 2, 2025 20:53:30.896320105 CEST2793580192.168.2.2380.32.80.82
            Apr 2, 2025 20:53:30.896320105 CEST2793580192.168.2.2380.189.66.40
            Apr 2, 2025 20:53:30.896320105 CEST2793580192.168.2.23169.60.115.80
            Apr 2, 2025 20:53:30.896333933 CEST2793580192.168.2.23206.114.17.35
            Apr 2, 2025 20:53:30.896337986 CEST2793580192.168.2.23178.205.123.67
            Apr 2, 2025 20:53:30.896337986 CEST2793580192.168.2.23213.88.77.66
            Apr 2, 2025 20:53:30.896344900 CEST2793580192.168.2.23169.198.92.98
            Apr 2, 2025 20:53:30.896344900 CEST2793580192.168.2.23178.233.210.29
            Apr 2, 2025 20:53:30.896344900 CEST2793580192.168.2.23206.166.24.227
            Apr 2, 2025 20:53:30.896362066 CEST2793580192.168.2.23200.40.176.254
            Apr 2, 2025 20:53:30.896362066 CEST2793580192.168.2.23169.132.80.41
            Apr 2, 2025 20:53:30.896369934 CEST2793580192.168.2.2380.194.128.36
            Apr 2, 2025 20:53:30.896369934 CEST2793580192.168.2.23178.43.38.169
            Apr 2, 2025 20:53:30.896369934 CEST2793580192.168.2.23178.59.145.208
            Apr 2, 2025 20:53:30.896370888 CEST2793580192.168.2.23200.107.245.98
            Apr 2, 2025 20:53:30.896382093 CEST2793580192.168.2.23169.93.59.131
            Apr 2, 2025 20:53:30.896382093 CEST2793580192.168.2.23169.38.174.54
            Apr 2, 2025 20:53:30.896382093 CEST2793580192.168.2.2386.210.108.104
            Apr 2, 2025 20:53:30.896384954 CEST2793580192.168.2.23206.178.238.56
            Apr 2, 2025 20:53:30.896384954 CEST2793580192.168.2.23213.231.3.60
            Apr 2, 2025 20:53:30.896389008 CEST2793580192.168.2.23213.85.87.83
            Apr 2, 2025 20:53:30.896389008 CEST2793580192.168.2.23200.123.91.153
            Apr 2, 2025 20:53:30.896398067 CEST2793580192.168.2.23200.147.79.48
            Apr 2, 2025 20:53:30.896398067 CEST2793580192.168.2.2383.187.38.9
            Apr 2, 2025 20:53:30.896398067 CEST2793580192.168.2.23200.242.31.166
            Apr 2, 2025 20:53:30.896399975 CEST2793580192.168.2.2382.184.8.243
            Apr 2, 2025 20:53:30.896399975 CEST2793580192.168.2.2383.122.222.178
            Apr 2, 2025 20:53:30.896399975 CEST2793580192.168.2.23181.1.203.108
            Apr 2, 2025 20:53:30.896413088 CEST2793580192.168.2.23181.45.150.248
            Apr 2, 2025 20:53:30.896419048 CEST2793580192.168.2.2386.130.229.126
            Apr 2, 2025 20:53:30.896426916 CEST2793580192.168.2.23200.104.38.50
            Apr 2, 2025 20:53:30.896429062 CEST2793580192.168.2.2386.208.11.108
            Apr 2, 2025 20:53:30.896436930 CEST2793580192.168.2.23206.101.207.91
            Apr 2, 2025 20:53:30.896436930 CEST2793580192.168.2.2382.52.176.223
            Apr 2, 2025 20:53:30.896436930 CEST2793580192.168.2.23169.252.153.199
            Apr 2, 2025 20:53:30.896436930 CEST2793580192.168.2.23181.113.60.96
            Apr 2, 2025 20:53:30.896436930 CEST2793580192.168.2.2380.47.107.224
            Apr 2, 2025 20:53:30.896445036 CEST2793580192.168.2.2386.90.72.9
            Apr 2, 2025 20:53:30.896445990 CEST2793580192.168.2.2382.153.199.6
            Apr 2, 2025 20:53:30.896445990 CEST2793580192.168.2.23206.99.248.255
            Apr 2, 2025 20:53:30.896445990 CEST2793580192.168.2.23206.129.52.146
            Apr 2, 2025 20:53:30.896445990 CEST2793580192.168.2.23200.50.153.111
            Apr 2, 2025 20:53:30.896445990 CEST2793580192.168.2.23178.139.91.36
            Apr 2, 2025 20:53:30.896454096 CEST2793580192.168.2.2386.220.89.56
            Apr 2, 2025 20:53:30.896460056 CEST2793580192.168.2.2380.121.94.235
            Apr 2, 2025 20:53:30.896460056 CEST2793580192.168.2.2383.116.242.112
            Apr 2, 2025 20:53:30.896461964 CEST2793580192.168.2.23200.165.157.228
            Apr 2, 2025 20:53:30.896476030 CEST2793580192.168.2.23206.118.57.62
            Apr 2, 2025 20:53:30.896477938 CEST2793580192.168.2.23206.155.148.86
            Apr 2, 2025 20:53:30.896482944 CEST2793580192.168.2.2380.246.194.10
            Apr 2, 2025 20:53:30.896483898 CEST2793580192.168.2.2380.196.174.25
            Apr 2, 2025 20:53:30.896487951 CEST2793580192.168.2.23213.170.37.148
            Apr 2, 2025 20:53:30.896496058 CEST2793580192.168.2.2382.227.79.193
            Apr 2, 2025 20:53:30.896496058 CEST2793580192.168.2.23181.123.66.176
            Apr 2, 2025 20:53:30.896496058 CEST2793580192.168.2.23181.224.91.201
            Apr 2, 2025 20:53:30.896498919 CEST2793580192.168.2.23206.203.66.218
            Apr 2, 2025 20:53:30.896498919 CEST2793580192.168.2.23169.28.12.116
            Apr 2, 2025 20:53:30.896501064 CEST2793580192.168.2.2383.92.2.186
            Apr 2, 2025 20:53:30.896501064 CEST2793580192.168.2.23213.217.82.126
            Apr 2, 2025 20:53:30.896509886 CEST2793580192.168.2.2382.75.190.220
            Apr 2, 2025 20:53:30.896533012 CEST2793580192.168.2.23213.195.93.100
            Apr 2, 2025 20:53:30.896533966 CEST2793580192.168.2.23206.38.122.41
            Apr 2, 2025 20:53:30.896533966 CEST2793580192.168.2.2380.215.114.26
            Apr 2, 2025 20:53:30.896533966 CEST2793580192.168.2.23213.72.173.221
            Apr 2, 2025 20:53:30.896544933 CEST2793580192.168.2.23200.160.222.250
            Apr 2, 2025 20:53:30.896544933 CEST2793580192.168.2.23169.62.69.224
            Apr 2, 2025 20:53:30.896545887 CEST2793580192.168.2.2386.214.217.81
            Apr 2, 2025 20:53:30.896559000 CEST2793580192.168.2.2386.176.41.208
            Apr 2, 2025 20:53:30.896559000 CEST2793580192.168.2.2383.247.78.142
            Apr 2, 2025 20:53:30.896564960 CEST2793580192.168.2.23169.144.5.195
            Apr 2, 2025 20:53:30.896564960 CEST2793580192.168.2.23169.64.215.3
            Apr 2, 2025 20:53:30.896564960 CEST2793580192.168.2.2386.149.80.68
            Apr 2, 2025 20:53:30.896564960 CEST2793580192.168.2.2386.37.4.168
            Apr 2, 2025 20:53:30.896565914 CEST2793580192.168.2.2383.204.146.54
            Apr 2, 2025 20:53:30.896576881 CEST2793580192.168.2.23169.111.124.247
            Apr 2, 2025 20:53:30.896578074 CEST2793580192.168.2.23206.234.163.102
            Apr 2, 2025 20:53:30.896579027 CEST2793580192.168.2.2386.93.133.29
            Apr 2, 2025 20:53:30.896579027 CEST2793580192.168.2.23213.164.69.198
            Apr 2, 2025 20:53:30.896580935 CEST2793580192.168.2.23178.126.122.207
            Apr 2, 2025 20:53:30.896586895 CEST2793580192.168.2.23169.61.15.193
            Apr 2, 2025 20:53:30.896586895 CEST2793580192.168.2.23169.115.201.35
            Apr 2, 2025 20:53:30.896600008 CEST2793580192.168.2.2386.9.249.33
            Apr 2, 2025 20:53:30.896600962 CEST2793580192.168.2.2380.125.100.215
            Apr 2, 2025 20:53:30.896601915 CEST2793580192.168.2.2382.198.242.249
            Apr 2, 2025 20:53:30.896601915 CEST2793580192.168.2.23206.39.28.230
            Apr 2, 2025 20:53:30.896610975 CEST2793580192.168.2.23206.121.192.0
            Apr 2, 2025 20:53:30.896612883 CEST2793580192.168.2.23200.27.116.169
            Apr 2, 2025 20:53:30.896610975 CEST2793580192.168.2.23213.15.116.62
            Apr 2, 2025 20:53:30.896615982 CEST2793580192.168.2.2383.206.166.225
            Apr 2, 2025 20:53:30.896619081 CEST2793580192.168.2.2386.236.111.181
            Apr 2, 2025 20:53:30.896629095 CEST2793580192.168.2.23169.225.255.4
            Apr 2, 2025 20:53:30.896630049 CEST2793580192.168.2.23213.35.254.14
            Apr 2, 2025 20:53:30.896630049 CEST2793580192.168.2.23178.224.31.29
            Apr 2, 2025 20:53:30.896632910 CEST2793580192.168.2.23206.53.117.241
            Apr 2, 2025 20:53:30.896632910 CEST2793580192.168.2.23169.232.32.53
            Apr 2, 2025 20:53:30.896632910 CEST2793580192.168.2.23169.134.24.165
            Apr 2, 2025 20:53:30.896632910 CEST2793580192.168.2.2382.85.29.233
            Apr 2, 2025 20:53:30.896632910 CEST2793580192.168.2.23206.173.52.39
            Apr 2, 2025 20:53:30.896632910 CEST2793580192.168.2.23200.227.70.63
            Apr 2, 2025 20:53:30.896641970 CEST2793580192.168.2.2383.106.216.9
            Apr 2, 2025 20:53:30.896641970 CEST2793580192.168.2.2386.5.34.153
            Apr 2, 2025 20:53:30.896641970 CEST2793580192.168.2.23206.201.135.185
            Apr 2, 2025 20:53:30.896668911 CEST2793580192.168.2.23181.5.18.234
            Apr 2, 2025 20:53:30.896670103 CEST2793580192.168.2.23178.240.238.30
            Apr 2, 2025 20:53:30.896671057 CEST2793580192.168.2.23206.96.185.139
            Apr 2, 2025 20:53:30.896670103 CEST2793580192.168.2.23213.186.37.145
            Apr 2, 2025 20:53:30.896671057 CEST2793580192.168.2.2383.195.118.35
            Apr 2, 2025 20:53:30.896670103 CEST2793580192.168.2.23200.126.146.136
            Apr 2, 2025 20:53:30.896668911 CEST2793580192.168.2.2380.94.132.183
            Apr 2, 2025 20:53:30.896677971 CEST2793580192.168.2.23213.48.152.77
            Apr 2, 2025 20:53:30.896677971 CEST2793580192.168.2.23178.144.255.246
            Apr 2, 2025 20:53:30.896677971 CEST2793580192.168.2.2380.31.88.234
            Apr 2, 2025 20:53:30.896683931 CEST2793580192.168.2.23213.89.207.143
            Apr 2, 2025 20:53:30.896693945 CEST2793580192.168.2.23213.42.16.217
            Apr 2, 2025 20:53:30.896703959 CEST2793580192.168.2.2386.156.201.163
            Apr 2, 2025 20:53:30.896704912 CEST2793580192.168.2.2386.68.66.125
            Apr 2, 2025 20:53:30.896708012 CEST2793580192.168.2.23200.126.221.225
            Apr 2, 2025 20:53:30.896720886 CEST2793580192.168.2.23213.90.212.162
            Apr 2, 2025 20:53:30.896723032 CEST2793580192.168.2.2380.169.87.179
            Apr 2, 2025 20:53:30.896723032 CEST2793580192.168.2.2386.248.179.134
            Apr 2, 2025 20:53:30.896727085 CEST2793580192.168.2.2382.155.147.168
            Apr 2, 2025 20:53:30.896727085 CEST2793580192.168.2.2382.203.65.131
            Apr 2, 2025 20:53:30.896737099 CEST2793580192.168.2.23206.187.0.14
            Apr 2, 2025 20:53:30.896737099 CEST2793580192.168.2.2386.79.98.112
            Apr 2, 2025 20:53:30.896738052 CEST2793580192.168.2.2382.209.32.54
            Apr 2, 2025 20:53:30.896739960 CEST2793580192.168.2.2382.211.169.136
            Apr 2, 2025 20:53:30.896739960 CEST2793580192.168.2.2382.106.61.137
            Apr 2, 2025 20:53:30.896739960 CEST2793580192.168.2.23178.71.25.13
            Apr 2, 2025 20:53:30.896743059 CEST2793580192.168.2.23200.233.15.250
            Apr 2, 2025 20:53:30.896744967 CEST2793580192.168.2.2382.47.70.202
            Apr 2, 2025 20:53:30.896760941 CEST2793580192.168.2.2382.116.131.80
            Apr 2, 2025 20:53:30.896761894 CEST2793580192.168.2.23178.43.139.221
            Apr 2, 2025 20:53:30.896763086 CEST2793580192.168.2.23178.48.133.220
            Apr 2, 2025 20:53:30.896763086 CEST2793580192.168.2.23169.176.231.236
            Apr 2, 2025 20:53:30.896763086 CEST2793580192.168.2.2382.15.18.196
            Apr 2, 2025 20:53:30.896775961 CEST2793580192.168.2.23178.235.63.6
            Apr 2, 2025 20:53:30.896775961 CEST2793580192.168.2.2382.66.82.103
            Apr 2, 2025 20:53:30.896775961 CEST2793580192.168.2.23206.133.235.246
            Apr 2, 2025 20:53:30.896779060 CEST2793580192.168.2.23169.10.221.28
            Apr 2, 2025 20:53:30.896783113 CEST2793580192.168.2.23213.3.238.198
            Apr 2, 2025 20:53:30.896783113 CEST2793580192.168.2.23181.213.90.150
            Apr 2, 2025 20:53:30.896784067 CEST2793580192.168.2.23200.165.57.24
            Apr 2, 2025 20:53:30.896795034 CEST2793580192.168.2.2382.186.127.64
            Apr 2, 2025 20:53:30.896795034 CEST2793580192.168.2.23206.249.236.126
            Apr 2, 2025 20:53:30.896800995 CEST2793580192.168.2.23169.38.214.21
            Apr 2, 2025 20:53:30.896804094 CEST2793580192.168.2.23200.190.227.77
            Apr 2, 2025 20:53:30.896804094 CEST2793580192.168.2.23178.227.20.193
            Apr 2, 2025 20:53:30.896814108 CEST2793580192.168.2.23181.223.37.147
            Apr 2, 2025 20:53:30.896821976 CEST2793580192.168.2.23200.128.230.131
            Apr 2, 2025 20:53:30.896827936 CEST2793580192.168.2.23178.57.31.230
            Apr 2, 2025 20:53:30.896828890 CEST2793580192.168.2.2386.156.253.240
            Apr 2, 2025 20:53:30.896830082 CEST2793580192.168.2.23178.42.98.60
            Apr 2, 2025 20:53:30.896830082 CEST2793580192.168.2.23181.188.81.172
            Apr 2, 2025 20:53:30.896840096 CEST2793580192.168.2.23178.44.175.181
            Apr 2, 2025 20:53:30.896840096 CEST2793580192.168.2.23200.58.217.205
            Apr 2, 2025 20:53:30.896848917 CEST2793580192.168.2.2383.11.131.226
            Apr 2, 2025 20:53:30.896848917 CEST2793580192.168.2.2383.228.112.61
            Apr 2, 2025 20:53:30.896848917 CEST2793580192.168.2.2382.168.214.35
            Apr 2, 2025 20:53:30.896848917 CEST2793580192.168.2.2386.120.59.244
            Apr 2, 2025 20:53:30.896852016 CEST2793580192.168.2.23181.160.31.166
            Apr 2, 2025 20:53:30.896856070 CEST2793580192.168.2.23169.12.132.160
            Apr 2, 2025 20:53:30.896872044 CEST2793580192.168.2.23200.71.136.24
            Apr 2, 2025 20:53:30.896872044 CEST2793580192.168.2.2380.195.213.161
            Apr 2, 2025 20:53:30.896878958 CEST2793580192.168.2.23206.0.129.248
            Apr 2, 2025 20:53:30.896881104 CEST2793580192.168.2.23169.35.147.18
            Apr 2, 2025 20:53:30.896882057 CEST2793580192.168.2.23213.235.13.170
            Apr 2, 2025 20:53:30.896887064 CEST2793580192.168.2.23213.135.64.212
            Apr 2, 2025 20:53:30.896887064 CEST2793580192.168.2.23181.243.246.117
            Apr 2, 2025 20:53:30.896897078 CEST2793580192.168.2.2382.2.88.32
            Apr 2, 2025 20:53:30.896900892 CEST2793580192.168.2.23200.112.211.155
            Apr 2, 2025 20:53:30.896903992 CEST2793580192.168.2.23169.233.71.60
            Apr 2, 2025 20:53:30.896903992 CEST2793580192.168.2.23213.239.250.17
            Apr 2, 2025 20:53:30.896904945 CEST2793580192.168.2.2382.213.172.62
            Apr 2, 2025 20:53:30.896904945 CEST2793580192.168.2.2386.183.236.203
            Apr 2, 2025 20:53:30.896904945 CEST2793580192.168.2.23181.66.8.208
            Apr 2, 2025 20:53:30.896918058 CEST2793580192.168.2.23206.245.180.186
            Apr 2, 2025 20:53:30.896919012 CEST2793580192.168.2.23178.254.219.106
            Apr 2, 2025 20:53:30.896923065 CEST2793580192.168.2.23206.142.131.147
            Apr 2, 2025 20:53:30.896924973 CEST2793580192.168.2.2386.80.148.116
            Apr 2, 2025 20:53:30.896928072 CEST2793580192.168.2.23169.17.244.122
            Apr 2, 2025 20:53:30.896945000 CEST2793580192.168.2.23206.175.19.27
            Apr 2, 2025 20:53:30.896945953 CEST2793580192.168.2.23181.127.64.229
            Apr 2, 2025 20:53:30.896945953 CEST2793580192.168.2.2380.164.161.11
            Apr 2, 2025 20:53:30.896946907 CEST2793580192.168.2.23178.247.110.67
            Apr 2, 2025 20:53:30.896946907 CEST2793580192.168.2.2383.91.105.6
            Apr 2, 2025 20:53:30.896950006 CEST2793580192.168.2.2382.59.221.27
            Apr 2, 2025 20:53:30.896950006 CEST2793580192.168.2.2382.124.75.211
            Apr 2, 2025 20:53:30.896959066 CEST2793580192.168.2.23213.198.36.163
            Apr 2, 2025 20:53:30.896972895 CEST2793580192.168.2.2380.13.5.183
            Apr 2, 2025 20:53:30.896974087 CEST2793580192.168.2.2386.47.52.68
            Apr 2, 2025 20:53:30.896982908 CEST2793580192.168.2.23206.180.196.73
            Apr 2, 2025 20:53:30.896992922 CEST2793580192.168.2.23213.198.137.59
            Apr 2, 2025 20:53:30.896992922 CEST2793580192.168.2.2383.181.253.196
            Apr 2, 2025 20:53:30.896992922 CEST2793580192.168.2.23206.239.154.139
            Apr 2, 2025 20:53:30.896997929 CEST2793580192.168.2.23181.63.48.196
            Apr 2, 2025 20:53:30.896997929 CEST2793580192.168.2.23206.37.167.243
            Apr 2, 2025 20:53:30.896998882 CEST2793580192.168.2.23213.120.183.212
            Apr 2, 2025 20:53:30.896998882 CEST2793580192.168.2.23206.132.173.247
            Apr 2, 2025 20:53:30.897002935 CEST2793580192.168.2.23178.132.117.98
            Apr 2, 2025 20:53:30.897011995 CEST2793580192.168.2.2383.181.188.61
            Apr 2, 2025 20:53:30.897011995 CEST2793580192.168.2.2383.3.27.172
            Apr 2, 2025 20:53:30.897021055 CEST2793580192.168.2.23169.118.216.41
            Apr 2, 2025 20:53:30.897021055 CEST2793580192.168.2.2382.250.132.197
            Apr 2, 2025 20:53:30.897038937 CEST2793580192.168.2.23181.203.93.10
            Apr 2, 2025 20:53:30.897038937 CEST2793580192.168.2.2380.7.52.63
            Apr 2, 2025 20:53:30.897047997 CEST2793580192.168.2.2386.68.241.64
            Apr 2, 2025 20:53:30.897047997 CEST2793580192.168.2.23206.125.10.145
            Apr 2, 2025 20:53:30.897047997 CEST2793580192.168.2.23178.207.103.34
            Apr 2, 2025 20:53:30.897047997 CEST2793580192.168.2.23181.42.216.200
            Apr 2, 2025 20:53:30.897047997 CEST2793580192.168.2.2382.116.26.230
            Apr 2, 2025 20:53:30.897052050 CEST2793580192.168.2.23206.220.212.102
            Apr 2, 2025 20:53:30.897053957 CEST2793580192.168.2.2383.103.157.227
            Apr 2, 2025 20:53:30.897053957 CEST2793580192.168.2.23206.165.250.76
            Apr 2, 2025 20:53:30.897056103 CEST2793580192.168.2.23213.187.128.54
            Apr 2, 2025 20:53:30.897070885 CEST2793580192.168.2.23169.186.84.41
            Apr 2, 2025 20:53:30.897070885 CEST2793580192.168.2.23206.239.171.213
            Apr 2, 2025 20:53:30.897070885 CEST2793580192.168.2.23200.136.31.213
            Apr 2, 2025 20:53:30.897083044 CEST2793580192.168.2.2386.176.6.43
            Apr 2, 2025 20:53:30.897083044 CEST2793580192.168.2.2380.205.53.251
            Apr 2, 2025 20:53:30.897089005 CEST2793580192.168.2.2380.49.142.217
            Apr 2, 2025 20:53:30.897089005 CEST2793580192.168.2.2386.227.105.138
            Apr 2, 2025 20:53:30.897094011 CEST2793580192.168.2.2380.143.190.130
            Apr 2, 2025 20:53:30.897094011 CEST2793580192.168.2.2380.65.88.125
            Apr 2, 2025 20:53:30.897094965 CEST2793580192.168.2.2386.97.78.117
            Apr 2, 2025 20:53:30.897095919 CEST2793580192.168.2.23178.31.101.231
            Apr 2, 2025 20:53:30.897105932 CEST2793580192.168.2.23200.159.176.140
            Apr 2, 2025 20:53:30.897108078 CEST2793580192.168.2.23169.29.238.39
            Apr 2, 2025 20:53:30.897108078 CEST2793580192.168.2.23169.226.29.243
            Apr 2, 2025 20:53:30.897108078 CEST2793580192.168.2.23206.155.25.189
            Apr 2, 2025 20:53:30.897108078 CEST2793580192.168.2.23181.210.214.131
            Apr 2, 2025 20:53:30.897108078 CEST2793580192.168.2.2383.81.64.181
            Apr 2, 2025 20:53:30.897109985 CEST2793580192.168.2.23181.215.136.220
            Apr 2, 2025 20:53:30.897113085 CEST2793580192.168.2.23169.54.135.69
            Apr 2, 2025 20:53:30.897113085 CEST2793580192.168.2.23181.13.166.74
            Apr 2, 2025 20:53:30.897130013 CEST2793580192.168.2.23169.129.150.179
            Apr 2, 2025 20:53:30.897133112 CEST2793580192.168.2.23213.69.44.70
            Apr 2, 2025 20:53:30.897139072 CEST2793580192.168.2.23200.9.179.245
            Apr 2, 2025 20:53:30.897141933 CEST2793580192.168.2.23213.79.252.4
            Apr 2, 2025 20:53:30.897150993 CEST2793580192.168.2.23213.73.200.238
            Apr 2, 2025 20:53:30.897151947 CEST2793580192.168.2.23181.67.33.63
            Apr 2, 2025 20:53:30.897157907 CEST2793580192.168.2.2382.20.70.32
            Apr 2, 2025 20:53:30.897157907 CEST2793580192.168.2.2383.39.6.194
            Apr 2, 2025 20:53:30.897167921 CEST2793580192.168.2.2386.65.25.120
            Apr 2, 2025 20:53:30.897176981 CEST2793580192.168.2.23200.162.236.21
            Apr 2, 2025 20:53:30.897176981 CEST2793580192.168.2.23200.144.31.3
            Apr 2, 2025 20:53:30.897176981 CEST2793580192.168.2.23213.61.151.17
            Apr 2, 2025 20:53:30.897181034 CEST2793580192.168.2.23200.214.152.243
            Apr 2, 2025 20:53:30.897181034 CEST2793580192.168.2.23169.124.100.178
            Apr 2, 2025 20:53:30.897197008 CEST2793580192.168.2.2382.1.192.150
            Apr 2, 2025 20:53:30.897197962 CEST2793580192.168.2.23200.121.63.107
            Apr 2, 2025 20:53:30.897197962 CEST2793580192.168.2.23206.96.241.174
            Apr 2, 2025 20:53:30.897197962 CEST2793580192.168.2.23169.59.252.99
            Apr 2, 2025 20:53:30.897198915 CEST2793580192.168.2.23181.201.200.37
            Apr 2, 2025 20:53:30.897202969 CEST2793580192.168.2.2386.92.5.77
            Apr 2, 2025 20:53:30.897202969 CEST2793580192.168.2.23200.133.207.20
            Apr 2, 2025 20:53:30.897203922 CEST2793580192.168.2.23169.121.16.188
            Apr 2, 2025 20:53:30.897205114 CEST2793580192.168.2.2382.252.155.164
            Apr 2, 2025 20:53:30.897205114 CEST2793580192.168.2.23178.148.162.45
            Apr 2, 2025 20:53:30.897205114 CEST2793580192.168.2.23169.128.6.119
            Apr 2, 2025 20:53:30.897207022 CEST2793580192.168.2.2380.137.85.132
            Apr 2, 2025 20:53:30.897209883 CEST2793580192.168.2.2380.33.96.90
            Apr 2, 2025 20:53:30.897209883 CEST2793580192.168.2.23181.236.2.28
            Apr 2, 2025 20:53:30.897209883 CEST2793580192.168.2.23181.18.240.130
            Apr 2, 2025 20:53:30.897237062 CEST2793580192.168.2.23200.2.102.220
            Apr 2, 2025 20:53:30.897237062 CEST2793580192.168.2.2386.41.44.71
            Apr 2, 2025 20:53:30.897237062 CEST2793580192.168.2.23169.21.184.194
            Apr 2, 2025 20:53:30.897237062 CEST2793580192.168.2.2386.142.163.126
            Apr 2, 2025 20:53:30.897238970 CEST2793580192.168.2.2383.30.43.198
            Apr 2, 2025 20:53:30.897237062 CEST2793580192.168.2.23206.247.190.121
            Apr 2, 2025 20:53:30.897239923 CEST2793580192.168.2.23213.177.104.212
            Apr 2, 2025 20:53:30.897238970 CEST2793580192.168.2.23213.13.184.149
            Apr 2, 2025 20:53:30.897239923 CEST2793580192.168.2.23206.57.89.119
            Apr 2, 2025 20:53:30.897243023 CEST2793580192.168.2.2386.195.133.43
            Apr 2, 2025 20:53:30.897258043 CEST2793580192.168.2.2380.213.242.231
            Apr 2, 2025 20:53:30.897263050 CEST2793580192.168.2.23178.129.250.27
            Apr 2, 2025 20:53:30.897263050 CEST2793580192.168.2.23169.99.62.102
            Apr 2, 2025 20:53:30.897263050 CEST2793580192.168.2.2382.135.228.165
            Apr 2, 2025 20:53:30.897279978 CEST2793580192.168.2.2383.155.153.25
            Apr 2, 2025 20:53:30.897280931 CEST2793580192.168.2.23181.65.182.151
            Apr 2, 2025 20:53:30.897280931 CEST2793580192.168.2.2382.88.241.183
            Apr 2, 2025 20:53:30.897281885 CEST2793580192.168.2.23169.201.253.96
            Apr 2, 2025 20:53:30.897281885 CEST2793580192.168.2.23181.210.85.192
            Apr 2, 2025 20:53:30.897281885 CEST2793580192.168.2.23206.197.250.177
            Apr 2, 2025 20:53:30.897281885 CEST2793580192.168.2.23169.88.151.126
            Apr 2, 2025 20:53:30.897285938 CEST2793580192.168.2.23213.127.231.9
            Apr 2, 2025 20:53:30.897285938 CEST2793580192.168.2.23200.126.188.121
            Apr 2, 2025 20:53:30.897291899 CEST2793580192.168.2.23200.33.158.155
            Apr 2, 2025 20:53:30.897291899 CEST2793580192.168.2.23200.95.157.173
            Apr 2, 2025 20:53:30.897291899 CEST2793580192.168.2.23169.97.24.238
            Apr 2, 2025 20:53:30.897296906 CEST2793580192.168.2.23206.181.193.226
            Apr 2, 2025 20:53:30.897303104 CEST2793580192.168.2.23181.18.98.194
            Apr 2, 2025 20:53:30.897304058 CEST2793580192.168.2.23206.17.254.66
            Apr 2, 2025 20:53:30.897310019 CEST2793580192.168.2.2382.77.249.124
            Apr 2, 2025 20:53:30.897317886 CEST2793580192.168.2.2383.69.161.183
            Apr 2, 2025 20:53:30.897321939 CEST2793580192.168.2.23178.102.60.253
            Apr 2, 2025 20:53:30.897327900 CEST2793580192.168.2.23178.91.33.252
            Apr 2, 2025 20:53:30.897329092 CEST2793580192.168.2.2383.160.194.110
            Apr 2, 2025 20:53:30.897329092 CEST2793580192.168.2.23181.105.92.139
            Apr 2, 2025 20:53:30.897329092 CEST2793580192.168.2.2382.165.50.80
            Apr 2, 2025 20:53:30.897339106 CEST2793580192.168.2.2382.127.195.17
            Apr 2, 2025 20:53:30.897340059 CEST2793580192.168.2.23178.222.239.239
            Apr 2, 2025 20:53:30.897349119 CEST2793580192.168.2.23181.210.235.217
            Apr 2, 2025 20:53:30.897349119 CEST2793580192.168.2.23206.254.22.119
            Apr 2, 2025 20:53:30.897349119 CEST2793580192.168.2.23178.116.208.72
            Apr 2, 2025 20:53:30.897355080 CEST2793580192.168.2.23213.128.158.15
            Apr 2, 2025 20:53:30.897362947 CEST2793580192.168.2.23181.205.145.188
            Apr 2, 2025 20:53:30.897363901 CEST2793580192.168.2.23181.27.51.4
            Apr 2, 2025 20:53:30.897363901 CEST2793580192.168.2.23206.163.125.154
            Apr 2, 2025 20:53:30.897392035 CEST2793580192.168.2.2380.176.234.5
            Apr 2, 2025 20:53:30.897393942 CEST2793580192.168.2.23206.80.239.24
            Apr 2, 2025 20:53:30.897393942 CEST2793580192.168.2.2383.10.141.15
            Apr 2, 2025 20:53:30.897394896 CEST2793580192.168.2.2382.212.190.144
            Apr 2, 2025 20:53:30.897393942 CEST2793580192.168.2.23213.161.215.68
            Apr 2, 2025 20:53:30.897397995 CEST2793580192.168.2.23178.226.3.14
            Apr 2, 2025 20:53:30.897396088 CEST2793580192.168.2.2382.255.85.174
            Apr 2, 2025 20:53:30.897398949 CEST2793580192.168.2.23169.175.140.218
            Apr 2, 2025 20:53:30.897398949 CEST2793580192.168.2.2382.141.101.72
            Apr 2, 2025 20:53:30.897403002 CEST2793580192.168.2.2380.11.161.194
            Apr 2, 2025 20:53:30.897412062 CEST2793580192.168.2.23169.236.114.158
            Apr 2, 2025 20:53:30.897412062 CEST2793580192.168.2.23178.175.231.86
            Apr 2, 2025 20:53:30.897416115 CEST2793580192.168.2.2382.40.237.233
            Apr 2, 2025 20:53:30.897417068 CEST2793580192.168.2.23181.9.114.5
            Apr 2, 2025 20:53:30.897417068 CEST2793580192.168.2.23206.125.203.127
            Apr 2, 2025 20:53:30.897416115 CEST2793580192.168.2.23178.170.204.97
            Apr 2, 2025 20:53:30.897417068 CEST2793580192.168.2.23206.235.134.90
            Apr 2, 2025 20:53:30.897422075 CEST2793580192.168.2.23181.48.4.75
            Apr 2, 2025 20:53:30.897422075 CEST2793580192.168.2.23206.3.67.58
            Apr 2, 2025 20:53:30.897438049 CEST2793580192.168.2.23213.134.220.125
            Apr 2, 2025 20:53:30.897438049 CEST2793580192.168.2.2380.227.200.186
            Apr 2, 2025 20:53:30.897440910 CEST2793580192.168.2.2386.133.199.130
            Apr 2, 2025 20:53:30.897442102 CEST2793580192.168.2.23181.121.2.155
            Apr 2, 2025 20:53:30.897444010 CEST2793580192.168.2.23178.20.120.250
            Apr 2, 2025 20:53:30.897444963 CEST2793580192.168.2.2386.49.96.226
            Apr 2, 2025 20:53:30.897459030 CEST2793580192.168.2.23169.81.69.137
            Apr 2, 2025 20:53:30.897459030 CEST2793580192.168.2.23181.223.35.228
            Apr 2, 2025 20:53:30.897459030 CEST2793580192.168.2.2383.74.80.115
            Apr 2, 2025 20:53:30.897465944 CEST2793580192.168.2.23213.230.144.159
            Apr 2, 2025 20:53:30.897466898 CEST2793580192.168.2.2380.162.92.225
            Apr 2, 2025 20:53:30.897466898 CEST2793580192.168.2.23181.195.132.112
            Apr 2, 2025 20:53:30.897468090 CEST2793580192.168.2.2386.245.155.223
            Apr 2, 2025 20:53:30.897473097 CEST2793580192.168.2.2386.70.135.10
            Apr 2, 2025 20:53:30.897468090 CEST2793580192.168.2.2380.206.173.23
            Apr 2, 2025 20:53:30.897468090 CEST2793580192.168.2.23181.101.191.142
            Apr 2, 2025 20:53:30.897473097 CEST2793580192.168.2.2380.79.11.27
            Apr 2, 2025 20:53:30.897468090 CEST2793580192.168.2.2380.48.69.109
            Apr 2, 2025 20:53:30.897480965 CEST2793580192.168.2.2380.220.67.172
            Apr 2, 2025 20:53:30.897490025 CEST2793580192.168.2.2380.71.52.194
            Apr 2, 2025 20:53:30.897490025 CEST2793580192.168.2.23181.177.190.133
            Apr 2, 2025 20:53:30.897490025 CEST2793580192.168.2.2382.130.193.158
            Apr 2, 2025 20:53:30.897497892 CEST2793580192.168.2.23213.62.122.230
            Apr 2, 2025 20:53:30.897500038 CEST2793580192.168.2.23169.78.104.208
            Apr 2, 2025 20:53:30.897500992 CEST2793580192.168.2.2380.159.250.135
            Apr 2, 2025 20:53:30.897500992 CEST2793580192.168.2.2383.58.85.109
            Apr 2, 2025 20:53:30.897500992 CEST2793580192.168.2.23200.151.191.201
            Apr 2, 2025 20:53:30.897504091 CEST2793580192.168.2.23206.228.139.70
            Apr 2, 2025 20:53:30.897507906 CEST2793580192.168.2.23200.158.253.96
            Apr 2, 2025 20:53:30.897509098 CEST2793580192.168.2.23169.199.219.198
            Apr 2, 2025 20:53:30.897509098 CEST2793580192.168.2.2380.234.146.209
            Apr 2, 2025 20:53:30.897509098 CEST2793580192.168.2.23213.113.208.120
            Apr 2, 2025 20:53:30.897512913 CEST2793580192.168.2.2386.72.106.8
            Apr 2, 2025 20:53:30.897512913 CEST2793580192.168.2.23200.34.248.251
            Apr 2, 2025 20:53:30.897547007 CEST2793580192.168.2.2380.204.243.14
            Apr 2, 2025 20:53:30.897547007 CEST2793580192.168.2.23169.70.187.144
            Apr 2, 2025 20:53:30.897547960 CEST2793580192.168.2.23169.153.218.157
            Apr 2, 2025 20:53:30.897547960 CEST2793580192.168.2.23206.54.73.63
            Apr 2, 2025 20:53:30.897551060 CEST2793580192.168.2.2382.54.189.51
            Apr 2, 2025 20:53:30.897552013 CEST2793580192.168.2.23200.116.101.115
            Apr 2, 2025 20:53:30.897561073 CEST2793580192.168.2.2382.43.153.77
            Apr 2, 2025 20:53:30.897561073 CEST2793580192.168.2.2386.203.238.43
            Apr 2, 2025 20:53:30.897561073 CEST2793580192.168.2.23181.118.57.30
            Apr 2, 2025 20:53:30.897562981 CEST2793580192.168.2.23178.155.5.34
            Apr 2, 2025 20:53:30.897562981 CEST2793580192.168.2.23206.218.55.123
            Apr 2, 2025 20:53:30.897566080 CEST2793580192.168.2.23213.135.9.238
            Apr 2, 2025 20:53:30.897566080 CEST2793580192.168.2.2386.155.5.132
            Apr 2, 2025 20:53:30.897566080 CEST2793580192.168.2.23181.90.40.75
            Apr 2, 2025 20:53:30.897566080 CEST2793580192.168.2.23200.134.232.134
            Apr 2, 2025 20:53:30.897566080 CEST2793580192.168.2.23206.103.113.125
            Apr 2, 2025 20:53:30.897566080 CEST2793580192.168.2.2380.121.99.26
            Apr 2, 2025 20:53:30.897566080 CEST2793580192.168.2.23181.129.149.79
            Apr 2, 2025 20:53:30.897566080 CEST2793580192.168.2.23213.119.83.197
            Apr 2, 2025 20:53:30.897578001 CEST2793580192.168.2.2383.136.137.127
            Apr 2, 2025 20:53:30.897578001 CEST2793580192.168.2.23200.89.160.214
            Apr 2, 2025 20:53:30.897589922 CEST2793580192.168.2.2382.105.159.147
            Apr 2, 2025 20:53:30.897589922 CEST2793580192.168.2.23178.232.234.115
            Apr 2, 2025 20:53:30.897597075 CEST2793580192.168.2.23181.124.169.247
            Apr 2, 2025 20:53:30.897597075 CEST2793580192.168.2.23169.172.226.241
            Apr 2, 2025 20:53:30.897598028 CEST2793580192.168.2.23169.216.126.147
            Apr 2, 2025 20:53:30.897598028 CEST2793580192.168.2.23206.247.132.193
            Apr 2, 2025 20:53:30.897598982 CEST2793580192.168.2.23213.25.70.94
            Apr 2, 2025 20:53:30.897614956 CEST2793580192.168.2.2383.85.34.7
            Apr 2, 2025 20:53:30.897615910 CEST2793580192.168.2.2383.52.105.44
            Apr 2, 2025 20:53:30.897617102 CEST2793580192.168.2.2380.169.203.196
            Apr 2, 2025 20:53:30.897619963 CEST2793580192.168.2.2380.101.145.38
            Apr 2, 2025 20:53:30.897622108 CEST2793580192.168.2.2383.92.228.104
            Apr 2, 2025 20:53:30.897622108 CEST2793580192.168.2.23213.170.110.81
            Apr 2, 2025 20:53:30.897622108 CEST2793580192.168.2.23213.205.18.54
            Apr 2, 2025 20:53:30.897622108 CEST2793580192.168.2.23206.212.18.20
            Apr 2, 2025 20:53:30.897633076 CEST2793580192.168.2.2383.93.174.88
            Apr 2, 2025 20:53:30.897634029 CEST2793580192.168.2.2382.5.142.100
            Apr 2, 2025 20:53:30.897634029 CEST2793580192.168.2.2382.176.216.243
            Apr 2, 2025 20:53:30.897635937 CEST2793580192.168.2.23178.246.204.8
            Apr 2, 2025 20:53:30.897644997 CEST2793580192.168.2.23181.64.174.176
            Apr 2, 2025 20:53:30.897650957 CEST2793580192.168.2.2386.84.123.42
            Apr 2, 2025 20:53:30.897650957 CEST2793580192.168.2.2386.213.37.4
            Apr 2, 2025 20:53:30.897660971 CEST2793580192.168.2.23178.163.136.2
            Apr 2, 2025 20:53:30.897665977 CEST2793580192.168.2.23169.220.23.3
            Apr 2, 2025 20:53:30.897666931 CEST2793580192.168.2.2386.143.86.182
            Apr 2, 2025 20:53:30.897667885 CEST2793580192.168.2.2383.134.195.72
            Apr 2, 2025 20:53:30.897667885 CEST2793580192.168.2.23200.219.185.204
            Apr 2, 2025 20:53:30.897666931 CEST2793580192.168.2.23213.95.160.73
            Apr 2, 2025 20:53:30.897675037 CEST2793580192.168.2.23178.173.116.144
            Apr 2, 2025 20:53:30.897675037 CEST2793580192.168.2.23178.101.143.188
            Apr 2, 2025 20:53:30.897690058 CEST2793580192.168.2.23200.164.117.77
            Apr 2, 2025 20:53:30.897696018 CEST2793580192.168.2.23178.254.170.166
            Apr 2, 2025 20:53:30.897696018 CEST2793580192.168.2.23213.154.255.232
            Apr 2, 2025 20:53:30.897696018 CEST2793580192.168.2.23206.55.33.209
            Apr 2, 2025 20:53:30.897701979 CEST2793580192.168.2.23213.54.14.163
            Apr 2, 2025 20:53:30.897713900 CEST2793580192.168.2.2382.79.39.44
            Apr 2, 2025 20:53:30.897713900 CEST2793580192.168.2.23181.52.176.208
            Apr 2, 2025 20:53:30.897715092 CEST2793580192.168.2.23213.140.102.155
            Apr 2, 2025 20:53:30.897715092 CEST2793580192.168.2.2386.199.63.135
            Apr 2, 2025 20:53:30.897716045 CEST2793580192.168.2.23181.190.39.27
            Apr 2, 2025 20:53:30.897716045 CEST2793580192.168.2.2383.28.142.136
            Apr 2, 2025 20:53:30.897716045 CEST2793580192.168.2.23169.68.42.43
            Apr 2, 2025 20:53:30.897716999 CEST2793580192.168.2.2386.33.50.55
            Apr 2, 2025 20:53:30.897716999 CEST2793580192.168.2.2383.149.0.231
            Apr 2, 2025 20:53:30.897716999 CEST2793580192.168.2.2380.140.35.118
            Apr 2, 2025 20:53:30.897727013 CEST2793580192.168.2.23206.187.68.128
            Apr 2, 2025 20:53:30.897727013 CEST2793580192.168.2.23178.124.32.145
            Apr 2, 2025 20:53:30.897730112 CEST2793580192.168.2.23178.41.19.76
            Apr 2, 2025 20:53:30.897730112 CEST2793580192.168.2.23181.171.237.26
            Apr 2, 2025 20:53:30.897730112 CEST2793580192.168.2.23178.140.40.28
            Apr 2, 2025 20:53:30.897742033 CEST2793580192.168.2.2380.18.133.98
            Apr 2, 2025 20:53:30.897743940 CEST2793580192.168.2.2382.98.18.27
            Apr 2, 2025 20:53:30.897743940 CEST2793580192.168.2.23200.101.117.206
            Apr 2, 2025 20:53:30.897743940 CEST2793580192.168.2.23178.74.135.112
            Apr 2, 2025 20:53:30.897749901 CEST2793580192.168.2.23200.214.117.92
            Apr 2, 2025 20:53:30.897749901 CEST2793580192.168.2.23181.158.241.99
            Apr 2, 2025 20:53:30.897751093 CEST2793580192.168.2.23169.182.93.255
            Apr 2, 2025 20:53:30.897753000 CEST2793580192.168.2.2382.74.204.3
            Apr 2, 2025 20:53:30.897753000 CEST2793580192.168.2.23178.223.78.34
            Apr 2, 2025 20:53:30.897753000 CEST2793580192.168.2.2383.136.218.246
            Apr 2, 2025 20:53:30.897753000 CEST2793580192.168.2.23169.180.30.65
            Apr 2, 2025 20:53:30.897753000 CEST2793580192.168.2.23169.226.172.162
            Apr 2, 2025 20:53:30.897764921 CEST2793580192.168.2.23213.168.125.73
            Apr 2, 2025 20:53:30.897767067 CEST2793580192.168.2.2382.54.82.253
            Apr 2, 2025 20:53:30.897789001 CEST2793580192.168.2.2380.235.208.171
            Apr 2, 2025 20:53:30.897789001 CEST2793580192.168.2.2380.85.192.130
            Apr 2, 2025 20:53:30.897789001 CEST2793580192.168.2.2383.228.21.221
            Apr 2, 2025 20:53:30.897790909 CEST2793580192.168.2.2383.171.156.114
            Apr 2, 2025 20:53:30.897799015 CEST2793580192.168.2.23178.108.175.187
            Apr 2, 2025 20:53:30.897799015 CEST2793580192.168.2.2380.24.170.226
            Apr 2, 2025 20:53:30.897799969 CEST2793580192.168.2.23206.236.118.206
            Apr 2, 2025 20:53:30.897799015 CEST2793580192.168.2.23169.118.22.154
            Apr 2, 2025 20:53:30.897799969 CEST2793580192.168.2.23178.223.104.19
            Apr 2, 2025 20:53:30.897799015 CEST2793580192.168.2.2382.159.134.237
            Apr 2, 2025 20:53:30.897799969 CEST2793580192.168.2.2383.178.165.253
            Apr 2, 2025 20:53:30.897804022 CEST2793580192.168.2.23213.65.15.136
            Apr 2, 2025 20:53:30.897813082 CEST2793580192.168.2.23178.159.215.136
            Apr 2, 2025 20:53:30.897819042 CEST2793580192.168.2.2383.180.191.8
            Apr 2, 2025 20:53:30.897819042 CEST2793580192.168.2.23206.26.146.3
            Apr 2, 2025 20:53:30.897819042 CEST2793580192.168.2.23200.132.134.188
            Apr 2, 2025 20:53:30.897823095 CEST2793580192.168.2.23178.158.199.169
            Apr 2, 2025 20:53:30.897824049 CEST2793580192.168.2.2383.63.206.69
            Apr 2, 2025 20:53:30.897824049 CEST2793580192.168.2.23169.158.7.226
            Apr 2, 2025 20:53:30.897831917 CEST2793580192.168.2.23200.142.37.192
            Apr 2, 2025 20:53:30.897831917 CEST2793580192.168.2.23206.50.101.182
            Apr 2, 2025 20:53:30.897831917 CEST2793580192.168.2.23181.147.85.8
            Apr 2, 2025 20:53:30.897831917 CEST2793580192.168.2.23200.27.178.155
            Apr 2, 2025 20:53:30.897845030 CEST2793580192.168.2.2383.101.90.126
            Apr 2, 2025 20:53:30.897850990 CEST2793580192.168.2.23181.193.185.236
            Apr 2, 2025 20:53:30.897851944 CEST2793580192.168.2.23200.73.50.21
            Apr 2, 2025 20:53:30.897851944 CEST2793580192.168.2.23169.123.130.96
            Apr 2, 2025 20:53:30.897864103 CEST2793580192.168.2.2383.24.180.194
            Apr 2, 2025 20:53:30.897866011 CEST2793580192.168.2.2382.216.84.132
            Apr 2, 2025 20:53:30.897869110 CEST2793580192.168.2.2380.145.39.197
            Apr 2, 2025 20:53:30.897869110 CEST2793580192.168.2.23169.52.189.189
            Apr 2, 2025 20:53:30.897872925 CEST2793580192.168.2.2380.217.177.123
            Apr 2, 2025 20:53:30.897874117 CEST2793580192.168.2.2386.194.102.57
            Apr 2, 2025 20:53:30.897874117 CEST2793580192.168.2.2380.118.162.28
            Apr 2, 2025 20:53:30.897877932 CEST2793580192.168.2.2386.167.170.63
            Apr 2, 2025 20:53:30.897878885 CEST2793580192.168.2.23206.52.93.197
            Apr 2, 2025 20:53:30.897890091 CEST2793580192.168.2.23213.112.93.185
            Apr 2, 2025 20:53:30.897890091 CEST2793580192.168.2.23213.171.109.81
            Apr 2, 2025 20:53:30.897891045 CEST2793580192.168.2.23200.34.241.173
            Apr 2, 2025 20:53:30.897891045 CEST2793580192.168.2.23169.40.115.187
            Apr 2, 2025 20:53:30.897893906 CEST2793580192.168.2.23181.191.198.225
            Apr 2, 2025 20:53:30.897893906 CEST2793580192.168.2.2386.26.145.191
            Apr 2, 2025 20:53:30.897895098 CEST2793580192.168.2.23169.25.129.27
            Apr 2, 2025 20:53:30.897895098 CEST2793580192.168.2.23178.224.74.41
            Apr 2, 2025 20:53:30.897895098 CEST2793580192.168.2.23169.85.244.77
            Apr 2, 2025 20:53:30.897902012 CEST2793580192.168.2.2382.0.80.133
            Apr 2, 2025 20:53:30.897903919 CEST2793580192.168.2.2386.18.235.172
            Apr 2, 2025 20:53:30.897903919 CEST2793580192.168.2.23169.190.245.129
            Apr 2, 2025 20:53:30.897912025 CEST2793580192.168.2.23181.212.70.42
            Apr 2, 2025 20:53:30.897912025 CEST2793580192.168.2.23169.214.254.230
            Apr 2, 2025 20:53:30.897918940 CEST2793580192.168.2.23178.25.55.140
            Apr 2, 2025 20:53:30.897918940 CEST2793580192.168.2.23213.93.25.126
            Apr 2, 2025 20:53:30.897927046 CEST2793580192.168.2.23178.220.220.112
            Apr 2, 2025 20:53:30.897927046 CEST2793580192.168.2.23206.78.50.100
            Apr 2, 2025 20:53:30.897941113 CEST2793580192.168.2.23181.209.202.70
            Apr 2, 2025 20:53:30.897943020 CEST2793580192.168.2.23213.85.97.204
            Apr 2, 2025 20:53:30.897943020 CEST2793580192.168.2.2386.18.197.122
            Apr 2, 2025 20:53:30.897941113 CEST2793580192.168.2.2386.118.188.176
            Apr 2, 2025 20:53:30.897941113 CEST2793580192.168.2.2383.187.156.232
            Apr 2, 2025 20:53:30.897950888 CEST2793580192.168.2.23178.223.13.109
            Apr 2, 2025 20:53:30.897953033 CEST2793580192.168.2.23213.104.39.94
            Apr 2, 2025 20:53:30.897953033 CEST2793580192.168.2.23213.136.16.36
            Apr 2, 2025 20:53:30.897953033 CEST2793580192.168.2.23200.49.204.3
            Apr 2, 2025 20:53:30.897960901 CEST2793580192.168.2.2386.245.24.44
            Apr 2, 2025 20:53:30.897960901 CEST2793580192.168.2.2382.17.198.21
            Apr 2, 2025 20:53:30.897962093 CEST2793580192.168.2.23169.214.118.118
            Apr 2, 2025 20:53:30.897960901 CEST2793580192.168.2.2382.2.188.24
            Apr 2, 2025 20:53:30.897974014 CEST2793580192.168.2.23206.248.43.109
            Apr 2, 2025 20:53:30.897974014 CEST2793580192.168.2.23178.174.205.47
            Apr 2, 2025 20:53:30.897977114 CEST2793580192.168.2.2380.126.191.98
            Apr 2, 2025 20:53:30.897979021 CEST2793580192.168.2.2386.91.15.21
            Apr 2, 2025 20:53:30.897979021 CEST2793580192.168.2.2386.232.82.254
            Apr 2, 2025 20:53:30.897993088 CEST2793580192.168.2.2386.94.251.209
            Apr 2, 2025 20:53:30.897995949 CEST2793580192.168.2.23178.237.195.118
            Apr 2, 2025 20:53:30.897995949 CEST2793580192.168.2.23213.49.221.136
            Apr 2, 2025 20:53:30.898000956 CEST2793580192.168.2.2386.211.10.107
            Apr 2, 2025 20:53:30.898000956 CEST2793580192.168.2.2380.21.18.116
            Apr 2, 2025 20:53:30.898000956 CEST2793580192.168.2.2383.136.50.38
            Apr 2, 2025 20:53:30.898004055 CEST2793580192.168.2.23181.6.53.227
            Apr 2, 2025 20:53:30.898005962 CEST2793580192.168.2.2382.25.246.75
            Apr 2, 2025 20:53:30.898014069 CEST2793580192.168.2.2380.136.100.218
            Apr 2, 2025 20:53:30.898014069 CEST2793580192.168.2.23206.193.237.148
            Apr 2, 2025 20:53:30.898015976 CEST2793580192.168.2.23200.142.228.12
            Apr 2, 2025 20:53:30.898024082 CEST2793580192.168.2.2382.90.37.77
            Apr 2, 2025 20:53:30.898024082 CEST2793580192.168.2.2380.228.156.254
            Apr 2, 2025 20:53:30.898024082 CEST2793580192.168.2.23178.204.170.46
            Apr 2, 2025 20:53:30.898024082 CEST2793580192.168.2.23206.174.115.103
            Apr 2, 2025 20:53:30.898029089 CEST2793580192.168.2.23181.195.119.174
            Apr 2, 2025 20:53:30.898030996 CEST2793580192.168.2.23178.211.47.67
            Apr 2, 2025 20:53:30.898030996 CEST2793580192.168.2.23213.121.211.181
            Apr 2, 2025 20:53:30.898031950 CEST2793580192.168.2.2383.145.193.24
            Apr 2, 2025 20:53:30.898044109 CEST2793580192.168.2.23181.209.123.136
            Apr 2, 2025 20:53:30.898047924 CEST2793580192.168.2.23181.218.162.111
            Apr 2, 2025 20:53:30.898047924 CEST2793580192.168.2.23169.123.109.158
            Apr 2, 2025 20:53:30.898052931 CEST2793580192.168.2.2382.149.98.20
            Apr 2, 2025 20:53:30.898055077 CEST2793580192.168.2.23200.159.13.6
            Apr 2, 2025 20:53:30.898060083 CEST2793580192.168.2.23178.12.252.144
            Apr 2, 2025 20:53:30.898060083 CEST2793580192.168.2.23213.116.133.198
            Apr 2, 2025 20:53:30.898060083 CEST2793580192.168.2.2382.230.51.195
            Apr 2, 2025 20:53:30.898060083 CEST2793580192.168.2.2382.185.234.9
            Apr 2, 2025 20:53:30.898065090 CEST2793580192.168.2.23213.190.134.28
            Apr 2, 2025 20:53:30.898065090 CEST2793580192.168.2.2382.134.18.248
            Apr 2, 2025 20:53:30.898065090 CEST2793580192.168.2.2383.24.61.127
            Apr 2, 2025 20:53:30.898077011 CEST2793580192.168.2.23206.147.66.62
            Apr 2, 2025 20:53:30.898081064 CEST2793580192.168.2.23200.210.91.56
            Apr 2, 2025 20:53:30.898081064 CEST2793580192.168.2.2380.126.127.110
            Apr 2, 2025 20:53:30.898082018 CEST2793580192.168.2.23206.57.46.36
            Apr 2, 2025 20:53:30.898085117 CEST2793580192.168.2.23200.228.223.72
            Apr 2, 2025 20:53:30.898087025 CEST2793580192.168.2.2380.174.242.237
            Apr 2, 2025 20:53:30.898087025 CEST2793580192.168.2.2386.170.11.199
            Apr 2, 2025 20:53:30.898106098 CEST2793580192.168.2.23200.130.227.162
            Apr 2, 2025 20:53:30.898132086 CEST2793580192.168.2.23206.146.137.118
            Apr 2, 2025 20:53:30.898133039 CEST2793580192.168.2.2380.75.226.20
            Apr 2, 2025 20:53:30.898132086 CEST2793580192.168.2.23169.78.5.239
            Apr 2, 2025 20:53:30.898132086 CEST2793580192.168.2.2382.106.106.106
            Apr 2, 2025 20:53:30.898134947 CEST2793580192.168.2.23206.200.83.27
            Apr 2, 2025 20:53:30.898134947 CEST2793580192.168.2.23169.17.193.171
            Apr 2, 2025 20:53:30.898134947 CEST2793580192.168.2.2382.75.248.113
            Apr 2, 2025 20:53:30.898138046 CEST2793580192.168.2.23213.113.173.174
            Apr 2, 2025 20:53:30.898138046 CEST2793580192.168.2.23181.254.157.41
            Apr 2, 2025 20:53:30.898138046 CEST2793580192.168.2.23178.204.117.221
            Apr 2, 2025 20:53:30.898138046 CEST2793580192.168.2.23181.126.173.200
            Apr 2, 2025 20:53:30.898144960 CEST2793580192.168.2.2386.58.107.241
            Apr 2, 2025 20:53:30.898144960 CEST2793580192.168.2.2386.240.254.150
            Apr 2, 2025 20:53:30.898139954 CEST2793580192.168.2.23213.126.38.9
            Apr 2, 2025 20:53:30.898139954 CEST2793580192.168.2.23206.114.247.74
            Apr 2, 2025 20:53:30.898139954 CEST2793580192.168.2.23178.78.76.22
            Apr 2, 2025 20:53:30.898139954 CEST2793580192.168.2.23181.69.103.33
            Apr 2, 2025 20:53:30.898150921 CEST2793580192.168.2.23206.111.233.34
            Apr 2, 2025 20:53:30.898150921 CEST2793580192.168.2.23200.10.152.67
            Apr 2, 2025 20:53:30.898150921 CEST2793580192.168.2.2380.18.41.38
            Apr 2, 2025 20:53:30.898159981 CEST2793580192.168.2.23206.193.200.132
            Apr 2, 2025 20:53:30.898159981 CEST2793580192.168.2.2383.228.247.170
            Apr 2, 2025 20:53:30.898161888 CEST2793580192.168.2.23181.160.206.44
            Apr 2, 2025 20:53:30.898169994 CEST2793580192.168.2.23169.48.215.173
            Apr 2, 2025 20:53:30.898169994 CEST2793580192.168.2.2380.40.239.11
            Apr 2, 2025 20:53:30.898169994 CEST2793580192.168.2.2380.96.60.144
            Apr 2, 2025 20:53:30.898169994 CEST2793580192.168.2.23169.9.53.107
            Apr 2, 2025 20:53:30.898169994 CEST2793580192.168.2.2380.73.75.83
            Apr 2, 2025 20:53:30.898169994 CEST2793580192.168.2.2380.36.34.220
            Apr 2, 2025 20:53:30.898180008 CEST2793580192.168.2.23178.163.220.74
            Apr 2, 2025 20:53:30.898180962 CEST2793580192.168.2.23213.129.175.154
            Apr 2, 2025 20:53:30.898181915 CEST2793580192.168.2.23169.198.15.82
            Apr 2, 2025 20:53:30.898181915 CEST2793580192.168.2.23178.11.156.250
            Apr 2, 2025 20:53:30.898186922 CEST2793580192.168.2.2386.116.120.53
            Apr 2, 2025 20:53:30.898186922 CEST2793580192.168.2.2380.198.37.189
            Apr 2, 2025 20:53:30.898194075 CEST2793580192.168.2.23178.105.179.77
            Apr 2, 2025 20:53:30.898194075 CEST2793580192.168.2.2383.232.191.215
            Apr 2, 2025 20:53:30.898207903 CEST2793580192.168.2.23213.122.240.234
            Apr 2, 2025 20:53:30.898212910 CEST2793580192.168.2.2383.78.193.229
            Apr 2, 2025 20:53:30.898221970 CEST2793580192.168.2.2386.136.133.124
            Apr 2, 2025 20:53:30.898221970 CEST2793580192.168.2.2386.78.164.37
            Apr 2, 2025 20:53:30.898221970 CEST2793580192.168.2.2380.132.126.22
            Apr 2, 2025 20:53:30.898224115 CEST2793580192.168.2.23213.172.6.105
            Apr 2, 2025 20:53:30.898224115 CEST2793580192.168.2.23200.185.189.26
            Apr 2, 2025 20:53:30.898224115 CEST2793580192.168.2.2383.129.72.74
            Apr 2, 2025 20:53:30.898227930 CEST2793580192.168.2.2380.226.181.179
            Apr 2, 2025 20:53:30.898237944 CEST2793580192.168.2.23169.58.246.211
            Apr 2, 2025 20:53:30.898237944 CEST2793580192.168.2.23213.188.170.39
            Apr 2, 2025 20:53:30.898237944 CEST2793580192.168.2.23200.194.248.82
            Apr 2, 2025 20:53:30.898237944 CEST2793580192.168.2.2386.226.24.82
            Apr 2, 2025 20:53:30.898242950 CEST2793580192.168.2.23181.187.147.207
            Apr 2, 2025 20:53:30.898243904 CEST2793580192.168.2.23181.153.146.63
            Apr 2, 2025 20:53:30.898242950 CEST2793580192.168.2.23181.151.203.109
            Apr 2, 2025 20:53:30.898247957 CEST2793580192.168.2.2383.17.149.184
            Apr 2, 2025 20:53:30.898250103 CEST2793580192.168.2.2382.59.9.75
            Apr 2, 2025 20:53:30.898253918 CEST2793580192.168.2.23206.172.42.244
            Apr 2, 2025 20:53:30.898264885 CEST2793580192.168.2.23181.96.202.80
            Apr 2, 2025 20:53:30.898274899 CEST2793580192.168.2.23213.83.56.189
            Apr 2, 2025 20:53:30.898274899 CEST2793580192.168.2.23178.77.172.57
            Apr 2, 2025 20:53:30.898274899 CEST2793580192.168.2.2386.97.156.4
            Apr 2, 2025 20:53:30.898274899 CEST2793580192.168.2.2386.98.147.135
            Apr 2, 2025 20:53:30.898276091 CEST2793580192.168.2.2386.233.35.227
            Apr 2, 2025 20:53:30.898276091 CEST2793580192.168.2.23206.254.151.119
            Apr 2, 2025 20:53:30.898276091 CEST2793580192.168.2.23200.152.242.240
            Apr 2, 2025 20:53:30.898283958 CEST2793580192.168.2.23181.233.217.147
            Apr 2, 2025 20:53:30.898283958 CEST2793580192.168.2.2380.134.123.141
            Apr 2, 2025 20:53:30.898284912 CEST2793580192.168.2.23169.138.109.204
            Apr 2, 2025 20:53:30.898284912 CEST2793580192.168.2.23178.13.58.149
            Apr 2, 2025 20:53:30.898291111 CEST2793580192.168.2.2386.150.45.122
            Apr 2, 2025 20:53:30.898294926 CEST2793580192.168.2.23200.0.23.46
            Apr 2, 2025 20:53:30.898294926 CEST2793580192.168.2.2380.124.214.162
            Apr 2, 2025 20:53:30.898299932 CEST2793580192.168.2.2383.179.249.87
            Apr 2, 2025 20:53:30.898299932 CEST2793580192.168.2.23169.158.111.91
            Apr 2, 2025 20:53:30.898300886 CEST2793580192.168.2.23200.238.253.236
            Apr 2, 2025 20:53:30.898300886 CEST2793580192.168.2.23169.203.25.22
            Apr 2, 2025 20:53:30.898302078 CEST2793580192.168.2.2383.105.79.70
            Apr 2, 2025 20:53:30.898302078 CEST2793580192.168.2.23181.186.131.225
            Apr 2, 2025 20:53:30.898302078 CEST2793580192.168.2.23178.235.179.173
            Apr 2, 2025 20:53:30.898305893 CEST2793580192.168.2.23200.246.187.187
            Apr 2, 2025 20:53:30.898308039 CEST2793580192.168.2.23213.139.62.159
            Apr 2, 2025 20:53:30.898319960 CEST2793580192.168.2.23200.198.128.79
            Apr 2, 2025 20:53:30.898329020 CEST2793580192.168.2.2382.220.98.132
            Apr 2, 2025 20:53:30.898329973 CEST2793580192.168.2.23206.219.142.192
            Apr 2, 2025 20:53:30.898332119 CEST2793580192.168.2.2386.178.60.65
            Apr 2, 2025 20:53:30.898333073 CEST2793580192.168.2.23169.118.247.64
            Apr 2, 2025 20:53:30.898358107 CEST2793580192.168.2.23169.195.187.214
            Apr 2, 2025 20:53:30.898360014 CEST2793580192.168.2.2383.225.15.97
            Apr 2, 2025 20:53:30.898360014 CEST2793580192.168.2.2383.183.125.167
            Apr 2, 2025 20:53:30.898360968 CEST2793580192.168.2.23178.150.96.254
            Apr 2, 2025 20:53:30.898360968 CEST2793580192.168.2.23169.54.28.110
            Apr 2, 2025 20:53:30.898360968 CEST2793580192.168.2.23181.106.65.205
            Apr 2, 2025 20:53:30.898363113 CEST2793580192.168.2.23200.48.31.112
            Apr 2, 2025 20:53:30.898363113 CEST2793580192.168.2.2382.186.59.95
            Apr 2, 2025 20:53:30.898363113 CEST2793580192.168.2.2386.121.135.28
            Apr 2, 2025 20:53:30.898364067 CEST2793580192.168.2.23169.199.123.38
            Apr 2, 2025 20:53:30.898371935 CEST2793580192.168.2.2382.83.100.244
            Apr 2, 2025 20:53:30.898371935 CEST2793580192.168.2.2380.197.127.168
            Apr 2, 2025 20:53:30.898381948 CEST2793580192.168.2.2382.140.228.167
            Apr 2, 2025 20:53:30.898381948 CEST2793580192.168.2.23178.224.146.41
            Apr 2, 2025 20:53:30.898384094 CEST2793580192.168.2.23181.183.57.231
            Apr 2, 2025 20:53:30.898384094 CEST2793580192.168.2.2383.249.42.76
            Apr 2, 2025 20:53:30.898385048 CEST2793580192.168.2.23178.211.182.165
            Apr 2, 2025 20:53:30.898385048 CEST2793580192.168.2.23169.52.106.246
            Apr 2, 2025 20:53:30.898385048 CEST2793580192.168.2.23181.140.243.72
            Apr 2, 2025 20:53:30.898385048 CEST2793580192.168.2.23181.46.146.174
            Apr 2, 2025 20:53:30.898394108 CEST2793580192.168.2.23200.68.163.167
            Apr 2, 2025 20:53:30.898395061 CEST2793580192.168.2.23206.213.111.99
            Apr 2, 2025 20:53:30.898395061 CEST2793580192.168.2.2380.138.64.149
            Apr 2, 2025 20:53:30.898399115 CEST2793580192.168.2.2382.77.62.244
            Apr 2, 2025 20:53:30.898399115 CEST2793580192.168.2.2383.46.18.87
            Apr 2, 2025 20:53:30.898399115 CEST2793580192.168.2.23169.142.224.215
            Apr 2, 2025 20:53:30.898399115 CEST2793580192.168.2.2386.174.178.78
            Apr 2, 2025 20:53:30.898402929 CEST2793580192.168.2.2383.240.30.140
            Apr 2, 2025 20:53:30.898400068 CEST2793580192.168.2.2380.141.203.132
            Apr 2, 2025 20:53:30.898405075 CEST2793580192.168.2.23181.177.232.158
            Apr 2, 2025 20:53:30.898405075 CEST2793580192.168.2.23206.183.118.220
            Apr 2, 2025 20:53:30.898406982 CEST2793580192.168.2.23169.56.53.43
            Apr 2, 2025 20:53:30.898406982 CEST2793580192.168.2.23206.218.167.244
            Apr 2, 2025 20:53:30.898402929 CEST2793580192.168.2.2382.170.91.174
            Apr 2, 2025 20:53:30.898402929 CEST2793580192.168.2.2382.18.19.108
            Apr 2, 2025 20:53:30.898413897 CEST2793580192.168.2.23169.125.73.98
            Apr 2, 2025 20:53:30.898420095 CEST2793580192.168.2.2382.161.29.182
            Apr 2, 2025 20:53:30.898423910 CEST2793580192.168.2.23178.240.89.171
            Apr 2, 2025 20:53:30.898432970 CEST2793580192.168.2.23181.208.156.244
            Apr 2, 2025 20:53:30.898432970 CEST2793580192.168.2.23169.113.61.108
            Apr 2, 2025 20:53:30.898442984 CEST2793580192.168.2.23200.247.182.240
            Apr 2, 2025 20:53:30.898447037 CEST2793580192.168.2.23206.235.5.218
            Apr 2, 2025 20:53:30.898449898 CEST2793580192.168.2.2386.171.43.152
            Apr 2, 2025 20:53:30.898449898 CEST2793580192.168.2.2380.104.87.114
            Apr 2, 2025 20:53:30.898451090 CEST2793580192.168.2.23181.175.242.37
            Apr 2, 2025 20:53:30.898452997 CEST2793580192.168.2.23206.26.177.137
            Apr 2, 2025 20:53:30.898462057 CEST2793580192.168.2.23181.92.64.101
            Apr 2, 2025 20:53:30.898462057 CEST2793580192.168.2.2386.9.73.106
            Apr 2, 2025 20:53:30.898471117 CEST2793580192.168.2.23200.72.96.137
            Apr 2, 2025 20:53:30.898471117 CEST2793580192.168.2.23181.242.54.192
            Apr 2, 2025 20:53:30.898471117 CEST2793580192.168.2.2380.48.175.158
            Apr 2, 2025 20:53:30.898474932 CEST2793580192.168.2.2383.191.12.26
            Apr 2, 2025 20:53:30.898474932 CEST2793580192.168.2.2382.65.135.179
            Apr 2, 2025 20:53:30.898477077 CEST2793580192.168.2.2382.155.145.88
            Apr 2, 2025 20:53:30.898477077 CEST2793580192.168.2.23200.73.25.26
            Apr 2, 2025 20:53:30.898480892 CEST2793580192.168.2.23200.86.64.20
            Apr 2, 2025 20:53:30.898480892 CEST2793580192.168.2.2383.72.69.5
            Apr 2, 2025 20:53:30.898487091 CEST2793580192.168.2.23213.212.81.96
            Apr 2, 2025 20:53:30.898487091 CEST2793580192.168.2.2382.220.181.98
            Apr 2, 2025 20:53:30.898487091 CEST2793580192.168.2.2382.111.254.33
            Apr 2, 2025 20:53:30.898489952 CEST2793580192.168.2.23213.250.142.78
            Apr 2, 2025 20:53:30.898504972 CEST2793580192.168.2.23178.135.86.247
            Apr 2, 2025 20:53:30.898508072 CEST2793580192.168.2.23181.187.181.109
            Apr 2, 2025 20:53:30.898508072 CEST2793580192.168.2.2382.246.147.17
            Apr 2, 2025 20:53:30.898509979 CEST2793580192.168.2.2383.146.213.162
            Apr 2, 2025 20:53:30.898514986 CEST2793580192.168.2.23181.5.52.245
            Apr 2, 2025 20:53:30.898514986 CEST2793580192.168.2.2386.77.25.0
            Apr 2, 2025 20:53:30.898518085 CEST2793580192.168.2.2382.35.72.122
            Apr 2, 2025 20:53:30.898518085 CEST2793580192.168.2.23213.138.4.112
            Apr 2, 2025 20:53:30.898520947 CEST2793580192.168.2.23169.247.183.249
            Apr 2, 2025 20:53:30.898530960 CEST2793580192.168.2.2383.82.34.52
            Apr 2, 2025 20:53:30.898530960 CEST2793580192.168.2.2383.11.205.73
            Apr 2, 2025 20:53:30.898547888 CEST2793580192.168.2.23178.194.88.226
            Apr 2, 2025 20:53:30.898550034 CEST2793580192.168.2.2383.60.219.27
            Apr 2, 2025 20:53:30.898557901 CEST2793580192.168.2.23181.179.215.214
            Apr 2, 2025 20:53:30.898557901 CEST2793580192.168.2.2386.8.207.249
            Apr 2, 2025 20:53:30.898565054 CEST2793580192.168.2.23181.135.37.218
            Apr 2, 2025 20:53:30.898576021 CEST2793580192.168.2.2386.98.122.167
            Apr 2, 2025 20:53:30.898606062 CEST2793580192.168.2.23178.206.234.170
            Apr 2, 2025 20:53:30.898606062 CEST2793580192.168.2.2380.131.176.174
            Apr 2, 2025 20:53:30.898607016 CEST2793580192.168.2.2380.123.1.78
            Apr 2, 2025 20:53:30.898607016 CEST2793580192.168.2.23213.1.155.229
            Apr 2, 2025 20:53:30.898607016 CEST2793580192.168.2.23213.43.62.107
            Apr 2, 2025 20:53:30.898607016 CEST2793580192.168.2.23213.3.147.108
            Apr 2, 2025 20:53:30.898614883 CEST2793580192.168.2.23206.78.49.252
            Apr 2, 2025 20:53:30.898614883 CEST2793580192.168.2.23181.190.181.68
            Apr 2, 2025 20:53:30.898617029 CEST2793580192.168.2.23206.222.17.200
            Apr 2, 2025 20:53:30.898617029 CEST2793580192.168.2.2383.156.202.41
            Apr 2, 2025 20:53:30.898617029 CEST2793580192.168.2.23200.60.221.44
            Apr 2, 2025 20:53:30.898617029 CEST2793580192.168.2.2386.157.23.247
            Apr 2, 2025 20:53:30.898622036 CEST2793580192.168.2.2380.162.183.36
            Apr 2, 2025 20:53:30.898628950 CEST2793580192.168.2.2386.243.5.213
            Apr 2, 2025 20:53:30.898628950 CEST2793580192.168.2.2386.101.19.0
            Apr 2, 2025 20:53:30.898629904 CEST2793580192.168.2.2380.153.161.97
            Apr 2, 2025 20:53:30.898629904 CEST2793580192.168.2.23206.148.253.243
            Apr 2, 2025 20:53:30.898636103 CEST2793580192.168.2.23181.14.33.141
            Apr 2, 2025 20:53:30.898637056 CEST2793580192.168.2.23213.18.225.205
            Apr 2, 2025 20:53:30.898643970 CEST2793580192.168.2.2386.202.18.45
            Apr 2, 2025 20:53:30.898643970 CEST2793580192.168.2.23178.171.125.95
            Apr 2, 2025 20:53:30.898653030 CEST2793580192.168.2.23169.252.194.112
            Apr 2, 2025 20:53:30.898653030 CEST2793580192.168.2.2386.67.119.95
            Apr 2, 2025 20:53:30.898653030 CEST2793580192.168.2.23200.231.90.35
            Apr 2, 2025 20:53:30.898653030 CEST2793580192.168.2.2383.60.238.233
            Apr 2, 2025 20:53:31.052771091 CEST8027935181.215.136.220192.168.2.23
            Apr 2, 2025 20:53:31.052830935 CEST2793580192.168.2.23181.215.136.220
            Apr 2, 2025 20:53:31.081078053 CEST8027935213.64.179.208192.168.2.23
            Apr 2, 2025 20:53:31.084520102 CEST802793582.20.70.32192.168.2.23
            Apr 2, 2025 20:53:31.089611053 CEST802793580.79.11.27192.168.2.23
            Apr 2, 2025 20:53:31.089668989 CEST2793580192.168.2.2380.79.11.27
            Apr 2, 2025 20:53:31.095527887 CEST8027935200.160.222.250192.168.2.23
            Apr 2, 2025 20:53:31.095700026 CEST2793580192.168.2.23200.160.222.250
            Apr 2, 2025 20:53:31.096775055 CEST802793583.227.3.102192.168.2.23
            Apr 2, 2025 20:53:31.096827984 CEST2793580192.168.2.2383.227.3.102
            Apr 2, 2025 20:53:31.100416899 CEST802793582.165.50.80192.168.2.23
            Apr 2, 2025 20:53:31.100640059 CEST2793580192.168.2.2382.165.50.80
            Apr 2, 2025 20:53:31.107769966 CEST802793582.59.221.27192.168.2.23
            Apr 2, 2025 20:53:31.117460966 CEST8027935200.144.31.3192.168.2.23
            Apr 2, 2025 20:53:31.117477894 CEST802793582.77.249.124192.168.2.23
            Apr 2, 2025 20:53:31.117494106 CEST8027935178.235.63.6192.168.2.23
            Apr 2, 2025 20:53:31.117527008 CEST2793580192.168.2.2382.77.249.124
            Apr 2, 2025 20:53:31.135121107 CEST8027935178.31.101.231192.168.2.23
            Apr 2, 2025 20:53:31.135255098 CEST2793580192.168.2.23178.31.101.231
            Apr 2, 2025 20:53:31.135392904 CEST8027935200.107.245.98192.168.2.23
            Apr 2, 2025 20:53:31.135943890 CEST2793580192.168.2.23200.107.245.98
            Apr 2, 2025 20:53:31.161864042 CEST8027935181.13.166.74192.168.2.23
            Apr 2, 2025 20:53:31.171875954 CEST8027935178.219.56.12192.168.2.23
            Apr 2, 2025 20:53:31.171941996 CEST2793580192.168.2.23178.219.56.12
            Apr 2, 2025 20:53:31.173770905 CEST8027935200.43.169.247192.168.2.23
            Apr 2, 2025 20:53:31.257859945 CEST8027935181.101.191.142192.168.2.23
            Apr 2, 2025 20:53:31.486623049 CEST8027935213.87.12.229192.168.2.23
            Apr 2, 2025 20:53:32.090413094 CEST42836443192.168.2.2391.189.91.43
            Apr 2, 2025 20:53:32.145283937 CEST8027935181.18.240.130192.168.2.23
            Apr 2, 2025 20:53:33.626389027 CEST4251680192.168.2.23109.202.202.202
            Apr 2, 2025 20:53:47.192466974 CEST43928443192.168.2.2391.189.91.42
            Apr 2, 2025 20:53:54.130896091 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:54.130949020 CEST44337606162.213.35.24192.168.2.23
            Apr 2, 2025 20:53:54.130992889 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:56.684053898 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:56.684078932 CEST44337606162.213.35.24192.168.2.23
            Apr 2, 2025 20:53:56.926353931 CEST44337606162.213.35.24192.168.2.23
            Apr 2, 2025 20:53:56.926439047 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:56.927153111 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:56.927153111 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:56.927160978 CEST44337606162.213.35.24192.168.2.23
            Apr 2, 2025 20:53:56.927174091 CEST44337606162.213.35.24192.168.2.23
            Apr 2, 2025 20:53:56.927426100 CEST44337606162.213.35.24192.168.2.23
            Apr 2, 2025 20:53:56.927766085 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:56.927793026 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:56.927797079 CEST44337606162.213.35.24192.168.2.23
            Apr 2, 2025 20:53:56.927908897 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:57.124095917 CEST44337606162.213.35.24192.168.2.23
            Apr 2, 2025 20:53:57.124233961 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:57.124329090 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:57.124329090 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:57.124370098 CEST44337606162.213.35.24192.168.2.23
            Apr 2, 2025 20:53:57.124449968 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:57.124464035 CEST44337606162.213.35.24192.168.2.23
            Apr 2, 2025 20:53:57.124480963 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:57.124511003 CEST44337606162.213.35.24192.168.2.23
            Apr 2, 2025 20:53:57.124532938 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:57.124532938 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:57.124574900 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:57.124584913 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:57.124674082 CEST44337606162.213.35.24192.168.2.23
            Apr 2, 2025 20:53:57.124742031 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:57.124742031 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:57.124754906 CEST44337606162.213.35.24192.168.2.23
            Apr 2, 2025 20:53:57.124769926 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:57.124769926 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:57.124802113 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:57.124965906 CEST44337606162.213.35.24192.168.2.23
            Apr 2, 2025 20:53:57.125036001 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:57.125046015 CEST44337606162.213.35.24192.168.2.23
            Apr 2, 2025 20:53:57.125053883 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:57.125111103 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:57.125135899 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:57.125135899 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:57.125183105 CEST44337606162.213.35.24192.168.2.23
            Apr 2, 2025 20:53:57.125283003 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:57.125291109 CEST44337606162.213.35.24192.168.2.23
            Apr 2, 2025 20:53:57.555282116 CEST44337606162.213.35.24192.168.2.23
            Apr 2, 2025 20:53:57.555427074 CEST44337606162.213.35.24192.168.2.23
            Apr 2, 2025 20:53:57.555464983 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:57.555464983 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:57.555490971 CEST44337606162.213.35.24192.168.2.23
            Apr 2, 2025 20:53:57.556955099 CEST37606443192.168.2.23162.213.35.24
            Apr 2, 2025 20:53:59.478620052 CEST42836443192.168.2.2391.189.91.43
            Apr 2, 2025 20:54:03.574232101 CEST4251680192.168.2.23109.202.202.202
            Apr 2, 2025 20:54:28.146704912 CEST43928443192.168.2.2391.189.91.42
            TimestampSource PortDest PortSource IPDest IP
            Apr 2, 2025 20:53:53.863008976 CEST3439853192.168.2.231.1.1.1
            Apr 2, 2025 20:53:53.863130093 CEST4601653192.168.2.231.1.1.1
            Apr 2, 2025 20:53:53.966358900 CEST53460161.1.1.1192.168.2.23
            Apr 2, 2025 20:53:53.967715979 CEST53343981.1.1.1192.168.2.23
            Apr 2, 2025 20:53:54.014563084 CEST3899553192.168.2.231.1.1.1
            Apr 2, 2025 20:53:54.123881102 CEST53389951.1.1.1192.168.2.23
            TimestampSource IPDest IPChecksumCodeType
            Apr 2, 2025 20:53:55.161330938 CEST192.168.2.23192.168.2.18283(Port unreachable)Destination Unreachable
            Apr 2, 2025 20:55:15.179532051 CEST192.168.2.23192.168.2.18283(Port unreachable)Destination Unreachable
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Apr 2, 2025 20:53:53.863008976 CEST192.168.2.231.1.1.10x6463Standard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
            Apr 2, 2025 20:53:53.863130093 CEST192.168.2.231.1.1.10x84c9Standard query (0)daisy.ubuntu.com28IN (0x0001)false
            Apr 2, 2025 20:53:54.014563084 CEST192.168.2.231.1.1.10x5e6Standard query (0)daisy.ubuntu.com28IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Apr 2, 2025 20:53:53.967715979 CEST1.1.1.1192.168.2.230x6463No error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
            Apr 2, 2025 20:53:53.967715979 CEST1.1.1.1192.168.2.230x6463No error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
            • daisy.ubuntu.com
            Session IDSource IPSource PortDestination IPDestination Port
            0192.168.2.2337606162.213.35.24443
            TimestampBytes transferredDirectionData
            2025-04-02 18:53:56 UTC307OUTPOST /9aadafe2051348cd32033e1cad68f0a5fe46fba3240ac1e6e42158f31b8a1371790c09baf3996b4979fe8e533446c7dedf30f654c68b25357334c66911dc6a9e HTTP/1.1
            Host: daisy.ubuntu.com
            Accept: */*
            Content-Type: application/octet-stream
            X-Whoopsie-Version: 0.2.69ubuntu0.3
            Content-Length: 164887
            Expect: 100-continue
            2025-04-02 18:53:57 UTC25INHTTP/1.1 100 Continue
            2025-04-02 18:53:57 UTC16384OUTData Raw: 17 84 02 00 02 50 72 6f 63 45 6e 76 69 72 6f 6e 00 4e 00 00 00 50 41 54 48 3d 28 63 75 73 74 6f 6d 2c 20 6e 6f 20 75 73 65 72 29 0a 58 44 47 5f 52 55 4e 54 49 4d 45 5f 44 49 52 3d 3c 73 65 74 3e 0a 4c 41 4e 47 3d 65 6e 5f 55 53 2e 55 54 46 2d 38 0a 53 48 45 4c 4c 3d 2f 62 69 6e 2f 62 61 73 68 00 02 5f 4c 6f 67 69 6e 64 53 65 73 73 69 6f 6e 00 02 00 00 00 35 00 02 44 61 74 65 00 19 00 00 00 54 75 65 20 41 75 67 20 31 37 20 32 30 3a 31 38 3a 30 34 20 32 30 32 31 00 02 53 6f 75 72 63 65 50 61 63 6b 61 67 65 00 0d 00 00 00 6c 69 67 68 74 2d 6c 6f 63 6b 65 72 00 02 50 61 63 6b 61 67 65 41 72 63 68 69 74 65 63 74 75 72 65 00 06 00 00 00 61 6d 64 36 34 00 02 41 72 63 68 69 74 65 63 74 75 72 65 00 06 00 00 00 61 6d 64 36 34 00 02 44 69 73 74 72 6f 52 65 6c 65 61
            Data Ascii: ProcEnvironNPATH=(custom, no user)XDG_RUNTIME_DIR=<set>LANG=en_US.UTF-8SHELL=/bin/bash_LogindSession5DateTue Aug 17 20:18:04 2021SourcePackagelight-lockerPackageArchitectureamd64Architectureamd64DistroRelea
            2025-04-02 18:53:57 UTC16384OUTData Raw: 74 75 34 2e 31 0a 6c 69 62 70 61 6d 2d 72 75 6e 74 69 6d 65 20 31 2e 33 2e 31 2d 35 75 62 75 6e 74 75 34 2e 31 0a 6c 69 62 70 61 6d 2d 73 79 73 74 65 6d 64 20 32 34 35 2e 34 2d 34 75 62 75 6e 74 75 33 2e 31 31 0a 6c 69 62 70 61 6d 30 67 20 31 2e 33 2e 31 2d 35 75 62 75 6e 74 75 34 2e 31 0a 6c 69 62 70 61 6e 67 6f 2d 31 2e 30 2d 30 20 31 2e 34 34 2e 37 2d 32 75 62 75 6e 74 75 34 0a 6c 69 62 70 61 6e 67 6f 63 61 69 72 6f 2d 31 2e 30 2d 30 20 31 2e 34 34 2e 37 2d 32 75 62 75 6e 74 75 34 0a 6c 69 62 70 61 6e 67 6f 66 74 32 2d 31 2e 30 2d 30 20 31 2e 34 34 2e 37 2d 32 75 62 75 6e 74 75 34 0a 6c 69 62 70 61 6e 67 6f 78 66 74 2d 31 2e 30 2d 30 20 31 2e 34 34 2e 37 2d 32 75 62 75 6e 74 75 34 0a 6c 69 62 70 61 70 65 72 2d 75 74 69 6c 73 20 31 2e 31 2e 32 38 0a 6c
            Data Ascii: tu4.1libpam-runtime 1.3.1-5ubuntu4.1libpam-systemd 245.4-4ubuntu3.11libpam0g 1.3.1-5ubuntu4.1libpango-1.0-0 1.44.7-2ubuntu4libpangocairo-1.0-0 1.44.7-2ubuntu4libpangoft2-1.0-0 1.44.7-2ubuntu4libpangoxft-1.0-0 1.44.7-2ubuntu4libpaper-utils 1.1.28l
            2025-04-02 18:53:57 UTC16384OUTData Raw: 20 20 20 20 20 20 20 20 30 78 30 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 30 0a 67 73 20 20 20 20 20 20 20 20 20 20 20 20 20 30 78 30 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 30 0a 6b 30 20 20 20 20 20 20 20 20 20 20 20 20 20 30 78 30 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 30 0a 6b 31 20 20 20 20 20 20 20 20 20 20 20 20 20 30 78 30 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 30 0a 6b 32 20 20 20 20 20 20 20 20 20 20 20 20 20 30 78 30 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 30 0a 6b 33 20 20 20 20 20 20 20 20 20 20 20 20 20 30 78 30 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 30 0a 6b 34 20 20 20 20 20 20 20 20 20 20 20 20 20 30 78 30 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 30 0a 6b 35 20
            Data Ascii: 0x0 0gs 0x0 0k0 0x0 0k1 0x0 0k2 0x0 0k3 0x0 0k4 0x0 0k5
            2025-04-02 18:53:57 UTC16384OUTData Raw: 20 20 20 20 20 20 20 20 20 2f 75 73 72 2f 6c 69 62 2f 78 38 36 5f 36 34 2d 6c 69 6e 75 78 2d 67 6e 75 2f 6c 69 62 78 63 62 2d 72 65 6e 64 65 72 2e 73 6f 2e 30 2e 30 2e 30 0a 37 66 37 39 31 63 30 37 34 30 30 30 2d 37 66 37 39 31 63 30 37 35 30 30 30 20 2d 2d 2d 70 20 30 30 30 30 63 30 30 30 20 66 64 3a 30 30 20 38 30 36 32 36 30 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 2f 75 73 72 2f 6c 69 62 2f 78 38 36 5f 36 34 2d 6c 69 6e 75 78 2d 67 6e 75 2f 6c 69 62 78 63 62 2d 72 65 6e 64 65 72 2e 73 6f 2e 30 2e 30 2e 30 0a 37 66 37 39 31 63 30 37 35 30 30 30 2d 37 66 37 39 31 63 30 37 36 30 30 30 20 72 2d 2d 70 20 30 30 30 30 63 30 30 30 20 66 64 3a 30 30 20 38 30 36 32 36 30 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 2f 75
            Data Ascii: /usr/lib/x86_64-linux-gnu/libxcb-render.so.0.0.07f791c074000-7f791c075000 ---p 0000c000 fd:00 806260 /usr/lib/x86_64-linux-gnu/libxcb-render.so.0.0.07f791c075000-7f791c076000 r--p 0000c000 fd:00 806260 /u
            2025-04-02 18:53:57 UTC16384OUTData Raw: 6e 75 78 2d 67 6e 75 2f 6c 69 62 67 64 6b 5f 70 69 78 62 75 66 2d 32 2e 30 2e 73 6f 2e 30 2e 34 30 30 30 2e 30 0a 37 66 37 39 31 63 37 37 33 30 30 30 2d 37 66 37 39 31 63 37 37 34 30 30 30 20 72 77 2d 70 20 30 30 30 32 36 30 30 30 20 66 64 3a 30 30 20 38 30 36 32 34 35 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 2f 75 73 72 2f 6c 69 62 2f 78 38 36 5f 36 34 2d 6c 69 6e 75 78 2d 67 6e 75 2f 6c 69 62 67 64 6b 5f 70 69 78 62 75 66 2d 32 2e 30 2e 73 6f 2e 30 2e 34 30 30 30 2e 30 0a 37 66 37 39 31 63 37 37 34 30 30 30 2d 37 66 37 39 31 63 37 37 38 30 30 30 20 72 2d 2d 70 20 30 30 30 30 30 30 30 30 20 66 64 3a 30 30 20 38 30 36 32 36 38 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 2f 75 73 72 2f 6c 69 62 2f 78 38 36 5f 36 34
            Data Ascii: nux-gnu/libgdk_pixbuf-2.0.so.0.4000.07f791c773000-7f791c774000 rw-p 00026000 fd:00 806245 /usr/lib/x86_64-linux-gnu/libgdk_pixbuf-2.0.so.0.4000.07f791c774000-7f791c778000 r--p 00000000 fd:00 806268 /usr/lib/x86_64
            2025-04-02 18:53:57 UTC16384OUTData Raw: 20 70 6c 61 74 66 6f 72 6d 20 65 69 73 61 2e 30 3a 20 43 61 6e 6e 6f 74 20 61 6c 6c 6f 63 61 74 65 20 72 65 73 6f 75 72 63 65 20 66 6f 72 20 45 49 53 41 20 73 6c 6f 74 20 37 0a 41 75 67 20 31 37 20 32 30 3a 32 34 3a 34 36 20 67 61 6c 61 73 73 69 61 20 6b 65 72 6e 65 6c 3a 20 70 6c 61 74 66 6f 72 6d 20 65 69 73 61 2e 30 3a 20 43 61 6e 6e 6f 74 20 61 6c 6c 6f 63 61 74 65 20 72 65 73 6f 75 72 63 65 20 66 6f 72 20 45 49 53 41 20 73 6c 6f 74 20 38 0a 41 75 67 20 31 37 20 32 30 3a 32 34 3a 34 36 20 67 61 6c 61 73 73 69 61 20 6b 65 72 6e 65 6c 3a 20 73 64 20 33 32 3a 30 3a 30 3a 30 3a 20 5b 73 64 61 5d 20 41 73 73 75 6d 69 6e 67 20 64 72 69 76 65 20 63 61 63 68 65 3a 20 77 72 69 74 65 20 74 68 72 6f 75 67 68 0a 41 75 67 20 31 37 20 32 30 3a 32 34 3a 34 37 20 67
            Data Ascii: platform eisa.0: Cannot allocate resource for EISA slot 7Aug 17 20:24:46 galassia kernel: platform eisa.0: Cannot allocate resource for EISA slot 8Aug 17 20:24:46 galassia kernel: sd 32:0:0:0: [sda] Assuming drive cache: write throughAug 17 20:24:47 g
            2025-04-02 18:53:57 UTC16384OUTData Raw: 35 35 31 5d 3a 20 28 49 49 29 20 4c 6f 61 64 4d 6f 64 75 6c 65 3a 20 22 66 62 64 65 76 68 77 22 0a 41 75 67 20 31 37 20 32 30 3a 32 35 3a 30 34 20 67 61 6c 61 73 73 69 61 20 2f 75 73 72 2f 6c 69 62 2f 67 64 6d 33 2f 67 64 6d 2d 78 2d 73 65 73 73 69 6f 6e 5b 31 35 35 31 5d 3a 20 28 49 49 29 20 4c 6f 61 64 69 6e 67 20 2f 75 73 72 2f 6c 69 62 2f 78 6f 72 67 2f 6d 6f 64 75 6c 65 73 2f 6c 69 62 66 62 64 65 76 68 77 2e 73 6f 0a 41 75 67 20 31 37 20 32 30 3a 32 35 3a 30 34 20 67 61 6c 61 73 73 69 61 20 2f 75 73 72 2f 6c 69 62 2f 67 64 6d 33 2f 67 64 6d 2d 78 2d 73 65 73 73 69 6f 6e 5b 31 35 35 31 5d 3a 20 28 49 49 29 20 4d 6f 64 75 6c 65 20 66 62 64 65 76 68 77 3a 20 76 65 6e 64 6f 72 3d 22 58 2e 4f 72 67 20 46 6f 75 6e 64 61 74 69 6f 6e 22 0a 41 75 67 20 31 37
            Data Ascii: 551]: (II) LoadModule: "fbdevhw"Aug 17 20:25:04 galassia /usr/lib/gdm3/gdm-x-session[1551]: (II) Loading /usr/lib/xorg/modules/libfbdevhw.soAug 17 20:25:04 galassia /usr/lib/gdm3/gdm-x-session[1551]: (II) Module fbdevhw: vendor="X.Org Foundation"Aug 17
            2025-04-02 18:53:57 UTC16384OUTData Raw: 2f 6c 69 62 2f 67 64 6d 33 2f 67 64 6d 2d 78 2d 73 65 73 73 69 6f 6e 5b 31 35 35 31 5d 3a 20 28 49 49 29 20 76 6d 77 61 72 65 28 30 29 3a 20 4e 6f 74 20 75 73 69 6e 67 20 64 65 66 61 75 6c 74 20 6d 6f 64 65 20 22 31 39 32 30 78 31 32 30 30 22 20 28 69 6e 73 75 66 66 69 63 69 65 6e 74 20 6d 65 6d 6f 72 79 20 66 6f 72 20 6d 6f 64 65 29 0a 41 75 67 20 31 37 20 32 30 3a 32 35 3a 30 35 20 67 61 6c 61 73 73 69 61 20 2f 75 73 72 2f 6c 69 62 2f 67 64 6d 33 2f 67 64 6d 2d 78 2d 73 65 73 73 69 6f 6e 5b 31 35 35 31 5d 3a 20 28 49 49 29 20 76 6d 77 61 72 65 28 30 29 3a 20 4e 6f 74 20 75 73 69 6e 67 20 64 65 66 61 75 6c 74 20 6d 6f 64 65 20 22 39 36 30 78 36 30 30 22 20 28 62 61 64 20 6d 6f 64 65 20 63 6c 6f 63 6b 2f 69 6e 74 65 72 6c 61 63 65 2f 64 6f 75 62 6c 65 73
            Data Ascii: /lib/gdm3/gdm-x-session[1551]: (II) vmware(0): Not using default mode "1920x1200" (insufficient memory for mode)Aug 17 20:25:05 galassia /usr/lib/gdm3/gdm-x-session[1551]: (II) vmware(0): Not using default mode "960x600" (bad mode clock/interlace/doubles
            2025-04-02 18:53:57 UTC16384OUTData Raw: 20 31 33 33 36 20 31 35 32 30 20 20 38 36 34 20 38 36 35 20 38 36 38 20 38 39 35 20 2d 68 73 79 6e 63 20 2b 76 73 79 6e 63 20 28 35 33 2e 37 20 6b 48 7a 20 64 29 0a 41 75 67 20 31 37 20 32 30 3a 32 35 3a 30 35 20 67 61 6c 61 73 73 69 61 20 2f 75 73 72 2f 6c 69 62 2f 67 64 6d 33 2f 67 64 6d 2d 78 2d 73 65 73 73 69 6f 6e 5b 31 35 35 31 5d 3a 20 28 2a 2a 29 20 76 6d 77 61 72 65 28 30 29 3a 20 20 44 65 66 61 75 6c 74 20 6d 6f 64 65 20 22 31 30 32 34 78 37 36 38 22 3a 20 39 34 2e 35 20 4d 48 7a 2c 20 36 38 2e 37 20 6b 48 7a 2c 20 38 35 2e 30 20 48 7a 0a 41 75 67 20 31 37 20 32 30 3a 32 35 3a 30 35 20 67 61 6c 61 73 73 69 61 20 2f 75 73 72 2f 6c 69 62 2f 67 64 6d 33 2f 67 64 6d 2d 78 2d 73 65 73 73 69 6f 6e 5b 31 35 35 31 5d 3a 20 28 49 49 29 20 76 6d 77 61 72
            Data Ascii: 1336 1520 864 865 868 895 -hsync +vsync (53.7 kHz d)Aug 17 20:25:05 galassia /usr/lib/gdm3/gdm-x-session[1551]: (**) vmware(0): Default mode "1024x768": 94.5 MHz, 68.7 kHz, 85.0 HzAug 17 20:25:05 galassia /usr/lib/gdm3/gdm-x-session[1551]: (II) vmwar
            2025-04-02 18:53:57 UTC16384OUTData Raw: 65 64 20 53 65 74 20 32 20 6b 65 79 62 6f 61 72 64 3a 20 61 6c 77 61 79 73 20 72 65 70 6f 72 74 73 20 63 6f 72 65 20 65 76 65 6e 74 73 0a 41 75 67 20 31 37 20 32 30 3a 32 35 3a 30 35 20 67 61 6c 61 73 73 69 61 20 2f 75 73 72 2f 6c 69 62 2f 67 64 6d 33 2f 67 64 6d 2d 78 2d 73 65 73 73 69 6f 6e 5b 31 35 35 31 5d 3a 20 28 2a 2a 29 20 4f 70 74 69 6f 6e 20 22 44 65 76 69 63 65 22 20 22 2f 64 65 76 2f 69 6e 70 75 74 2f 65 76 65 6e 74 31 22 0a 41 75 67 20 31 37 20 32 30 3a 32 35 3a 30 35 20 67 61 6c 61 73 73 69 61 20 2f 75 73 72 2f 6c 69 62 2f 67 64 6d 33 2f 67 64 6d 2d 78 2d 73 65 73 73 69 6f 6e 5b 31 35 35 31 5d 3a 20 28 2a 2a 29 20 4f 70 74 69 6f 6e 20 22 5f 73 6f 75 72 63 65 22 20 22 73 65 72 76 65 72 2f 75 64 65 76 22 0a 41 75 67 20 31 37 20 32 30 3a 32 35
            Data Ascii: ed Set 2 keyboard: always reports core eventsAug 17 20:25:05 galassia /usr/lib/gdm3/gdm-x-session[1551]: (**) Option "Device" "/dev/input/event1"Aug 17 20:25:05 galassia /usr/lib/gdm3/gdm-x-session[1551]: (**) Option "_source" "server/udev"Aug 17 20:25
            2025-04-02 18:53:57 UTC279INHTTP/1.1 400 Bad Request
            Date: Wed, 02 Apr 2025 18:53:57 GMT
            Server: gunicorn/19.7.1
            X-Daisy-Revision-Number: 979
            X-Oops-Repository-Version: 0.0.0
            Strict-Transport-Security: max-age=2592000
            Connection: close
            Transfer-Encoding: chunked
            17
            Crash already reported.
            0


            System Behavior

            Start time (UTC):18:53:27
            Start date (UTC):02/04/2025
            Path:/tmp/xd.x86.elf
            Arguments:/tmp/xd.x86.elf
            File size:37268 bytes
            MD5 hash:a68aa2179d0db1bb9cf010a4949ea024

            Start time (UTC):18:53:27
            Start date (UTC):02/04/2025
            Path:/tmp/xd.x86.elf
            Arguments:-
            File size:37268 bytes
            MD5 hash:a68aa2179d0db1bb9cf010a4949ea024

            Start time (UTC):18:53:28
            Start date (UTC):02/04/2025
            Path:/tmp/xd.x86.elf
            Arguments:-
            File size:37268 bytes
            MD5 hash:a68aa2179d0db1bb9cf010a4949ea024

            Start time (UTC):18:53:28
            Start date (UTC):02/04/2025
            Path:/tmp/xd.x86.elf
            Arguments:-
            File size:37268 bytes
            MD5 hash:a68aa2179d0db1bb9cf010a4949ea024

            Start time (UTC):18:53:28
            Start date (UTC):02/04/2025
            Path:/tmp/xd.x86.elf
            Arguments:-
            File size:37268 bytes
            MD5 hash:a68aa2179d0db1bb9cf010a4949ea024

            Start time (UTC):18:53:29
            Start date (UTC):02/04/2025
            Path:/tmp/xd.x86.elf
            Arguments:-
            File size:37268 bytes
            MD5 hash:a68aa2179d0db1bb9cf010a4949ea024

            Start time (UTC):18:53:29
            Start date (UTC):02/04/2025
            Path:/tmp/xd.x86.elf
            Arguments:-
            File size:37268 bytes
            MD5 hash:a68aa2179d0db1bb9cf010a4949ea024
            Start time (UTC):18:53:29
            Start date (UTC):02/04/2025
            Path:/tmp/xd.x86.elf
            Arguments:-
            File size:37268 bytes
            MD5 hash:a68aa2179d0db1bb9cf010a4949ea024
            Start time (UTC):18:53:40
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:53:40
            Start date (UTC):02/04/2025
            Path:/usr/bin/journalctl
            Arguments:/usr/bin/journalctl --smart-relinquish-var
            File size:80120 bytes
            MD5 hash:bf3a987344f3bacafc44efd882abda8b

            Start time (UTC):18:53:40
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:53:40
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:53:40
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:53:40
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:53:40
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:53:52
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:53:52
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:53:52
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:53:52
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:53:52
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:53:52
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:53:52
            Start date (UTC):02/04/2025
            Path:/usr/sbin/gdm3
            Arguments:-
            File size:453296 bytes
            MD5 hash:2492e2d8d34f9377e3e530a61a15674f

            Start time (UTC):18:53:52
            Start date (UTC):02/04/2025
            Path:/etc/gdm3/PrimeOff/Default
            Arguments:/etc/gdm3/PrimeOff/Default
            File size:129816 bytes
            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

            Start time (UTC):18:53:52
            Start date (UTC):02/04/2025
            Path:/usr/sbin/gdm3
            Arguments:-
            File size:453296 bytes
            MD5 hash:2492e2d8d34f9377e3e530a61a15674f

            Start time (UTC):18:53:52
            Start date (UTC):02/04/2025
            Path:/etc/gdm3/PrimeOff/Default
            Arguments:/etc/gdm3/PrimeOff/Default
            File size:129816 bytes
            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

            Start time (UTC):18:53:52
            Start date (UTC):02/04/2025
            Path:/usr/sbin/gdm3
            Arguments:-
            File size:453296 bytes
            MD5 hash:2492e2d8d34f9377e3e530a61a15674f

            Start time (UTC):18:53:52
            Start date (UTC):02/04/2025
            Path:/etc/gdm3/PrimeOff/Default
            Arguments:/etc/gdm3/PrimeOff/Default
            File size:129816 bytes
            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

            Start time (UTC):18:53:52
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:53:52
            Start date (UTC):02/04/2025
            Path:/usr/bin/pulseaudio
            Arguments:/usr/bin/pulseaudio --daemonize=no --log-target=journal
            File size:100832 bytes
            MD5 hash:0c3b4c789d8ffb12b25507f27e14c186

            Start time (UTC):18:53:52
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:53:53
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:53:53
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:53:53
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:53:54
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:53:54
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:/usr/bin/gpu-manager --log /var/log/gpu-manager.log
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:53:54
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:53:54
            Start date (UTC):02/04/2025
            Path:/bin/sh
            Arguments:sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
            File size:129816 bytes
            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

            Start time (UTC):18:53:54
            Start date (UTC):02/04/2025
            Path:/bin/sh
            Arguments:-
            File size:129816 bytes
            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

            Start time (UTC):18:53:54
            Start date (UTC):02/04/2025
            Path:/usr/bin/grep
            Arguments:grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
            File size:199136 bytes
            MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

            Start time (UTC):18:53:54
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:53:54
            Start date (UTC):02/04/2025
            Path:/bin/sh
            Arguments:sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
            File size:129816 bytes
            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

            Start time (UTC):18:53:54
            Start date (UTC):02/04/2025
            Path:/bin/sh
            Arguments:-
            File size:129816 bytes
            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

            Start time (UTC):18:53:54
            Start date (UTC):02/04/2025
            Path:/usr/bin/grep
            Arguments:grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
            File size:199136 bytes
            MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

            Start time (UTC):18:53:54
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:53:54
            Start date (UTC):02/04/2025
            Path:/bin/sh
            Arguments:sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
            File size:129816 bytes
            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

            Start time (UTC):18:53:54
            Start date (UTC):02/04/2025
            Path:/bin/sh
            Arguments:-
            File size:129816 bytes
            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

            Start time (UTC):18:53:54
            Start date (UTC):02/04/2025
            Path:/usr/bin/grep
            Arguments:grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
            File size:199136 bytes
            MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

            Start time (UTC):18:53:55
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:53:55
            Start date (UTC):02/04/2025
            Path:/bin/sh
            Arguments:sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
            File size:129816 bytes
            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

            Start time (UTC):18:53:55
            Start date (UTC):02/04/2025
            Path:/bin/sh
            Arguments:-
            File size:129816 bytes
            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

            Start time (UTC):18:53:55
            Start date (UTC):02/04/2025
            Path:/usr/bin/grep
            Arguments:grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
            File size:199136 bytes
            MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

            Start time (UTC):18:53:55
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:53:55
            Start date (UTC):02/04/2025
            Path:/bin/sh
            Arguments:sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
            File size:129816 bytes
            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

            Start time (UTC):18:53:55
            Start date (UTC):02/04/2025
            Path:/bin/sh
            Arguments:-
            File size:129816 bytes
            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

            Start time (UTC):18:53:55
            Start date (UTC):02/04/2025
            Path:/usr/bin/grep
            Arguments:grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
            File size:199136 bytes
            MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

            Start time (UTC):18:53:55
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:53:55
            Start date (UTC):02/04/2025
            Path:/bin/sh
            Arguments:sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf"
            File size:129816 bytes
            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

            Start time (UTC):18:53:55
            Start date (UTC):02/04/2025
            Path:/bin/sh
            Arguments:-
            File size:129816 bytes
            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

            Start time (UTC):18:53:55
            Start date (UTC):02/04/2025
            Path:/usr/bin/grep
            Arguments:grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
            File size:199136 bytes
            MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

            Start time (UTC):18:53:55
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:53:55
            Start date (UTC):02/04/2025
            Path:/bin/sh
            Arguments:sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /etc/modprobe.d/*.conf"
            File size:129816 bytes
            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

            Start time (UTC):18:53:55
            Start date (UTC):02/04/2025
            Path:/bin/sh
            Arguments:-
            File size:129816 bytes
            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

            Start time (UTC):18:53:55
            Start date (UTC):02/04/2025
            Path:/usr/bin/grep
            Arguments:grep -G ^blacklist.*nouveau[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
            File size:199136 bytes
            MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

            Start time (UTC):18:53:55
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:53:55
            Start date (UTC):02/04/2025
            Path:/bin/sh
            Arguments:sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /lib/modprobe.d/*.conf"
            File size:129816 bytes
            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

            Start time (UTC):18:53:56
            Start date (UTC):02/04/2025
            Path:/bin/sh
            Arguments:-
            File size:129816 bytes
            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

            Start time (UTC):18:53:56
            Start date (UTC):02/04/2025
            Path:/usr/bin/grep
            Arguments:grep -G ^blacklist.*nouveau[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
            File size:199136 bytes
            MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

            Start time (UTC):18:53:56
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:53:56
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:53:56
            Start date (UTC):02/04/2025
            Path:/usr/share/gdm/generate-config
            Arguments:/usr/share/gdm/generate-config
            File size:129816 bytes
            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

            Start time (UTC):18:53:56
            Start date (UTC):02/04/2025
            Path:/usr/share/gdm/generate-config
            Arguments:-
            File size:129816 bytes
            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

            Start time (UTC):18:53:56
            Start date (UTC):02/04/2025
            Path:/usr/bin/pkill
            Arguments:pkill --signal HUP --uid gdm dconf-service
            File size:30968 bytes
            MD5 hash:fa96a75a08109d8842e4865b2907d51f

            Start time (UTC):18:53:58
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:53:58
            Start date (UTC):02/04/2025
            Path:/usr/lib/gdm3/gdm-wait-for-drm
            Arguments:/usr/lib/gdm3/gdm-wait-for-drm
            File size:14640 bytes
            MD5 hash:82043ba752c6930b4e6aaea2f7747545

            Start time (UTC):18:54:08
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd (deleted)
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:54:08
            Start date (UTC):02/04/2025
            Path:/usr/sbin/gdm3
            Arguments:/usr/sbin/gdm3
            File size:453296 bytes
            MD5 hash:2492e2d8d34f9377e3e530a61a15674f

            Start time (UTC):18:54:09
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd (deleted)
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:54:09
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd (deleted)
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:54:09
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd (deleted)
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:54:09
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd (deleted)
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:54:09
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd (deleted)
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:54:23
            Start date (UTC):02/04/2025
            Path:/usr/libexec/gvfsd-fuse
            Arguments:-
            File size:47632 bytes
            MD5 hash:d18fbf1cbf8eb57b17fac48b7b4be933

            Start time (UTC):18:54:23
            Start date (UTC):02/04/2025
            Path:/bin/fusermount
            Arguments:fusermount -u -q -z -- /run/user/1000/gvfs
            File size:39144 bytes
            MD5 hash:576a1b135c82bdcbc97a91acea900566

            Start time (UTC):18:54:55
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd (deleted)
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:54:56
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd (deleted)
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:54:56
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd (deleted)
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:54:56
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd (deleted)
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:54:56
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd (deleted)
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:54:56
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:/usr/bin/gpu-manager --log /var/log/gpu-manager.log
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:54:56
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:54:56
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:54:56
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:54:56
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:54:56
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:54:56
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:54:57
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:54:57
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:54:56
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd (deleted)
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:54:57
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd (deleted)
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:54:59
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd (deleted)
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:54:59
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:/usr/bin/gpu-manager --log /var/log/gpu-manager.log
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:54:59
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:54:59
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:54:59
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:54:59
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:54:59
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:54:59
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:54:59
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:54:59
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:54:59
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd (deleted)
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:55:00
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd (deleted)
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:55:00
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:/usr/bin/gpu-manager --log /var/log/gpu-manager.log
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:55:00
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:55:00
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:55:00
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:55:00
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:55:00
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:55:00
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:55:00
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:55:00
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:55:01
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd (deleted)
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:55:02
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd (deleted)
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:55:02
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:/usr/bin/gpu-manager --log /var/log/gpu-manager.log
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:55:02
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:55:02
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:55:02
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:55:02
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:55:02
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:55:02
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:55:02
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:55:02
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:55:03
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd (deleted)
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:55:04
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd (deleted)
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:55:04
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:/usr/bin/gpu-manager --log /var/log/gpu-manager.log
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:55:04
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:55:04
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:55:04
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:55:04
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:55:04
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:55:04
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:55:04
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:55:04
            Start date (UTC):02/04/2025
            Path:/usr/bin/gpu-manager
            Arguments:-
            File size:76616 bytes
            MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

            Start time (UTC):18:55:05
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd (deleted)
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:55:06
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd (deleted)
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):18:55:06
            Start date (UTC):02/04/2025
            Path:/bin/plymouth
            Arguments:/bin/plymouth quit
            File size:51352 bytes
            MD5 hash:87003efd8dad470042f5e75360a8f49f

            Start time (UTC):18:55:53
            Start date (UTC):02/04/2025
            Path:/usr/lib/systemd/systemd (deleted)
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75