Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
na.elf

Overview

General Information

Sample name:na.elf
Analysis ID:1527234
MD5:1b0e1d2bf03f0593cbb08b390c80e809
SHA1:ad168a1383186aef1e21615d81d1b40b628b1b64
SHA256:ca0952bad4ffd4d54211f312c879c063ce0be249a0926d865db38305aeabfe96
Tags:elfMiraiuser-abuse_ch
Infos:

Detection

Mirai
Score:80
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Machine Learning detection for sample
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample tries to kill a process (SIGKILL)
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1527234
Start date and time:2024-10-06 22:08:58 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 13s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:na.elf
Detection:MAL
Classification:mal80.troj.evad.linELF@0/0@39/0
  • VT rate limit hit for: na.elf
Command:/tmp/na.elf
PID:5465
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • na.elf (PID: 5465, Parent: 5388, MD5: 1b0e1d2bf03f0593cbb08b390c80e809) Arguments: /tmp/na.elf
    • na.elf New Fork (PID: 5466, Parent: 5465)
      • na.elf New Fork (PID: 5467, Parent: 5466)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
na.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    na.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
    • 0x16360:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x16374:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x16388:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1639c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x163b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x163c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x163d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x163ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x16400:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x16414:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x16428:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1643c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x16450:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x16464:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x16478:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1648c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x164a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x164b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x164c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x164dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x164f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    na.elfLinux_Trojan_Gafgyt_9e9530a7unknownunknown
    • 0xcd28:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
    na.elfLinux_Trojan_Gafgyt_807911a2unknownunknown
    • 0xd61f:$a: FE 48 39 F3 0F 94 C2 48 83 F9 FF 0F 94 C0 84 D0 74 16 4B 8D
    na.elfLinux_Trojan_Gafgyt_d4227dbfunknownunknown
    • 0x9f96:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
    • 0xf564:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
    Click to see the 9 entries
    SourceRuleDescriptionAuthorStrings
    5465.1.0000000000400000.0000000000419000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      5465.1.0000000000400000.0000000000419000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x16360:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x16374:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x16388:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1639c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x163b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x163c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x163d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x163ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x16400:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x16414:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x16428:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1643c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x16450:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x16464:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x16478:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1648c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x164a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x164b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x164c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x164dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x164f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      5465.1.0000000000400000.0000000000419000.r-x.sdmpLinux_Trojan_Gafgyt_9e9530a7unknownunknown
      • 0xcd28:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
      5465.1.0000000000400000.0000000000419000.r-x.sdmpLinux_Trojan_Gafgyt_807911a2unknownunknown
      • 0xd61f:$a: FE 48 39 F3 0F 94 C2 48 83 F9 FF 0F 94 C0 84 D0 74 16 4B 8D
      5465.1.0000000000400000.0000000000419000.r-x.sdmpLinux_Trojan_Gafgyt_d4227dbfunknownunknown
      • 0x9f96:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
      • 0xf564:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
      Click to see the 11 entries
      No Suricata rule has matched

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: na.elfAvira: detected
      Source: na.elfReversingLabs: Detection: 57%
      Source: na.elfJoe Sandbox ML: detected
      Source: global trafficTCP traffic: 192.168.2.13:49406 -> 5.59.249.232:1995
      Source: global trafficTCP traffic: 192.168.2.13:48202 -> 185.125.190.26:443
      Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
      Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
      Source: global trafficDNS traffic detected: DNS query: net.igxhost.ru
      Source: unknownNetwork traffic detected: HTTP traffic on port 48202 -> 443

      System Summary

      barindex
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d0c57a2e Author: unknown
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_1e0c5ce0 Author: unknown
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_6a77af0f Author: unknown
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
      Source: 5465.1.0000000000400000.0000000000419000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: 5465.1.0000000000400000.0000000000419000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
      Source: 5465.1.0000000000400000.0000000000419000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
      Source: 5465.1.0000000000400000.0000000000419000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
      Source: 5465.1.0000000000400000.0000000000419000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
      Source: 5465.1.0000000000400000.0000000000419000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d0c57a2e Author: unknown
      Source: 5465.1.0000000000400000.0000000000419000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
      Source: 5465.1.0000000000400000.0000000000419000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown
      Source: 5465.1.0000000000400000.0000000000419000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
      Source: 5465.1.0000000000400000.0000000000419000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown
      Source: 5465.1.0000000000400000.0000000000419000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_1e0c5ce0 Author: unknown
      Source: 5465.1.0000000000400000.0000000000419000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f Author: unknown
      Source: 5465.1.0000000000400000.0000000000419000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
      Source: Process Memory Space: na.elf PID: 5465, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: Initial sampleString containing 'busybox' found: /bin/busybox
      Source: Initial sampleString containing 'busybox' found: /x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/x38/xFJ/x93/xID/x9A/pro
      Source: ELF static info symbol of initial sample.symtab present: no
      Source: /tmp/na.elf (PID: 5467)SIGKILL sent: pid: 2, result: successfulJump to behavior
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d0c57a2e os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ee7d3a33575ed3aa7431489a8fb18bf30cfd5d6c776066ab2a27f93303124b6, id = d0c57a2e-c10c-436c-be13-50a269326cf2, last_modified = 2021-09-16
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_1e0c5ce0 reference_sample = 5b1f95840caebf9721bf318126be27085ec08cf7881ec64a884211a934351c2d, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 8e45538b59f9c9b8bc49661069044900c8199e487714c715c1b1f970fd528e3b, id = 1e0c5ce0-3b76-4da4-8bed-2e5036b6ce79, last_modified = 2021-09-16
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_6a77af0f os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 4e436f509e7e732e3d0326bcbdde555bba0653213ddf31b43cfdfbe16abb0016, id = 6a77af0f-31fa-4793-82aa-10b065ba1ec0, last_modified = 2021-09-16
      Source: na.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
      Source: 5465.1.0000000000400000.0000000000419000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: 5465.1.0000000000400000.0000000000419000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
      Source: 5465.1.0000000000400000.0000000000419000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
      Source: 5465.1.0000000000400000.0000000000419000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
      Source: 5465.1.0000000000400000.0000000000419000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
      Source: 5465.1.0000000000400000.0000000000419000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d0c57a2e os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ee7d3a33575ed3aa7431489a8fb18bf30cfd5d6c776066ab2a27f93303124b6, id = d0c57a2e-c10c-436c-be13-50a269326cf2, last_modified = 2021-09-16
      Source: 5465.1.0000000000400000.0000000000419000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
      Source: 5465.1.0000000000400000.0000000000419000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16
      Source: 5465.1.0000000000400000.0000000000419000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
      Source: 5465.1.0000000000400000.0000000000419000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16
      Source: 5465.1.0000000000400000.0000000000419000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_1e0c5ce0 reference_sample = 5b1f95840caebf9721bf318126be27085ec08cf7881ec64a884211a934351c2d, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 8e45538b59f9c9b8bc49661069044900c8199e487714c715c1b1f970fd528e3b, id = 1e0c5ce0-3b76-4da4-8bed-2e5036b6ce79, last_modified = 2021-09-16
      Source: 5465.1.0000000000400000.0000000000419000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 4e436f509e7e732e3d0326bcbdde555bba0653213ddf31b43cfdfbe16abb0016, id = 6a77af0f-31fa-4793-82aa-10b065ba1ec0, last_modified = 2021-09-16
      Source: 5465.1.0000000000400000.0000000000419000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
      Source: Process Memory Space: na.elf PID: 5465, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: classification engineClassification label: mal80.troj.evad.linELF@0/0@39/0

      Hooking and other Techniques for Hiding and Protection

      barindex
      Source: /tmp/na.elf (PID: 5465)File: /tmp/na.elfJump to behavior

      Stealing of Sensitive Information

      barindex
      Source: Yara matchFile source: na.elf, type: SAMPLE
      Source: Yara matchFile source: 5465.1.0000000000400000.0000000000419000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: na.elf PID: 5465, type: MEMORYSTR

      Remote Access Functionality

      barindex
      Source: Yara matchFile source: na.elf, type: SAMPLE
      Source: Yara matchFile source: 5465.1.0000000000400000.0000000000419000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: na.elf PID: 5465, type: MEMORYSTR
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
      File Deletion
      OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
      Encrypted Channel
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
      Non-Standard Port
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
      Non-Application Layer Protocol
      Automated ExfiltrationData Encrypted for Impact
      Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
      Application Layer Protocol
      Traffic DuplicationData Destruction
      No configs have been found
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Number of created Files
      • Is malicious
      • Internet
      SourceDetectionScannerLabelLink
      na.elf58%ReversingLabsLinux.Backdoor.Mirai
      na.elf100%AviraEXP/ELF.Mirai.Z.A
      na.elf100%Joe Sandbox ML
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      NameIPActiveMaliciousAntivirus DetectionReputation
      net.igxhost.ru
      5.59.249.232
      truefalse
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        185.125.190.26
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        5.59.249.232
        net.igxhost.ruCzech Republic
        50923METRO-SET-ASMetrosetAutonomousSystemRUfalse
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        185.125.190.26na.elfGet hashmaliciousMiraiBrowse
          na.elfGet hashmaliciousUnknownBrowse
            na.elfGet hashmaliciousMirai, MoobotBrowse
              na.elfGet hashmaliciousUnknownBrowse
                na.elfGet hashmaliciousUnknownBrowse
                  na.elfGet hashmaliciousMirai, MoobotBrowse
                    na.elfGet hashmaliciousUnknownBrowse
                      arm7.elfGet hashmaliciousMiraiBrowse
                        cayo.arm7.elfGet hashmaliciousGafgyt, MiraiBrowse
                          SecuriteInfo.com.Linux.Siggen.9999.5706.5318.elfGet hashmaliciousMiraiBrowse
                            No context
                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                            CANONICAL-ASGBna.elfGet hashmaliciousMiraiBrowse
                            • 91.189.91.42
                            na.elfGet hashmaliciousMiraiBrowse
                            • 91.189.91.42
                            na.elfGet hashmaliciousMiraiBrowse
                            • 185.125.190.26
                            na.elfGet hashmaliciousUnknownBrowse
                            • 91.189.91.42
                            na.elfGet hashmaliciousUnknownBrowse
                            • 185.125.190.26
                            na.elfGet hashmaliciousMirai, MoobotBrowse
                            • 91.189.91.42
                            na.elfGet hashmaliciousUnknownBrowse
                            • 91.189.91.42
                            na.elfGet hashmaliciousMirai, MoobotBrowse
                            • 91.189.91.42
                            na.elfGet hashmaliciousUnknownBrowse
                            • 91.189.91.42
                            na.elfGet hashmaliciousMirai, MoobotBrowse
                            • 91.189.91.42
                            METRO-SET-ASMetrosetAutonomousSystemRUc.mips.elfGet hashmaliciousUnknownBrowse
                            • 5.59.248.92
                            hidakibest.arm4.elfGet hashmaliciousGafgyt, MiraiBrowse
                            • 5.59.248.206
                            hidakibest.arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                            • 5.59.248.206
                            hidakibest.arm6.elfGet hashmaliciousGafgyt, MiraiBrowse
                            • 5.59.248.206
                            hidakibest.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                            • 5.59.248.206
                            hidakibest.mpsl.elfGet hashmaliciousGafgyt, MiraiBrowse
                            • 5.59.248.206
                            hidakibest.ppc.elfGet hashmaliciousGafgyt, MiraiBrowse
                            • 5.59.248.206
                            hidakibest.sparc.elfGet hashmaliciousGafgyt, MiraiBrowse
                            • 5.59.248.206
                            hidakibest.x86.elfGet hashmaliciousMirai, GafgytBrowse
                            • 5.59.248.206
                            aHvzby2qN7.elfGet hashmaliciousMiraiBrowse
                            • 5.59.248.52
                            No context
                            No context
                            No created / dropped files found
                            File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped
                            Entropy (8bit):5.202440339486156
                            TrID:
                            • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                            File name:na.elf
                            File size:138'552 bytes
                            MD5:1b0e1d2bf03f0593cbb08b390c80e809
                            SHA1:ad168a1383186aef1e21615d81d1b40b628b1b64
                            SHA256:ca0952bad4ffd4d54211f312c879c063ce0be249a0926d865db38305aeabfe96
                            SHA512:2f30340abb7d3fee7d38698e46edabf978972239bd95e92116d014d06feea89c8e151b48fa1860864779f26eb46080722d6bd4d4f1693e9cd861a5d92fc5b722
                            SSDEEP:3072:gfJBhdnBRTHcLCzsyvSVv2mW+BsgQyeWvtdHkWm6:gfJBhdnnTHcLT9GWJm
                            TLSH:5DD34A1BB5C180FDC4DAC1B84BDAF53ADD32B1AD1238B15B27D4AA222E4DE315F1DA50
                            File Content Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@...............................................Q.......Q.............................Q.td....................................................H...._....*]..H........

                            ELF header

                            Class:ELF64
                            Data:2's complement, little endian
                            Version:1 (current)
                            Machine:Advanced Micro Devices X86-64
                            Version Number:0x1
                            Type:EXEC (Executable file)
                            OS/ABI:UNIX - System V
                            ABI Version:0
                            Entry Point Address:0x400194
                            Flags:0x0
                            ELF Header Size:64
                            Program Header Offset:64
                            Program Header Size:56
                            Number of Program Headers:3
                            Section Header Offset:137912
                            Section Header Size:64
                            Number of Section Headers:10
                            Header String Table Index:9
                            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                            NULL0x00x00x00x00x0000
                            .initPROGBITS0x4000e80xe80x130x00x6AX001
                            .textPROGBITS0x4001000x1000x15d560x00x6AX0016
                            .finiPROGBITS0x415e560x15e560xe0x00x6AX001
                            .rodataPROGBITS0x415e800x15e800x2d400x00x2A0032
                            .ctorsPROGBITS0x518bc80x18bc80x180x00x3WA008
                            .dtorsPROGBITS0x518be00x18be00x100x00x3WA008
                            .dataPROGBITS0x518c000x18c000x8e780x00x3WA0032
                            .bssNOBITS0x521a800x21a780x82000x00x3WA0032
                            .shstrtabSTRTAB0x00x21a780x3e0x00x0001
                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                            LOAD0x00x4000000x4000000x18bc00x18bc06.38220x5R E0x100000.init .text .fini .rodata
                            LOAD0x18bc80x518bc80x518bc80x8eb00x110b80.23350x6RW 0x100000.ctors .dtors .data .bss
                            GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
                            TimestampSource PortDest PortSource IPDest IP
                            Oct 6, 2024 22:09:38.371193886 CEST494061995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:38.376074076 CEST1995494065.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:38.376132011 CEST494061995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:38.377057076 CEST494061995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:38.381856918 CEST1995494065.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:38.381900072 CEST494061995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:38.386713028 CEST1995494065.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:40.141983032 CEST1995494065.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:40.142086983 CEST494061995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:40.147301912 CEST1995494065.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:41.187748909 CEST494081995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:41.192624092 CEST1995494085.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:41.192677021 CEST494081995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:41.194463015 CEST494081995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:41.199357986 CEST1995494085.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:41.199400902 CEST494081995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:41.204379082 CEST1995494085.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:42.955596924 CEST1995494085.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:42.955926895 CEST494081995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:42.961519957 CEST1995494085.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:43.965662956 CEST494101995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:43.970586061 CEST1995494105.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:43.970686913 CEST494101995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:43.972197056 CEST494101995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:43.977102995 CEST1995494105.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:43.977169991 CEST494101995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:43.981961012 CEST1995494105.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:45.784327984 CEST1995494105.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:45.784626961 CEST494101995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:45.789731026 CEST1995494105.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:46.797396898 CEST494121995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:46.802551031 CEST1995494125.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:46.802606106 CEST494121995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:46.803248882 CEST494121995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:46.807985067 CEST1995494125.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:46.808029890 CEST494121995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:46.812877893 CEST1995494125.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:48.485088110 CEST1995494125.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:48.485228062 CEST494121995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:48.490251064 CEST1995494125.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:49.122787952 CEST48202443192.168.2.13185.125.190.26
                            Oct 6, 2024 22:09:49.499286890 CEST494141995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:49.504120111 CEST1995494145.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:49.504194021 CEST494141995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:49.505153894 CEST494141995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:49.509960890 CEST1995494145.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:49.510011911 CEST494141995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:49.514873981 CEST1995494145.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:51.223680973 CEST1995494145.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:51.223824024 CEST494141995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:51.228713989 CEST1995494145.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:52.232971907 CEST494161995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:52.237888098 CEST1995494165.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:52.237952948 CEST494161995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:52.238497019 CEST494161995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:52.243532896 CEST1995494165.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:52.244618893 CEST494161995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:52.249425888 CEST1995494165.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:53.977335930 CEST1995494165.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:53.977672100 CEST494161995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:53.982609987 CEST1995494165.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:54.997082949 CEST494181995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:55.002341032 CEST1995494185.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:55.002408981 CEST494181995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:55.003532887 CEST494181995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:55.008342981 CEST1995494185.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:55.008400917 CEST494181995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:55.013175964 CEST1995494185.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:56.739718914 CEST1995494185.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:56.739962101 CEST494181995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:56.744818926 CEST1995494185.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:57.749505043 CEST494201995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:57.754508972 CEST1995494205.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:57.754591942 CEST494201995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:57.755301952 CEST494201995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:57.760229111 CEST1995494205.59.249.232192.168.2.13
                            Oct 6, 2024 22:09:57.760318995 CEST494201995192.168.2.135.59.249.232
                            Oct 6, 2024 22:09:57.765259027 CEST1995494205.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:01.924298048 CEST1995494205.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:01.924488068 CEST494201995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:01.929258108 CEST1995494205.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:02.937685966 CEST494221995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:02.942498922 CEST1995494225.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:02.942696095 CEST494221995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:02.943902969 CEST494221995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:02.948780060 CEST1995494225.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:02.948849916 CEST494221995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:02.953732014 CEST1995494225.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:04.638881922 CEST1995494225.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:04.639209032 CEST494221995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:04.644153118 CEST1995494225.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:05.648914099 CEST494241995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:05.653686047 CEST1995494245.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:05.653749943 CEST494241995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:05.655410051 CEST494241995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:05.660223961 CEST1995494245.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:05.660280943 CEST494241995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:05.665119886 CEST1995494245.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:07.378062010 CEST1995494245.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:07.378164053 CEST494241995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:07.382973909 CEST1995494245.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:08.388310909 CEST494261995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:08.393163919 CEST1995494265.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:08.393232107 CEST494261995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:08.394036055 CEST494261995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:08.398866892 CEST1995494265.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:08.398920059 CEST494261995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:08.403803110 CEST1995494265.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:10.150229931 CEST1995494265.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:10.150403023 CEST494261995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:10.155261993 CEST1995494265.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:11.160469055 CEST494281995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:11.165283918 CEST1995494285.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:11.165350914 CEST494281995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:11.166096926 CEST494281995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:11.170860052 CEST1995494285.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:11.170928001 CEST494281995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:11.175792933 CEST1995494285.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:12.893942118 CEST1995494285.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:12.894161940 CEST494281995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:12.898948908 CEST1995494285.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:13.904391050 CEST494301995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:13.909303904 CEST1995494305.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:13.909389019 CEST494301995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:13.910118103 CEST494301995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:13.914923906 CEST1995494305.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:13.914980888 CEST494301995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:13.919816971 CEST1995494305.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:19.842808008 CEST48202443192.168.2.13185.125.190.26
                            Oct 6, 2024 22:10:23.920387030 CEST494301995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:23.925451994 CEST1995494305.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:27.520725965 CEST1995494305.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:27.520939112 CEST494301995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:27.525784969 CEST1995494305.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:28.531563044 CEST494321995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:28.536434889 CEST1995494325.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:28.536556005 CEST494321995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:28.537647963 CEST494321995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:28.542404890 CEST1995494325.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:28.542480946 CEST494321995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:28.750968933 CEST494321995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:28.761933088 CEST1995494325.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:28.761950016 CEST1995494325.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:30.217767000 CEST1995494325.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:30.218118906 CEST494321995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:30.224293947 CEST1995494325.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:31.229091883 CEST494341995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:31.234338999 CEST1995494345.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:31.234441996 CEST494341995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:31.235374928 CEST494341995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:31.240493059 CEST1995494345.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:31.240561008 CEST494341995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:31.245755911 CEST1995494345.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:32.976198912 CEST1995494345.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:32.976658106 CEST494341995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:32.981535912 CEST1995494345.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:33.992719889 CEST494361995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:33.997704029 CEST1995494365.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:33.997823000 CEST494361995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:33.999627113 CEST494361995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:34.004399061 CEST1995494365.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:34.004461050 CEST494361995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:34.009243011 CEST1995494365.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:35.724889040 CEST1995494365.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:35.725100040 CEST494361995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:35.730007887 CEST1995494365.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:36.735718966 CEST494381995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:36.740612030 CEST1995494385.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:36.740700006 CEST494381995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:36.741570950 CEST494381995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:36.746370077 CEST1995494385.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:36.746439934 CEST494381995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:36.751435041 CEST1995494385.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:38.443934917 CEST1995494385.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:38.444107056 CEST494381995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:38.449095964 CEST1995494385.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:39.455045938 CEST494401995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:39.459923983 CEST1995494405.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:39.460004091 CEST494401995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:39.461256027 CEST494401995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:39.466269016 CEST1995494405.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:39.466341972 CEST494401995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:39.471123934 CEST1995494405.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:41.194755077 CEST1995494405.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:41.194930077 CEST494401995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:41.199856043 CEST1995494405.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:42.206228971 CEST494421995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:42.211273909 CEST1995494425.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:42.211374998 CEST494421995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:42.212135077 CEST494421995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:42.217107058 CEST1995494425.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:42.217179060 CEST494421995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:42.222479105 CEST1995494425.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:43.963856936 CEST1995494425.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:43.964210033 CEST494421995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:43.969099045 CEST1995494425.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:44.975142956 CEST494441995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:44.980000973 CEST1995494445.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:44.980082989 CEST494441995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:44.981197119 CEST494441995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:44.986090899 CEST1995494445.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:44.986150980 CEST494441995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:44.991067886 CEST1995494445.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:46.710232973 CEST1995494445.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:46.710544109 CEST494441995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:46.715424061 CEST1995494445.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:47.895963907 CEST494461995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:47.900932074 CEST1995494465.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:47.901019096 CEST494461995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:47.902201891 CEST494461995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:47.907061100 CEST1995494465.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:47.907182932 CEST494461995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:47.912018061 CEST1995494465.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:49.614336014 CEST1995494465.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:49.614794970 CEST494461995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:49.619788885 CEST1995494465.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:50.627964020 CEST494481995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:50.632858992 CEST1995494485.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:50.633004904 CEST494481995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:50.634342909 CEST494481995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:50.639147043 CEST1995494485.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:50.639254093 CEST494481995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:50.644120932 CEST1995494485.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:52.351934910 CEST1995494485.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:52.352159977 CEST494481995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:52.357116938 CEST1995494485.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:53.362564087 CEST494501995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:53.368035078 CEST1995494505.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:53.368107080 CEST494501995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:53.368949890 CEST494501995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:53.373697996 CEST1995494505.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:53.373804092 CEST494501995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:53.378681898 CEST1995494505.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:55.084492922 CEST1995494505.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:55.084729910 CEST494501995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:55.089642048 CEST1995494505.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:56.095401049 CEST494521995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:56.100215912 CEST1995494525.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:56.100337029 CEST494521995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:56.101357937 CEST494521995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:56.106199980 CEST1995494525.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:56.106307983 CEST494521995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:56.111125946 CEST1995494525.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:57.845263958 CEST1995494525.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:57.845495939 CEST494521995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:57.850361109 CEST1995494525.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:58.856230974 CEST494541995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:58.861565113 CEST1995494545.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:58.861632109 CEST494541995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:58.862680912 CEST494541995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:58.867469072 CEST1995494545.59.249.232192.168.2.13
                            Oct 6, 2024 22:10:58.867558002 CEST494541995192.168.2.135.59.249.232
                            Oct 6, 2024 22:10:58.872482061 CEST1995494545.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:00.586643934 CEST1995494545.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:00.586987972 CEST494541995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:00.591976881 CEST1995494545.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:01.600074053 CEST494561995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:01.605038881 CEST1995494565.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:01.605120897 CEST494561995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:01.606797934 CEST494561995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:01.611737967 CEST1995494565.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:01.611805916 CEST494561995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:01.616667032 CEST1995494565.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:03.435551882 CEST1995494565.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:03.435925961 CEST494561995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:03.440747023 CEST1995494565.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:04.447230101 CEST494581995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:04.452007055 CEST1995494585.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:04.452094078 CEST494581995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:04.453244925 CEST494581995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:04.457990885 CEST1995494585.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:04.458055973 CEST494581995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:04.462877035 CEST1995494585.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:06.141119957 CEST1995494585.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:06.141545057 CEST494581995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:06.146352053 CEST1995494585.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:07.159902096 CEST494601995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:07.164844036 CEST1995494605.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:07.164932013 CEST494601995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:07.165827990 CEST494601995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:07.170649052 CEST1995494605.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:07.170712948 CEST494601995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:07.175575018 CEST1995494605.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:08.926022053 CEST1995494605.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:08.926167965 CEST494601995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:09.122061014 CEST1995494605.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:09.122409105 CEST494601995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:09.126508951 CEST1995494605.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:09.936968088 CEST494621995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:09.941837072 CEST1995494625.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:09.941900015 CEST494621995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:09.942462921 CEST494621995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:09.947211027 CEST1995494625.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:09.947254896 CEST494621995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:09.952068090 CEST1995494625.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:11.660957098 CEST1995494625.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:11.661407948 CEST494621995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:11.666225910 CEST1995494625.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:12.673372984 CEST494641995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:12.678580999 CEST1995494645.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:12.678704023 CEST494641995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:12.679696083 CEST494641995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:12.684597015 CEST1995494645.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:12.684668064 CEST494641995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:12.689476013 CEST1995494645.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:14.447338104 CEST1995494645.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:14.447613955 CEST494641995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:14.452554941 CEST1995494645.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:15.459884882 CEST494661995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:15.464834929 CEST1995494665.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:15.464886904 CEST494661995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:15.465843916 CEST494661995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:15.470678091 CEST1995494665.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:15.470721006 CEST494661995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:15.475537062 CEST1995494665.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:22.566400051 CEST1995494665.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:22.566620111 CEST494661995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:22.571518898 CEST1995494665.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:23.577400923 CEST494681995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:23.582294941 CEST1995494685.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:23.582370043 CEST494681995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:23.583343983 CEST494681995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:23.588223934 CEST1995494685.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:23.588288069 CEST494681995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:23.593126059 CEST1995494685.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:25.265397072 CEST1995494685.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:25.265542984 CEST494681995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:25.270472050 CEST1995494685.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:26.457564116 CEST494701995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:26.462991953 CEST1995494705.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:26.463057995 CEST494701995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:26.464421034 CEST494701995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:26.469167948 CEST1995494705.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:26.469227076 CEST494701995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:26.474073887 CEST1995494705.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:28.190047979 CEST1995494705.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:28.190500021 CEST494701995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:28.195342064 CEST1995494705.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:29.201361895 CEST494721995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:29.206581116 CEST1995494725.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:29.206635952 CEST494721995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:29.207403898 CEST494721995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:29.212152004 CEST1995494725.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:29.212203979 CEST494721995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:29.217040062 CEST1995494725.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:30.927373886 CEST1995494725.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:30.927721024 CEST494721995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:30.932625055 CEST1995494725.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:31.939335108 CEST494741995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:31.944381952 CEST1995494745.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:31.944483042 CEST494741995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:31.945657015 CEST494741995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:31.950537920 CEST1995494745.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:31.950638056 CEST494741995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:31.955545902 CEST1995494745.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:33.679214954 CEST1995494745.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:33.679609060 CEST494741995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:33.684525967 CEST1995494745.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:34.692291021 CEST494761995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:34.697242022 CEST1995494765.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:34.697335005 CEST494761995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:34.699002028 CEST494761995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:34.703876972 CEST1995494765.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:34.703962088 CEST494761995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:34.711205006 CEST1995494765.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:36.414783001 CEST1995494765.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:36.415098906 CEST494761995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:36.420049906 CEST1995494765.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:37.426647902 CEST494781995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:37.431754112 CEST1995494785.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:37.431921959 CEST494781995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:37.433247089 CEST494781995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:37.438111067 CEST1995494785.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:37.438241959 CEST494781995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:37.443090916 CEST1995494785.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:39.164176941 CEST1995494785.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:39.164618969 CEST494781995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:39.169639111 CEST1995494785.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:40.176419020 CEST494801995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:40.181906939 CEST1995494805.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:40.182037115 CEST494801995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:40.183382034 CEST494801995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:40.188785076 CEST1995494805.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:40.188873053 CEST494801995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:40.193737984 CEST1995494805.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:41.933124065 CEST1995494805.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:41.933526039 CEST494801995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:41.938477993 CEST1995494805.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:42.945652008 CEST494821995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:42.950489998 CEST1995494825.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:42.950577974 CEST494821995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:42.952141047 CEST494821995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:42.957043886 CEST1995494825.59.249.232192.168.2.13
                            Oct 6, 2024 22:11:42.957125902 CEST494821995192.168.2.135.59.249.232
                            Oct 6, 2024 22:11:42.961958885 CEST1995494825.59.249.232192.168.2.13
                            TimestampSource PortDest PortSource IPDest IP
                            Oct 6, 2024 22:09:38.360402107 CEST3827953192.168.2.138.8.8.8
                            Oct 6, 2024 22:09:38.370762110 CEST53382798.8.8.8192.168.2.13
                            Oct 6, 2024 22:09:41.175715923 CEST3530753192.168.2.138.8.8.8
                            Oct 6, 2024 22:09:41.187001944 CEST53353078.8.8.8192.168.2.13
                            Oct 6, 2024 22:09:43.958245993 CEST4883853192.168.2.138.8.8.8
                            Oct 6, 2024 22:09:43.965132952 CEST53488388.8.8.8192.168.2.13
                            Oct 6, 2024 22:09:46.786849976 CEST4663253192.168.2.138.8.8.8
                            Oct 6, 2024 22:09:46.796998978 CEST53466328.8.8.8192.168.2.13
                            Oct 6, 2024 22:09:49.487801075 CEST5589853192.168.2.138.8.8.8
                            Oct 6, 2024 22:09:49.498610020 CEST53558988.8.8.8192.168.2.13
                            Oct 6, 2024 22:09:52.225361109 CEST5252953192.168.2.138.8.8.8
                            Oct 6, 2024 22:09:52.232527018 CEST53525298.8.8.8192.168.2.13
                            Oct 6, 2024 22:09:54.980596066 CEST3657553192.168.2.138.8.8.8
                            Oct 6, 2024 22:09:54.996314049 CEST53365758.8.8.8192.168.2.13
                            Oct 6, 2024 22:09:57.742005110 CEST5201753192.168.2.138.8.8.8
                            Oct 6, 2024 22:09:57.749001980 CEST53520178.8.8.8192.168.2.13
                            Oct 6, 2024 22:10:02.927088022 CEST4720653192.168.2.138.8.8.8
                            Oct 6, 2024 22:10:02.936974049 CEST53472068.8.8.8192.168.2.13
                            Oct 6, 2024 22:10:05.641073942 CEST5040453192.168.2.138.8.8.8
                            Oct 6, 2024 22:10:05.648036003 CEST53504048.8.8.8192.168.2.13
                            Oct 6, 2024 22:10:08.380064011 CEST3451753192.168.2.138.8.8.8
                            Oct 6, 2024 22:10:08.387876034 CEST53345178.8.8.8192.168.2.13
                            Oct 6, 2024 22:10:11.152724981 CEST5692753192.168.2.138.8.8.8
                            Oct 6, 2024 22:10:11.159836054 CEST53569278.8.8.8192.168.2.13
                            Oct 6, 2024 22:10:13.896749973 CEST3458553192.168.2.138.8.8.8
                            Oct 6, 2024 22:10:13.903717995 CEST53345858.8.8.8192.168.2.13
                            Oct 6, 2024 22:10:28.524224997 CEST5038553192.168.2.138.8.8.8
                            Oct 6, 2024 22:10:28.530868053 CEST53503858.8.8.8192.168.2.13
                            Oct 6, 2024 22:10:31.220633984 CEST3702853192.168.2.138.8.8.8
                            Oct 6, 2024 22:10:31.228269100 CEST53370288.8.8.8192.168.2.13
                            Oct 6, 2024 22:10:33.980103016 CEST3963953192.168.2.138.8.8.8
                            Oct 6, 2024 22:10:33.991739988 CEST53396398.8.8.8192.168.2.13
                            Oct 6, 2024 22:10:36.727780104 CEST4016453192.168.2.138.8.8.8
                            Oct 6, 2024 22:10:36.735121965 CEST53401648.8.8.8192.168.2.13
                            Oct 6, 2024 22:10:39.447360039 CEST4881553192.168.2.138.8.8.8
                            Oct 6, 2024 22:10:39.454317093 CEST53488158.8.8.8192.168.2.13
                            Oct 6, 2024 22:10:42.198185921 CEST4663253192.168.2.138.8.8.8
                            Oct 6, 2024 22:10:42.205600977 CEST53466328.8.8.8192.168.2.13
                            Oct 6, 2024 22:10:44.967211962 CEST3357353192.168.2.138.8.8.8
                            Oct 6, 2024 22:10:44.974422932 CEST53335738.8.8.8192.168.2.13
                            Oct 6, 2024 22:10:47.713612080 CEST3420153192.168.2.138.8.8.8
                            Oct 6, 2024 22:10:47.895107031 CEST53342018.8.8.8192.168.2.13
                            Oct 6, 2024 22:10:50.619590998 CEST5220253192.168.2.138.8.8.8
                            Oct 6, 2024 22:10:50.627274036 CEST53522028.8.8.8192.168.2.13
                            Oct 6, 2024 22:10:53.355279922 CEST3486353192.168.2.138.8.8.8
                            Oct 6, 2024 22:10:53.361999035 CEST53348638.8.8.8192.168.2.13
                            Oct 6, 2024 22:10:56.087830067 CEST4041753192.168.2.138.8.8.8
                            Oct 6, 2024 22:10:56.094717979 CEST53404178.8.8.8192.168.2.13
                            Oct 6, 2024 22:10:58.848510027 CEST3413853192.168.2.138.8.8.8
                            Oct 6, 2024 22:10:58.855632067 CEST53341388.8.8.8192.168.2.13
                            Oct 6, 2024 22:11:01.591825962 CEST3430053192.168.2.138.8.8.8
                            Oct 6, 2024 22:11:01.599216938 CEST53343008.8.8.8192.168.2.13
                            Oct 6, 2024 22:11:04.439254045 CEST5774353192.168.2.138.8.8.8
                            Oct 6, 2024 22:11:04.446610928 CEST53577438.8.8.8192.168.2.13
                            Oct 6, 2024 22:11:07.151496887 CEST3621853192.168.2.138.8.8.8
                            Oct 6, 2024 22:11:07.158289909 CEST53362188.8.8.8192.168.2.13
                            Oct 6, 2024 22:11:09.928961992 CEST3808853192.168.2.138.8.8.8
                            Oct 6, 2024 22:11:09.936636925 CEST53380888.8.8.8192.168.2.13
                            Oct 6, 2024 22:11:12.664838076 CEST4365853192.168.2.138.8.8.8
                            Oct 6, 2024 22:11:12.672718048 CEST53436588.8.8.8192.168.2.13
                            Oct 6, 2024 22:11:15.451641083 CEST3812753192.168.2.138.8.8.8
                            Oct 6, 2024 22:11:15.459114075 CEST53381278.8.8.8192.168.2.13
                            Oct 6, 2024 22:11:23.569418907 CEST4011453192.168.2.138.8.8.8
                            Oct 6, 2024 22:11:23.576715946 CEST53401148.8.8.8192.168.2.13
                            Oct 6, 2024 22:11:26.268511057 CEST5707053192.168.2.138.8.8.8
                            Oct 6, 2024 22:11:26.456413031 CEST53570708.8.8.8192.168.2.13
                            Oct 6, 2024 22:11:29.193089962 CEST3623553192.168.2.138.8.8.8
                            Oct 6, 2024 22:11:29.200699091 CEST53362358.8.8.8192.168.2.13
                            Oct 6, 2024 22:11:31.931051016 CEST3657753192.168.2.138.8.8.8
                            Oct 6, 2024 22:11:31.938533068 CEST53365778.8.8.8192.168.2.13
                            Oct 6, 2024 22:11:34.683834076 CEST5431653192.168.2.138.8.8.8
                            Oct 6, 2024 22:11:34.691499949 CEST53543168.8.8.8192.168.2.13
                            Oct 6, 2024 22:11:37.418788910 CEST3389053192.168.2.138.8.8.8
                            Oct 6, 2024 22:11:37.425869942 CEST53338908.8.8.8192.168.2.13
                            Oct 6, 2024 22:11:40.168328047 CEST5934753192.168.2.138.8.8.8
                            Oct 6, 2024 22:11:40.175748110 CEST53593478.8.8.8192.168.2.13
                            Oct 6, 2024 22:11:42.937793016 CEST4880653192.168.2.138.8.8.8
                            Oct 6, 2024 22:11:42.944783926 CEST53488068.8.8.8192.168.2.13
                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                            Oct 6, 2024 22:09:38.360402107 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:09:41.175715923 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:09:43.958245993 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:09:46.786849976 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:09:49.487801075 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:09:52.225361109 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:09:54.980596066 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:09:57.742005110 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:02.927088022 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:05.641073942 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:08.380064011 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:11.152724981 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:13.896749973 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:28.524224997 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:31.220633984 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:33.980103016 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:36.727780104 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:39.447360039 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:42.198185921 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:44.967211962 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:47.713612080 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:50.619590998 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:53.355279922 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:56.087830067 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:58.848510027 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:11:01.591825962 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:11:04.439254045 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:11:07.151496887 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:11:09.928961992 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:11:12.664838076 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:11:15.451641083 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:11:23.569418907 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:11:26.268511057 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:11:29.193089962 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:11:31.931051016 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:11:34.683834076 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:11:37.418788910 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:11:40.168328047 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            Oct 6, 2024 22:11:42.937793016 CEST192.168.2.138.8.8.80x0Standard query (0)net.igxhost.ruA (IP address)IN (0x0001)false
                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                            Oct 6, 2024 22:09:38.370762110 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:09:41.187001944 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:09:43.965132952 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:09:46.796998978 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:09:49.498610020 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:09:52.232527018 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:09:54.996314049 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:09:57.749001980 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:02.936974049 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:05.648036003 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:08.387876034 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:11.159836054 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:13.903717995 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:28.530868053 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:31.228269100 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:33.991739988 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:36.735121965 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:39.454317093 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:42.205600977 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:44.974422932 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:47.895107031 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:50.627274036 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:53.361999035 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:56.094717979 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:10:58.855632067 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:11:01.599216938 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:11:04.446610928 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:11:07.158289909 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:11:09.936636925 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:11:12.672718048 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:11:15.459114075 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:11:23.576715946 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:11:26.456413031 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:11:29.200699091 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:11:31.938533068 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:11:34.691499949 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:11:37.425869942 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:11:40.175748110 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false
                            Oct 6, 2024 22:11:42.944783926 CEST8.8.8.8192.168.2.130x0No error (0)net.igxhost.ru5.59.249.232A (IP address)IN (0x0001)false

                            System Behavior

                            Start time (UTC):20:09:37
                            Start date (UTC):06/10/2024
                            Path:/tmp/na.elf
                            Arguments:/tmp/na.elf
                            File size:138552 bytes
                            MD5 hash:1b0e1d2bf03f0593cbb08b390c80e809

                            Start time (UTC):20:09:37
                            Start date (UTC):06/10/2024
                            Path:/tmp/na.elf
                            Arguments:-
                            File size:138552 bytes
                            MD5 hash:1b0e1d2bf03f0593cbb08b390c80e809

                            Start time (UTC):20:09:37
                            Start date (UTC):06/10/2024
                            Path:/tmp/na.elf
                            Arguments:-
                            File size:138552 bytes
                            MD5 hash:1b0e1d2bf03f0593cbb08b390c80e809