Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
5FteLLQ1oY.elf

Overview

General Information

Sample name:5FteLLQ1oY.elf
renamed because original name is a hash value
Original sample name:d9d9bf404ee4d140658b2f84d2924795.elf
Analysis ID:1529277
MD5:d9d9bf404ee4d140658b2f84d2924795
SHA1:281ef5fb0a7e619ebf9f5d35cd33318247060274
SHA256:c15bcb9b5fbff2d7eeeae1c141b8aee193df7defa6e2e7a96a9033917578bc4c
Tags:32elfmipsmirai
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1529277
Start date and time:2024-10-08 20:18:36 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 15s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:5FteLLQ1oY.elf
renamed because original name is a hash value
Original Sample Name:d9d9bf404ee4d140658b2f84d2924795.elf
Detection:MAL
Classification:mal48.linELF@0/0@2/0
  • VT rate limit hit for: 5FteLLQ1oY.elf
Command:/tmp/5FteLLQ1oY.elf
PID:5540
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • sh (PID: 5580, Parent: 1383, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/bin/gnome-shell
  • gnome-shell (PID: 5580, Parent: 1383, MD5: da7a257239677622fe4b3a65972c9e87) Arguments: /usr/bin/gnome-shell
  • sh (PID: 5583, Parent: 1383, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing
  • gsd-sharing (PID: 5583, Parent: 1383, MD5: e29d9025d98590fbb69f89fdbd4438b3) Arguments: /usr/libexec/gsd-sharing
  • gdm3 New Fork (PID: 5584, Parent: 1289)
  • Default (PID: 5584, Parent: 1289, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • gdm3 New Fork (PID: 5605, Parent: 1289)
  • Default (PID: 5605, Parent: 1289, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • systemd New Fork (PID: 5611, Parent: 1)
  • systemd-user-runtime-dir (PID: 5611, Parent: 1, MD5: d55f4b0847f88131dbcfb07435178e54) Arguments: /lib/systemd/systemd-user-runtime-dir stop 127
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: 5FteLLQ1oY.elfReversingLabs: Detection: 23%
Source: /tmp/5FteLLQ1oY.elf (PID: 5540)Socket: 127.0.0.1:1234Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: unknownTCP traffic detected without corresponding DNS query: 199.59.243.227
Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
Source: ELF static info symbol of initial sample.symtab present: no
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)SIGKILL sent: pid: 888, result: successfulJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)SIGKILL sent: pid: 1444, result: successfulJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)SIGKILL sent: pid: 1599, result: successfulJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)SIGKILL sent: pid: 1610, result: successfulJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)SIGKILL sent: pid: 5580, result: successfulJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)SIGKILL sent: pid: 5583, result: successfulJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)SIGKILL sent: pid: 5583, result: no such processJump to behavior
Source: classification engineClassification label: mal48.linELF@0/0@2/0
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3760/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3760/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3761/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3761/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/1583/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/1583/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/2672/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/2672/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3759/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3759/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/1577/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/917/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/917/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/1593/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/1593/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3406/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3406/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/1/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/1/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/2/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/2/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/1589/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/1588/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/1588/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/4/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/4/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3402/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3402/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/5/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/5/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/6/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/6/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/7/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/7/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/8/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/8/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/800/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/800/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3762/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3762/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/9/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/9/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/801/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/801/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/803/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/803/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/806/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/806/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/807/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/807/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/928/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/928/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3420/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3420/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/1599/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3412/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3412/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/1371/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/5608/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/1369/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3304/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3304/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3425/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3425/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/940/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/940/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/941/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/941/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/1364/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/5600/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/5601/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/5602/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/5603/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/5604/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/5620/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/1383/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/1382/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/1381/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/5618/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/5619/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/5611/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/5612/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/5613/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/5614/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/5615/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/5616/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3319/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3319/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/5617/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/1394/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3329/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3329/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/5629/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3207/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3207/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/5621/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/5622/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/725/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/725/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3687/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/3687/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/5623/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/726/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5544)File opened: /proc/726/cmdlineJump to behavior
Source: /tmp/5FteLLQ1oY.elf (PID: 5540)Queries kernel information via 'uname': Jump to behavior
Source: 5FteLLQ1oY.elf, 5540.1.000055e03e828000.000055e03e8d0000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mipsel
Source: 5FteLLQ1oY.elf, 5540.1.00007ffd442bb000.00007ffd442dc000.rw-.sdmpBinary or memory string: ex86_64/usr/bin/qemu-mipsel/tmp/5FteLLQ1oY.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/5FteLLQ1oY.elf
Source: 5FteLLQ1oY.elf, 5540.1.000055e03e828000.000055e03e8d0000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mipsel
Source: 5FteLLQ1oY.elf, 5540.1.00007ffd442bb000.00007ffd442dc000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsel
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume Access1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Non-Application Layer Protocol
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1529277 Sample: 5FteLLQ1oY.elf Startdate: 08/10/2024 Architecture: LINUX Score: 48 19 199.59.243.227, 33104, 33106, 33108 BODIS-NJUS United States 2->19 21 subcarrace.indy 2->21 23 4 other IPs or domains 2->23 25 Multi AV Scanner detection for submitted file 2->25 7 5FteLLQ1oY.elf 2->7         started        9 gnome-session-binary sh gnome-shell 2->9         started        11 gnome-session-binary sh gsd-sharing 2->11         started        13 3 other processes 2->13 signatures3 process4 process5 15 5FteLLQ1oY.elf 7->15         started        17 5FteLLQ1oY.elf 7->17         started       
SourceDetectionScannerLabelLink
5FteLLQ1oY.elf24%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
daisy.ubuntu.com
162.213.35.24
truefalse
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    199.59.243.227
    unknownUnited States
    395082BODIS-NJUSfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    199.59.243.227enkJ6J7dAn.exeGet hashmaliciousFormBookBrowse
    • www.polarmuseum.info/nuqv/
    PO59458.exeGet hashmaliciousFormBookBrowse
    • www.notepad.mobi/42yt/
    NARLOG 08.10.2024.exeGet hashmaliciousFormBookBrowse
    • www.online-dating28.xyz/xl8n/
    IRYzGMMbSw.exeGet hashmaliciousFormBookBrowse
    • www.pmjjewels.online/aygf/
    SOA SIL TL382920.exeGet hashmaliciousFormBookBrowse
    • www.online-dating28.xyz/6nb6/
    Arrival Notice.exeGet hashmaliciousFormBookBrowse
    • www.polarmuseum.info/reui/
    PURCHASE ORDER-6350.exeGet hashmaliciousFormBookBrowse
    • www.donante-de-ovulos.biz/8lrv/
    https://pancake-swapp.github.io/Get hashmaliciousHTMLPhisherBrowse
    • ww25.blockaircypher.com/_tr
    http://wiki.hostmaster.chinametrogroup.com/Get hashmaliciousUnknownBrowse
    • wiki.hostmaster.chinametrogroup.com/_tr
    PO#001498.exeGet hashmaliciousFormBookBrowse
    • www.notepad.mobi/l4rw/
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    daisy.ubuntu.comgMYQFxufu0.elfGet hashmaliciousMiraiBrowse
    • 162.213.35.24
    k49syyxi7V.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.24
    4LbWi40g57.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.24
    NLHiAJgSnj.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.24
    irods-runtime-4.1.9-centos7-x86_64.rpmGet hashmaliciousXmrigBrowse
    • 162.213.35.24
    na.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.25
    na.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.24
    logrotate_malware.elfGet hashmaliciousXmrigBrowse
    • 162.213.35.25
    na.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.25
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    BODIS-NJUSk49syyxi7V.elfGet hashmaliciousUnknownBrowse
    • 199.59.243.227
    enkJ6J7dAn.exeGet hashmaliciousFormBookBrowse
    • 199.59.243.227
    PO59458.exeGet hashmaliciousFormBookBrowse
    • 199.59.243.227
    NARLOG 08.10.2024.exeGet hashmaliciousFormBookBrowse
    • 199.59.243.227
    IRYzGMMbSw.exeGet hashmaliciousFormBookBrowse
    • 199.59.243.227
    Payment.vbsGet hashmaliciousFormBookBrowse
    • 199.59.243.227
    SOA SIL TL382920.exeGet hashmaliciousFormBookBrowse
    • 199.59.243.227
    Arrival Notice.exeGet hashmaliciousFormBookBrowse
    • 199.59.243.227
    PURCHASE ORDER-6350.exeGet hashmaliciousFormBookBrowse
    • 199.59.243.227
    https://pancake-swapp.github.io/Get hashmaliciousHTMLPhisherBrowse
    • 199.59.243.205
    No context
    No context
    No created / dropped files found
    File type:ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
    Entropy (8bit):5.349174607156046
    TrID:
    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
    File name:5FteLLQ1oY.elf
    File size:65'288 bytes
    MD5:d9d9bf404ee4d140658b2f84d2924795
    SHA1:281ef5fb0a7e619ebf9f5d35cd33318247060274
    SHA256:c15bcb9b5fbff2d7eeeae1c141b8aee193df7defa6e2e7a96a9033917578bc4c
    SHA512:3f7a761c12a96e302d2d5107fa7333343f08e1f2abf99402cc430a0d92c7e07845737ec12583de466b34a598100515527c34026f72ee90c1028267ea4d4f6bd2
    SSDEEP:1536:R0KfMygQc0F3ghpNfxTZT+0JU0+9Z6iY0Hi:R04MyPRF3ghvJ1+9LQ
    TLSH:C753950ABF610EF7EC5BDD3705E81B0634CD651A21A97F397934D928FA1A20B49E3C64
    File Content Preview:.ELF....................`.@.4...........4. ...(...............@...@.`...`...............d...d.D.d.D.D...$Y..........Q.td...............................<.w.'!......'.......................<.w.'!... .........9'.. ........................<hw.'!...........0.9

    ELF header

    Class:ELF32
    Data:2's complement, little endian
    Version:1 (current)
    Machine:MIPS R3000
    Version Number:0x1
    Type:EXEC (Executable file)
    OS/ABI:UNIX - System V
    ABI Version:0
    Entry Point Address:0x400260
    Flags:0x1007
    ELF Header Size:52
    Program Header Offset:52
    Program Header Size:32
    Number of Program Headers:3
    Section Header Offset:64768
    Section Header Size:40
    Number of Section Headers:13
    Header String Table Index:12
    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
    NULL0x00x00x00x00x0000
    .initPROGBITS0x4000940x940x8c0x00x6AX004
    .textPROGBITS0x4001200x1200xec800x00x6AX0016
    .finiPROGBITS0x40eda00xeda00x5c0x00x6AX004
    .rodataPROGBITS0x40ee000xee000x7600x00x2A0016
    .ctorsPROGBITS0x44f5640xf5640x80x00x3WA004
    .dtorsPROGBITS0x44f56c0xf56c0x80x00x3WA004
    .data.rel.roPROGBITS0x44f5780xf5780x5c0x00x3WA004
    .dataPROGBITS0x44f5e00xf5e00x2800x00x3WA0016
    .gotPROGBITS0x44f8600xf8600x4480x40x10000003WAp0016
    .sbssNOBITS0x44fca80xfca80x3c0x00x10000003WAp004
    .bssNOBITS0x44fcf00xfca80x51980x00x3WA0016
    .shstrtabSTRTAB0x00xfca80x560x00x0001
    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
    LOAD0x00x4000000x4000000xf5600xf5605.37220x5R E0x10000.init .text .fini .rodata
    LOAD0xf5640x44f5640x44f5640x7440x59243.82250x6RW 0x10000.ctors .dtors .data.rel.ro .data .got .sbss .bss
    GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
    TimestampSource PortDest PortSource IPDest IP
    Oct 8, 2024 20:19:47.365628004 CEST3310480192.168.2.14199.59.243.227
    Oct 8, 2024 20:19:47.372400999 CEST8033104199.59.243.227192.168.2.14
    Oct 8, 2024 20:19:47.372457981 CEST3310480192.168.2.14199.59.243.227
    Oct 8, 2024 20:19:47.373347998 CEST3310480192.168.2.14199.59.243.227
    Oct 8, 2024 20:19:47.379403114 CEST8033104199.59.243.227192.168.2.14
    Oct 8, 2024 20:19:47.843147993 CEST8033104199.59.243.227192.168.2.14
    Oct 8, 2024 20:19:47.843316078 CEST3310480192.168.2.14199.59.243.227
    Oct 8, 2024 20:19:47.843765020 CEST8033104199.59.243.227192.168.2.14
    Oct 8, 2024 20:19:47.843843937 CEST3310480192.168.2.14199.59.243.227
    Oct 8, 2024 20:19:47.850024939 CEST8033104199.59.243.227192.168.2.14
    Oct 8, 2024 20:20:11.682131052 CEST3310680192.168.2.14199.59.243.227
    Oct 8, 2024 20:20:11.687092066 CEST8033106199.59.243.227192.168.2.14
    Oct 8, 2024 20:20:11.687150002 CEST3310680192.168.2.14199.59.243.227
    Oct 8, 2024 20:20:11.695779085 CEST3310680192.168.2.14199.59.243.227
    Oct 8, 2024 20:20:11.700978994 CEST8033106199.59.243.227192.168.2.14
    Oct 8, 2024 20:20:12.173404932 CEST8033106199.59.243.227192.168.2.14
    Oct 8, 2024 20:20:12.173477888 CEST3310680192.168.2.14199.59.243.227
    Oct 8, 2024 20:20:12.173516035 CEST8033106199.59.243.227192.168.2.14
    Oct 8, 2024 20:20:12.173574924 CEST3310680192.168.2.14199.59.243.227
    Oct 8, 2024 20:20:12.178468943 CEST8033106199.59.243.227192.168.2.14
    Oct 8, 2024 20:20:26.053037882 CEST3310880192.168.2.14199.59.243.227
    Oct 8, 2024 20:20:26.058711052 CEST8033108199.59.243.227192.168.2.14
    Oct 8, 2024 20:20:26.058772087 CEST3310880192.168.2.14199.59.243.227
    Oct 8, 2024 20:20:26.059340000 CEST3310880192.168.2.14199.59.243.227
    Oct 8, 2024 20:20:26.065340042 CEST8033108199.59.243.227192.168.2.14
    Oct 8, 2024 20:20:26.526227951 CEST8033108199.59.243.227192.168.2.14
    Oct 8, 2024 20:20:26.526283979 CEST8033108199.59.243.227192.168.2.14
    Oct 8, 2024 20:20:26.526393890 CEST3310880192.168.2.14199.59.243.227
    Oct 8, 2024 20:20:26.526437998 CEST3310880192.168.2.14199.59.243.227
    Oct 8, 2024 20:20:26.531348944 CEST8033108199.59.243.227192.168.2.14
    Oct 8, 2024 20:20:49.859952927 CEST3311080192.168.2.14199.59.243.227
    Oct 8, 2024 20:20:49.865695953 CEST8033110199.59.243.227192.168.2.14
    Oct 8, 2024 20:20:49.865767002 CEST3311080192.168.2.14199.59.243.227
    Oct 8, 2024 20:20:49.866497993 CEST3311080192.168.2.14199.59.243.227
    Oct 8, 2024 20:20:49.871352911 CEST8033110199.59.243.227192.168.2.14
    Oct 8, 2024 20:20:50.344234943 CEST8033110199.59.243.227192.168.2.14
    Oct 8, 2024 20:20:50.344350100 CEST8033110199.59.243.227192.168.2.14
    Oct 8, 2024 20:20:50.344398975 CEST3311080192.168.2.14199.59.243.227
    Oct 8, 2024 20:20:50.344537020 CEST3311080192.168.2.14199.59.243.227
    Oct 8, 2024 20:20:50.349378109 CEST8033110199.59.243.227192.168.2.14
    Oct 8, 2024 20:20:59.101859093 CEST3311280192.168.2.14199.59.243.227
    Oct 8, 2024 20:20:59.108006954 CEST8033112199.59.243.227192.168.2.14
    Oct 8, 2024 20:20:59.108098984 CEST3311280192.168.2.14199.59.243.227
    Oct 8, 2024 20:20:59.109082937 CEST3311280192.168.2.14199.59.243.227
    Oct 8, 2024 20:20:59.115457058 CEST8033112199.59.243.227192.168.2.14
    Oct 8, 2024 20:20:59.797863007 CEST8033112199.59.243.227192.168.2.14
    Oct 8, 2024 20:20:59.797882080 CEST8033112199.59.243.227192.168.2.14
    Oct 8, 2024 20:20:59.797888994 CEST8033112199.59.243.227192.168.2.14
    Oct 8, 2024 20:20:59.798033953 CEST3311280192.168.2.14199.59.243.227
    Oct 8, 2024 20:20:59.798033953 CEST3311280192.168.2.14199.59.243.227
    Oct 8, 2024 20:20:59.798141003 CEST3311280192.168.2.14199.59.243.227
    Oct 8, 2024 20:20:59.803253889 CEST8033112199.59.243.227192.168.2.14
    Oct 8, 2024 20:21:13.674357891 CEST3311480192.168.2.14199.59.243.227
    Oct 8, 2024 20:21:13.679318905 CEST8033114199.59.243.227192.168.2.14
    Oct 8, 2024 20:21:13.679395914 CEST3311480192.168.2.14199.59.243.227
    Oct 8, 2024 20:21:13.680114985 CEST3311480192.168.2.14199.59.243.227
    Oct 8, 2024 20:21:13.685018063 CEST8033114199.59.243.227192.168.2.14
    Oct 8, 2024 20:21:14.162556887 CEST8033114199.59.243.227192.168.2.14
    Oct 8, 2024 20:21:14.162638903 CEST8033114199.59.243.227192.168.2.14
    Oct 8, 2024 20:21:14.162975073 CEST3311480192.168.2.14199.59.243.227
    Oct 8, 2024 20:21:14.163007975 CEST3311480192.168.2.14199.59.243.227
    Oct 8, 2024 20:21:14.168059111 CEST8033114199.59.243.227192.168.2.14
    Oct 8, 2024 20:21:30.041249037 CEST3311680192.168.2.14199.59.243.227
    Oct 8, 2024 20:21:30.046802044 CEST8033116199.59.243.227192.168.2.14
    Oct 8, 2024 20:21:30.046906948 CEST3311680192.168.2.14199.59.243.227
    Oct 8, 2024 20:21:30.048418045 CEST3311680192.168.2.14199.59.243.227
    Oct 8, 2024 20:21:30.052959919 CEST8033116199.59.243.227192.168.2.14
    Oct 8, 2024 20:21:30.053097010 CEST3311680192.168.2.14199.59.243.227
    Oct 8, 2024 20:21:30.053875923 CEST8033116199.59.243.227192.168.2.14
    Oct 8, 2024 20:21:30.058693886 CEST8033116199.59.243.227192.168.2.14
    Oct 8, 2024 20:21:42.447593927 CEST3311880192.168.2.14199.59.243.227
    Oct 8, 2024 20:21:42.452490091 CEST8033118199.59.243.227192.168.2.14
    Oct 8, 2024 20:21:42.452581882 CEST3311880192.168.2.14199.59.243.227
    Oct 8, 2024 20:21:42.453486919 CEST3311880192.168.2.14199.59.243.227
    Oct 8, 2024 20:21:42.458334923 CEST8033118199.59.243.227192.168.2.14
    Oct 8, 2024 20:21:42.927510977 CEST8033118199.59.243.227192.168.2.14
    Oct 8, 2024 20:21:42.927668095 CEST8033118199.59.243.227192.168.2.14
    Oct 8, 2024 20:21:42.927896976 CEST3311880192.168.2.14199.59.243.227
    Oct 8, 2024 20:21:42.927980900 CEST3311880192.168.2.14199.59.243.227
    Oct 8, 2024 20:21:42.934856892 CEST8033118199.59.243.227192.168.2.14
    Oct 8, 2024 20:22:14.815640926 CEST3312080192.168.2.14199.59.243.227
    Oct 8, 2024 20:22:14.820924044 CEST8033120199.59.243.227192.168.2.14
    Oct 8, 2024 20:22:14.821052074 CEST3312080192.168.2.14199.59.243.227
    Oct 8, 2024 20:22:14.822201967 CEST3312080192.168.2.14199.59.243.227
    Oct 8, 2024 20:22:14.827188015 CEST8033120199.59.243.227192.168.2.14
    Oct 8, 2024 20:22:15.279346943 CEST8033120199.59.243.227192.168.2.14
    Oct 8, 2024 20:22:15.279478073 CEST8033120199.59.243.227192.168.2.14
    Oct 8, 2024 20:22:15.279597044 CEST3312080192.168.2.14199.59.243.227
    Oct 8, 2024 20:22:15.279673100 CEST3312080192.168.2.14199.59.243.227
    Oct 8, 2024 20:22:15.284615040 CEST8033120199.59.243.227192.168.2.14
    Oct 8, 2024 20:22:32.206984997 CEST3312280192.168.2.14199.59.243.227
    Oct 8, 2024 20:22:32.212446928 CEST8033122199.59.243.227192.168.2.14
    Oct 8, 2024 20:22:32.212616920 CEST3312280192.168.2.14199.59.243.227
    Oct 8, 2024 20:22:32.213443995 CEST3312280192.168.2.14199.59.243.227
    Oct 8, 2024 20:22:32.218233109 CEST8033122199.59.243.227192.168.2.14
    Oct 8, 2024 20:22:32.218414068 CEST3312280192.168.2.14199.59.243.227
    Oct 8, 2024 20:22:32.218513966 CEST8033122199.59.243.227192.168.2.14
    Oct 8, 2024 20:22:32.223617077 CEST8033122199.59.243.227192.168.2.14
    Oct 8, 2024 20:22:45.649241924 CEST3312480192.168.2.14199.59.243.227
    Oct 8, 2024 20:22:45.654429913 CEST8033124199.59.243.227192.168.2.14
    Oct 8, 2024 20:22:45.654553890 CEST3312480192.168.2.14199.59.243.227
    Oct 8, 2024 20:22:45.655659914 CEST3312480192.168.2.14199.59.243.227
    Oct 8, 2024 20:22:45.661699057 CEST8033124199.59.243.227192.168.2.14
    Oct 8, 2024 20:22:46.120522976 CEST8033124199.59.243.227192.168.2.14
    Oct 8, 2024 20:22:46.120574951 CEST8033124199.59.243.227192.168.2.14
    Oct 8, 2024 20:22:46.120702982 CEST3312480192.168.2.14199.59.243.227
    Oct 8, 2024 20:22:46.120702982 CEST3312480192.168.2.14199.59.243.227
    Oct 8, 2024 20:22:46.127016068 CEST8033124199.59.243.227192.168.2.14
    Oct 8, 2024 20:23:08.046067953 CEST3312680192.168.2.14199.59.243.227
    Oct 8, 2024 20:23:08.051054001 CEST8033126199.59.243.227192.168.2.14
    Oct 8, 2024 20:23:08.051145077 CEST3312680192.168.2.14199.59.243.227
    Oct 8, 2024 20:23:08.052462101 CEST3312680192.168.2.14199.59.243.227
    Oct 8, 2024 20:23:08.057257891 CEST8033126199.59.243.227192.168.2.14
    Oct 8, 2024 20:23:08.529373884 CEST8033126199.59.243.227192.168.2.14
    Oct 8, 2024 20:23:08.529603958 CEST3312680192.168.2.14199.59.243.227
    Oct 8, 2024 20:23:08.529694080 CEST8033126199.59.243.227192.168.2.14
    Oct 8, 2024 20:23:08.529803038 CEST3312680192.168.2.14199.59.243.227
    Oct 8, 2024 20:23:08.535788059 CEST8033126199.59.243.227192.168.2.14
    TimestampSource PortDest PortSource IPDest IP
    Oct 8, 2024 20:19:40.450983047 CEST3321853192.168.2.1463.231.92.27
    Oct 8, 2024 20:19:40.597141981 CEST533321863.231.92.27192.168.2.14
    Oct 8, 2024 20:19:40.600852013 CEST3571153192.168.2.14192.3.165.37
    Oct 8, 2024 20:19:40.699297905 CEST5335711192.3.165.37192.168.2.14
    Oct 8, 2024 20:19:40.700542927 CEST3795153192.168.2.14185.84.81.194
    Oct 8, 2024 20:19:40.710639000 CEST5337951185.84.81.194192.168.2.14
    Oct 8, 2024 20:19:40.712369919 CEST5725153192.168.2.14116.203.104.203
    Oct 8, 2024 20:19:40.723932028 CEST5357251116.203.104.203192.168.2.14
    Oct 8, 2024 20:19:40.725243092 CEST5686453192.168.2.14116.203.104.203
    Oct 8, 2024 20:19:40.735186100 CEST5356864116.203.104.203192.168.2.14
    Oct 8, 2024 20:19:40.736689091 CEST391315353192.168.2.14116.203.104.203
    Oct 8, 2024 20:19:42.061801910 CEST535339131116.203.104.203192.168.2.14
    Oct 8, 2024 20:19:42.063604116 CEST3692253192.168.2.14116.203.104.203
    Oct 8, 2024 20:19:42.074065924 CEST5336922116.203.104.203192.168.2.14
    Oct 8, 2024 20:19:42.076646090 CEST3619753192.168.2.1463.231.92.27
    Oct 8, 2024 20:19:42.235573053 CEST533619763.231.92.27192.168.2.14
    Oct 8, 2024 20:19:42.239484072 CEST4910653192.168.2.14185.84.81.194
    Oct 8, 2024 20:19:42.250123978 CEST5349106185.84.81.194192.168.2.14
    Oct 8, 2024 20:19:42.252120972 CEST5332553192.168.2.14116.203.104.203
    Oct 8, 2024 20:19:42.262043953 CEST5353325116.203.104.203192.168.2.14
    Oct 8, 2024 20:19:42.265103102 CEST5223153192.168.2.14116.203.104.203
    Oct 8, 2024 20:19:42.274955034 CEST5352231116.203.104.203192.168.2.14
    Oct 8, 2024 20:19:42.279901028 CEST467735353192.168.2.14130.61.69.123
    Oct 8, 2024 20:19:47.280822992 CEST5889153192.168.2.148.8.8.8
    Oct 8, 2024 20:19:47.288454056 CEST53588918.8.8.8192.168.2.14
    Oct 8, 2024 20:19:47.289040089 CEST3469853192.168.2.148.8.8.8
    Oct 8, 2024 20:19:47.297095060 CEST53346988.8.8.8192.168.2.14
    Oct 8, 2024 20:19:47.297669888 CEST3696853192.168.2.148.8.8.8
    Oct 8, 2024 20:19:47.304200888 CEST53369688.8.8.8192.168.2.14
    Oct 8, 2024 20:19:47.304749966 CEST3973453192.168.2.148.8.8.8
    Oct 8, 2024 20:19:47.311883926 CEST53397348.8.8.8192.168.2.14
    Oct 8, 2024 20:19:47.312786102 CEST5548353192.168.2.148.8.8.8
    Oct 8, 2024 20:19:47.319752932 CEST53554838.8.8.8192.168.2.14
    Oct 8, 2024 20:19:47.320370913 CEST3637053192.168.2.148.8.8.8
    Oct 8, 2024 20:19:47.329379082 CEST53363708.8.8.8192.168.2.14
    Oct 8, 2024 20:19:47.329984903 CEST5565453192.168.2.148.8.8.8
    Oct 8, 2024 20:19:47.341173887 CEST53556548.8.8.8192.168.2.14
    Oct 8, 2024 20:19:47.341712952 CEST5606153192.168.2.148.8.8.8
    Oct 8, 2024 20:19:47.349178076 CEST53560618.8.8.8192.168.2.14
    Oct 8, 2024 20:19:47.349677086 CEST4276253192.168.2.148.8.8.8
    Oct 8, 2024 20:19:47.357510090 CEST53427628.8.8.8192.168.2.14
    Oct 8, 2024 20:19:47.358007908 CEST5931253192.168.2.148.8.8.8
    Oct 8, 2024 20:19:47.365142107 CEST53593128.8.8.8192.168.2.14
    Oct 8, 2024 20:19:48.845206022 CEST350935353192.168.2.14130.61.64.122
    Oct 8, 2024 20:19:53.849376917 CEST545225353192.168.2.1454.36.111.116
    Oct 8, 2024 20:19:58.855736971 CEST5838253192.168.2.14185.84.81.194
    Oct 8, 2024 20:19:58.866183043 CEST5358382185.84.81.194192.168.2.14
    Oct 8, 2024 20:19:58.866838932 CEST4332553192.168.2.14130.61.64.122
    Oct 8, 2024 20:19:58.875030041 CEST5343325130.61.64.122192.168.2.14
    Oct 8, 2024 20:19:58.875930071 CEST398885353192.168.2.14161.97.219.84
    Oct 8, 2024 20:19:59.684346914 CEST535339888161.97.219.84192.168.2.14
    Oct 8, 2024 20:19:59.685667038 CEST5853153192.168.2.14116.203.104.203
    Oct 8, 2024 20:19:59.697520018 CEST5358531116.203.104.203192.168.2.14
    Oct 8, 2024 20:19:59.698436022 CEST5904853192.168.2.14116.203.104.203
    Oct 8, 2024 20:19:59.708340883 CEST5359048116.203.104.203192.168.2.14
    Oct 8, 2024 20:19:59.709052086 CEST550675353192.168.2.14162.243.19.47
    Oct 8, 2024 20:20:04.715361118 CEST586225353192.168.2.1454.36.111.116
    Oct 8, 2024 20:20:09.721781969 CEST526375353192.168.2.14192.3.165.37
    Oct 8, 2024 20:20:10.968718052 CEST535352637192.3.165.37192.168.2.14
    Oct 8, 2024 20:20:10.979000092 CEST479655353192.168.2.14116.203.104.203
    Oct 8, 2024 20:20:11.519974947 CEST535347965116.203.104.203192.168.2.14
    Oct 8, 2024 20:20:11.525162935 CEST3313953192.168.2.1454.36.111.116
    Oct 8, 2024 20:20:11.547236919 CEST4349853192.168.2.148.8.8.8
    Oct 8, 2024 20:20:11.555303097 CEST53434988.8.8.8192.168.2.14
    Oct 8, 2024 20:20:11.562331915 CEST3661553192.168.2.148.8.8.8
    Oct 8, 2024 20:20:11.569261074 CEST53366158.8.8.8192.168.2.14
    Oct 8, 2024 20:20:11.578017950 CEST4483653192.168.2.148.8.8.8
    Oct 8, 2024 20:20:11.584671021 CEST53448368.8.8.8192.168.2.14
    Oct 8, 2024 20:20:11.589751005 CEST4515253192.168.2.148.8.8.8
    Oct 8, 2024 20:20:11.596559048 CEST53451528.8.8.8192.168.2.14
    Oct 8, 2024 20:20:11.602782965 CEST5675353192.168.2.148.8.8.8
    Oct 8, 2024 20:20:11.609913111 CEST53567538.8.8.8192.168.2.14
    Oct 8, 2024 20:20:11.615158081 CEST5725753192.168.2.148.8.8.8
    Oct 8, 2024 20:20:11.622176886 CEST53572578.8.8.8192.168.2.14
    Oct 8, 2024 20:20:11.627296925 CEST3876853192.168.2.148.8.8.8
    Oct 8, 2024 20:20:11.633910894 CEST53387688.8.8.8192.168.2.14
    Oct 8, 2024 20:20:11.639364004 CEST4250153192.168.2.148.8.8.8
    Oct 8, 2024 20:20:11.646716118 CEST53425018.8.8.8192.168.2.14
    Oct 8, 2024 20:20:11.650760889 CEST5569353192.168.2.148.8.8.8
    Oct 8, 2024 20:20:11.657272100 CEST53556938.8.8.8192.168.2.14
    Oct 8, 2024 20:20:11.673908949 CEST5273953192.168.2.148.8.8.8
    Oct 8, 2024 20:20:11.680421114 CEST53527398.8.8.8192.168.2.14
    Oct 8, 2024 20:20:13.175182104 CEST3618553192.168.2.14130.61.69.123
    Oct 8, 2024 20:20:13.182322025 CEST5336185130.61.69.123192.168.2.14
    Oct 8, 2024 20:20:13.182934999 CEST4498653192.168.2.14185.84.81.194
    Oct 8, 2024 20:20:13.193257093 CEST5344986185.84.81.194192.168.2.14
    Oct 8, 2024 20:20:13.193872929 CEST5150053192.168.2.14192.3.165.37
    Oct 8, 2024 20:20:13.298801899 CEST5351500192.3.165.37192.168.2.14
    Oct 8, 2024 20:20:13.300033092 CEST432685353192.168.2.14162.243.19.47
    Oct 8, 2024 20:20:18.303220987 CEST444255353192.168.2.14162.243.19.47
    Oct 8, 2024 20:20:23.309140921 CEST4869953192.168.2.14116.203.104.203
    Oct 8, 2024 20:20:23.319907904 CEST5348699116.203.104.203192.168.2.14
    Oct 8, 2024 20:20:23.320707083 CEST5617953192.168.2.14161.97.219.84
    Oct 8, 2024 20:20:23.507981062 CEST5356179161.97.219.84192.168.2.14
    Oct 8, 2024 20:20:23.508842945 CEST4684453192.168.2.14161.97.219.84
    Oct 8, 2024 20:20:23.697593927 CEST5346844161.97.219.84192.168.2.14
    Oct 8, 2024 20:20:23.699348927 CEST343015353192.168.2.14192.3.165.37
    Oct 8, 2024 20:20:24.781743050 CEST535334301192.3.165.37192.168.2.14
    Oct 8, 2024 20:20:24.782831907 CEST5245953192.168.2.1463.231.92.27
    Oct 8, 2024 20:20:25.458728075 CEST535245963.231.92.27192.168.2.14
    Oct 8, 2024 20:20:25.459841013 CEST4678753192.168.2.14116.203.104.203
    Oct 8, 2024 20:20:25.470024109 CEST5346787116.203.104.203192.168.2.14
    Oct 8, 2024 20:20:25.470882893 CEST367875353192.168.2.14161.97.219.84
    Oct 8, 2024 20:20:25.974101067 CEST535336787161.97.219.84192.168.2.14
    Oct 8, 2024 20:20:25.975157022 CEST4483153192.168.2.148.8.8.8
    Oct 8, 2024 20:20:25.981693029 CEST53448318.8.8.8192.168.2.14
    Oct 8, 2024 20:20:25.982712984 CEST5522153192.168.2.148.8.8.8
    Oct 8, 2024 20:20:25.989029884 CEST53552218.8.8.8192.168.2.14
    Oct 8, 2024 20:20:25.989943981 CEST4845453192.168.2.148.8.8.8
    Oct 8, 2024 20:20:25.997886896 CEST53484548.8.8.8192.168.2.14
    Oct 8, 2024 20:20:25.998733044 CEST3530553192.168.2.148.8.8.8
    Oct 8, 2024 20:20:26.008369923 CEST53353058.8.8.8192.168.2.14
    Oct 8, 2024 20:20:26.009068966 CEST5639153192.168.2.148.8.8.8
    Oct 8, 2024 20:20:26.015908957 CEST53563918.8.8.8192.168.2.14
    Oct 8, 2024 20:20:26.016515017 CEST3408153192.168.2.148.8.8.8
    Oct 8, 2024 20:20:26.022845030 CEST53340818.8.8.8192.168.2.14
    Oct 8, 2024 20:20:26.023590088 CEST5272953192.168.2.148.8.8.8
    Oct 8, 2024 20:20:26.030278921 CEST53527298.8.8.8192.168.2.14
    Oct 8, 2024 20:20:26.031186104 CEST4894253192.168.2.148.8.8.8
    Oct 8, 2024 20:20:26.037839890 CEST53489428.8.8.8192.168.2.14
    Oct 8, 2024 20:20:26.038435936 CEST3790253192.168.2.148.8.8.8
    Oct 8, 2024 20:20:26.045129061 CEST53379028.8.8.8192.168.2.14
    Oct 8, 2024 20:20:26.045814991 CEST4466353192.168.2.148.8.8.8
    Oct 8, 2024 20:20:26.052700043 CEST53446638.8.8.8192.168.2.14
    Oct 8, 2024 20:20:27.528486013 CEST3382053192.168.2.14116.203.104.203
    Oct 8, 2024 20:20:27.541825056 CEST5333820116.203.104.203192.168.2.14
    Oct 8, 2024 20:20:27.542772055 CEST5589053192.168.2.14116.203.104.203
    Oct 8, 2024 20:20:27.552789927 CEST5355890116.203.104.203192.168.2.14
    Oct 8, 2024 20:20:27.553750992 CEST533205353192.168.2.14116.203.104.203
    Oct 8, 2024 20:20:28.104345083 CEST535353320116.203.104.203192.168.2.14
    Oct 8, 2024 20:20:28.105355978 CEST518205353192.168.2.14130.61.69.123
    Oct 8, 2024 20:20:33.110677004 CEST473405353192.168.2.14130.61.64.122
    Oct 8, 2024 20:20:38.113682032 CEST358555353192.168.2.14130.61.69.123
    Oct 8, 2024 20:20:43.119775057 CEST432535353192.168.2.14116.203.104.203
    Oct 8, 2024 20:20:43.670248985 CEST535343253116.203.104.203192.168.2.14
    Oct 8, 2024 20:20:43.672161102 CEST5703053192.168.2.1454.36.111.116
    Oct 8, 2024 20:20:43.679327011 CEST389415353192.168.2.14192.3.165.37
    Oct 8, 2024 20:20:44.161928892 CEST535338941192.3.165.37192.168.2.14
    Oct 8, 2024 20:20:44.163414955 CEST448755353192.168.2.14185.84.81.194
    Oct 8, 2024 20:20:44.688043118 CEST535344875185.84.81.194192.168.2.14
    Oct 8, 2024 20:20:44.689743042 CEST340635353192.168.2.14130.61.64.122
    Oct 8, 2024 20:20:49.692643881 CEST3875853192.168.2.14162.243.19.47
    Oct 8, 2024 20:20:49.780920982 CEST5338758162.243.19.47192.168.2.14
    Oct 8, 2024 20:20:49.782166004 CEST5556853192.168.2.148.8.8.8
    Oct 8, 2024 20:20:49.788589954 CEST53555688.8.8.8192.168.2.14
    Oct 8, 2024 20:20:49.789650917 CEST3631953192.168.2.148.8.8.8
    Oct 8, 2024 20:20:49.795938015 CEST53363198.8.8.8192.168.2.14
    Oct 8, 2024 20:20:49.797028065 CEST5673453192.168.2.148.8.8.8
    Oct 8, 2024 20:20:49.803431034 CEST53567348.8.8.8192.168.2.14
    Oct 8, 2024 20:20:49.804451942 CEST5749053192.168.2.148.8.8.8
    Oct 8, 2024 20:20:49.811760902 CEST53574908.8.8.8192.168.2.14
    Oct 8, 2024 20:20:49.812952042 CEST3832753192.168.2.148.8.8.8
    Oct 8, 2024 20:20:49.819536924 CEST53383278.8.8.8192.168.2.14
    Oct 8, 2024 20:20:49.820633888 CEST5932353192.168.2.148.8.8.8
    Oct 8, 2024 20:20:49.827713966 CEST53593238.8.8.8192.168.2.14
    Oct 8, 2024 20:20:49.828922987 CEST4248053192.168.2.148.8.8.8
    Oct 8, 2024 20:20:49.836491108 CEST53424808.8.8.8192.168.2.14
    Oct 8, 2024 20:20:49.837496042 CEST3566853192.168.2.148.8.8.8
    Oct 8, 2024 20:20:49.844433069 CEST53356688.8.8.8192.168.2.14
    Oct 8, 2024 20:20:49.845491886 CEST4860453192.168.2.148.8.8.8
    Oct 8, 2024 20:20:49.852263927 CEST53486048.8.8.8192.168.2.14
    Oct 8, 2024 20:20:49.853162050 CEST5800553192.168.2.148.8.8.8
    Oct 8, 2024 20:20:49.859569073 CEST53580058.8.8.8192.168.2.14
    Oct 8, 2024 20:20:51.347414970 CEST4168353192.168.2.14192.3.165.37
    Oct 8, 2024 20:20:51.442116976 CEST5341683192.3.165.37192.168.2.14
    Oct 8, 2024 20:20:51.443342924 CEST4851353192.168.2.14116.203.104.203
    Oct 8, 2024 20:20:51.455539942 CEST5348513116.203.104.203192.168.2.14
    Oct 8, 2024 20:20:51.456608057 CEST331185353192.168.2.14130.61.64.122
    Oct 8, 2024 20:20:56.461132050 CEST4760553192.168.2.14192.3.165.37
    Oct 8, 2024 20:20:56.715090036 CEST5347605192.3.165.37192.168.2.14
    Oct 8, 2024 20:20:56.716491938 CEST3496953192.168.2.14192.3.165.37
    Oct 8, 2024 20:20:56.809453011 CEST5334969192.3.165.37192.168.2.14
    Oct 8, 2024 20:20:56.810951948 CEST3586753192.168.2.14130.61.64.122
    Oct 8, 2024 20:20:56.818171978 CEST5335867130.61.64.122192.168.2.14
    Oct 8, 2024 20:20:56.819364071 CEST331905353192.168.2.14116.203.104.203
    Oct 8, 2024 20:20:57.382746935 CEST535333190116.203.104.203192.168.2.14
    Oct 8, 2024 20:20:57.384193897 CEST526085353192.168.2.14116.203.104.203
    Oct 8, 2024 20:20:57.932131052 CEST535352608116.203.104.203192.168.2.14
    Oct 8, 2024 20:20:57.933525085 CEST5133253192.168.2.14185.84.81.194
    Oct 8, 2024 20:20:57.944401026 CEST5351332185.84.81.194192.168.2.14
    Oct 8, 2024 20:20:57.945282936 CEST561455353192.168.2.14116.203.104.203
    Oct 8, 2024 20:20:58.484025955 CEST535356145116.203.104.203192.168.2.14
    Oct 8, 2024 20:20:58.485313892 CEST3296953192.168.2.14130.61.69.123
    Oct 8, 2024 20:20:58.492290020 CEST5332969130.61.69.123192.168.2.14
    Oct 8, 2024 20:20:58.493094921 CEST390985353192.168.2.14185.84.81.194
    Oct 8, 2024 20:20:59.024666071 CEST535339098185.84.81.194192.168.2.14
    Oct 8, 2024 20:20:59.025871992 CEST5617153192.168.2.148.8.8.8
    Oct 8, 2024 20:20:59.032149076 CEST53561718.8.8.8192.168.2.14
    Oct 8, 2024 20:20:59.032972097 CEST4099253192.168.2.148.8.8.8
    Oct 8, 2024 20:20:59.039442062 CEST53409928.8.8.8192.168.2.14
    Oct 8, 2024 20:20:59.040292025 CEST3813353192.168.2.148.8.8.8
    Oct 8, 2024 20:20:59.047205925 CEST53381338.8.8.8192.168.2.14
    Oct 8, 2024 20:20:59.048290014 CEST4724053192.168.2.148.8.8.8
    Oct 8, 2024 20:20:59.054913998 CEST53472408.8.8.8192.168.2.14
    Oct 8, 2024 20:20:59.055947065 CEST5882853192.168.2.148.8.8.8
    Oct 8, 2024 20:20:59.062561989 CEST53588288.8.8.8192.168.2.14
    Oct 8, 2024 20:20:59.063580036 CEST3489253192.168.2.148.8.8.8
    Oct 8, 2024 20:20:59.070183039 CEST53348928.8.8.8192.168.2.14
    Oct 8, 2024 20:20:59.071166992 CEST5476253192.168.2.148.8.8.8
    Oct 8, 2024 20:20:59.077792883 CEST53547628.8.8.8192.168.2.14
    Oct 8, 2024 20:20:59.078754902 CEST4908953192.168.2.148.8.8.8
    Oct 8, 2024 20:20:59.085407972 CEST53490898.8.8.8192.168.2.14
    Oct 8, 2024 20:20:59.086365938 CEST4429253192.168.2.148.8.8.8
    Oct 8, 2024 20:20:59.093630075 CEST53442928.8.8.8192.168.2.14
    Oct 8, 2024 20:20:59.094623089 CEST4103953192.168.2.148.8.8.8
    Oct 8, 2024 20:20:59.101254940 CEST53410398.8.8.8192.168.2.14
    Oct 8, 2024 20:21:00.800580978 CEST3820253192.168.2.14130.61.69.123
    Oct 8, 2024 20:21:00.808069944 CEST5338202130.61.69.123192.168.2.14
    Oct 8, 2024 20:21:00.808980942 CEST3488653192.168.2.14161.97.219.84
    Oct 8, 2024 20:21:00.994215965 CEST5334886161.97.219.84192.168.2.14
    Oct 8, 2024 20:21:00.995496988 CEST4998353192.168.2.14116.203.104.203
    Oct 8, 2024 20:21:01.008327007 CEST5349983116.203.104.203192.168.2.14
    Oct 8, 2024 20:21:01.009392023 CEST381775353192.168.2.14116.203.104.203
    Oct 8, 2024 20:21:01.549860001 CEST535338177116.203.104.203192.168.2.14
    Oct 8, 2024 20:21:01.551254034 CEST5794453192.168.2.14162.243.19.47
    Oct 8, 2024 20:21:01.646045923 CEST5357944162.243.19.47192.168.2.14
    Oct 8, 2024 20:21:01.647310972 CEST3681953192.168.2.14162.243.19.47
    Oct 8, 2024 20:21:01.732405901 CEST5336819162.243.19.47192.168.2.14
    Oct 8, 2024 20:21:01.733743906 CEST328325353192.168.2.14192.3.165.37
    Oct 8, 2024 20:21:02.215987921 CEST535332832192.3.165.37192.168.2.14
    Oct 8, 2024 20:21:02.217674017 CEST337775353192.168.2.1463.231.92.27
    Oct 8, 2024 20:21:02.790657043 CEST53533377763.231.92.27192.168.2.14
    Oct 8, 2024 20:21:02.791832924 CEST5483353192.168.2.14162.243.19.47
    Oct 8, 2024 20:21:03.396605015 CEST5354833162.243.19.47192.168.2.14
    Oct 8, 2024 20:21:03.397970915 CEST453535353192.168.2.14130.61.69.123
    Oct 8, 2024 20:21:08.401266098 CEST537295353192.168.2.1454.36.111.116
    Oct 8, 2024 20:21:13.405407906 CEST5773853192.168.2.14161.97.219.84
    Oct 8, 2024 20:21:13.593156099 CEST5357738161.97.219.84192.168.2.14
    Oct 8, 2024 20:21:13.594742060 CEST4072353192.168.2.148.8.8.8
    Oct 8, 2024 20:21:13.602981091 CEST53407238.8.8.8192.168.2.14
    Oct 8, 2024 20:21:13.604020119 CEST3445353192.168.2.148.8.8.8
    Oct 8, 2024 20:21:13.611471891 CEST53344538.8.8.8192.168.2.14
    Oct 8, 2024 20:21:13.612463951 CEST4052553192.168.2.148.8.8.8
    Oct 8, 2024 20:21:13.620152950 CEST53405258.8.8.8192.168.2.14
    Oct 8, 2024 20:21:13.621126890 CEST5944553192.168.2.148.8.8.8
    Oct 8, 2024 20:21:13.629000902 CEST53594458.8.8.8192.168.2.14
    Oct 8, 2024 20:21:13.629873037 CEST3654753192.168.2.148.8.8.8
    Oct 8, 2024 20:21:13.636547089 CEST53365478.8.8.8192.168.2.14
    Oct 8, 2024 20:21:13.638679981 CEST5127853192.168.2.148.8.8.8
    Oct 8, 2024 20:21:13.645260096 CEST53512788.8.8.8192.168.2.14
    Oct 8, 2024 20:21:13.646039963 CEST5743653192.168.2.148.8.8.8
    Oct 8, 2024 20:21:13.652364016 CEST53574368.8.8.8192.168.2.14
    Oct 8, 2024 20:21:13.653098106 CEST5688953192.168.2.148.8.8.8
    Oct 8, 2024 20:21:13.659559965 CEST53568898.8.8.8192.168.2.14
    Oct 8, 2024 20:21:13.660479069 CEST4415853192.168.2.148.8.8.8
    Oct 8, 2024 20:21:13.666831970 CEST53441588.8.8.8192.168.2.14
    Oct 8, 2024 20:21:13.667658091 CEST3396453192.168.2.148.8.8.8
    Oct 8, 2024 20:21:13.673963070 CEST53339648.8.8.8192.168.2.14
    Oct 8, 2024 20:21:15.165838957 CEST394785353192.168.2.14185.84.81.194
    Oct 8, 2024 20:21:16.009663105 CEST535339478185.84.81.194192.168.2.14
    Oct 8, 2024 20:21:16.011054039 CEST5462353192.168.2.14116.203.104.203
    Oct 8, 2024 20:21:16.022658110 CEST5354623116.203.104.203192.168.2.14
    Oct 8, 2024 20:21:16.023665905 CEST3731953192.168.2.14130.61.64.122
    Oct 8, 2024 20:21:16.032110929 CEST5337319130.61.64.122192.168.2.14
    Oct 8, 2024 20:21:16.032900095 CEST408065353192.168.2.14130.61.64.122
    Oct 8, 2024 20:21:21.039083958 CEST440435353192.168.2.14116.203.104.203
    Oct 8, 2024 20:21:22.265096903 CEST535344043116.203.104.203192.168.2.14
    Oct 8, 2024 20:21:22.266781092 CEST407235353192.168.2.14116.203.104.203
    Oct 8, 2024 20:21:22.813466072 CEST535340723116.203.104.203192.168.2.14
    Oct 8, 2024 20:21:22.814754963 CEST586025353192.168.2.1463.231.92.27
    Oct 8, 2024 20:21:23.438535929 CEST53535860263.231.92.27192.168.2.14
    Oct 8, 2024 20:21:23.439995050 CEST3750653192.168.2.1454.36.111.116
    Oct 8, 2024 20:21:23.447798967 CEST3859453192.168.2.14130.61.64.122
    Oct 8, 2024 20:21:23.455792904 CEST5338594130.61.64.122192.168.2.14
    Oct 8, 2024 20:21:23.456909895 CEST566715353192.168.2.14162.243.19.47
    Oct 8, 2024 20:21:28.464844942 CEST3515953192.168.2.14192.3.165.37
    Oct 8, 2024 20:21:28.891568899 CEST5335159192.3.165.37192.168.2.14
    Oct 8, 2024 20:21:28.894387007 CEST354335353192.168.2.14116.203.104.203
    Oct 8, 2024 20:21:29.558475018 CEST535335433116.203.104.203192.168.2.14
    Oct 8, 2024 20:21:29.560635090 CEST4034953192.168.2.148.8.8.8
    Oct 8, 2024 20:21:29.965619087 CEST53403498.8.8.8192.168.2.14
    Oct 8, 2024 20:21:29.967777014 CEST4013753192.168.2.148.8.8.8
    Oct 8, 2024 20:21:29.974853039 CEST53401378.8.8.8192.168.2.14
    Oct 8, 2024 20:21:29.975598097 CEST3787053192.168.2.148.8.8.8
    Oct 8, 2024 20:21:29.981831074 CEST53378708.8.8.8192.168.2.14
    Oct 8, 2024 20:21:29.982559919 CEST5603853192.168.2.148.8.8.8
    Oct 8, 2024 20:21:29.989073038 CEST53560388.8.8.8192.168.2.14
    Oct 8, 2024 20:21:29.990434885 CEST5475753192.168.2.148.8.8.8
    Oct 8, 2024 20:21:29.997533083 CEST53547578.8.8.8192.168.2.14
    Oct 8, 2024 20:21:29.999114037 CEST3756853192.168.2.148.8.8.8
    Oct 8, 2024 20:21:30.006899118 CEST53375688.8.8.8192.168.2.14
    Oct 8, 2024 20:21:30.008266926 CEST4422053192.168.2.148.8.8.8
    Oct 8, 2024 20:21:30.014919996 CEST53442208.8.8.8192.168.2.14
    Oct 8, 2024 20:21:30.016427994 CEST4745453192.168.2.148.8.8.8
    Oct 8, 2024 20:21:30.022896051 CEST53474548.8.8.8192.168.2.14
    Oct 8, 2024 20:21:30.024295092 CEST6024753192.168.2.148.8.8.8
    Oct 8, 2024 20:21:30.030936956 CEST53602478.8.8.8192.168.2.14
    Oct 8, 2024 20:21:30.032936096 CEST4961053192.168.2.148.8.8.8
    Oct 8, 2024 20:21:30.039921999 CEST53496108.8.8.8192.168.2.14
    Oct 8, 2024 20:21:31.055622101 CEST4442253192.168.2.14162.243.19.47
    Oct 8, 2024 20:21:31.148807049 CEST5344422162.243.19.47192.168.2.14
    Oct 8, 2024 20:21:31.149867058 CEST5165553192.168.2.14161.97.219.84
    Oct 8, 2024 20:21:31.338769913 CEST5351655161.97.219.84192.168.2.14
    Oct 8, 2024 20:21:31.341202021 CEST4400353192.168.2.14130.61.69.123
    Oct 8, 2024 20:21:31.349564075 CEST5344003130.61.69.123192.168.2.14
    Oct 8, 2024 20:21:31.350853920 CEST538165353192.168.2.14130.61.69.123
    Oct 8, 2024 20:21:36.355684042 CEST506495353192.168.2.14130.61.64.122
    Oct 8, 2024 20:21:41.359081984 CEST5997453192.168.2.1463.231.92.27
    Oct 8, 2024 20:21:41.505295992 CEST535997463.231.92.27192.168.2.14
    Oct 8, 2024 20:21:41.506524086 CEST3915053192.168.2.14192.3.165.37
    Oct 8, 2024 20:21:41.612451077 CEST5339150192.3.165.37192.168.2.14
    Oct 8, 2024 20:21:41.613893986 CEST5432553192.168.2.1454.36.111.116
    Oct 8, 2024 20:21:41.620345116 CEST5462153192.168.2.1463.231.92.27
    Oct 8, 2024 20:21:41.769054890 CEST535462163.231.92.27192.168.2.14
    Oct 8, 2024 20:21:41.770298004 CEST5419753192.168.2.14130.61.64.122
    Oct 8, 2024 20:21:41.779650927 CEST5354197130.61.64.122192.168.2.14
    Oct 8, 2024 20:21:41.780842066 CEST591005353192.168.2.14192.3.165.37
    Oct 8, 2024 20:21:42.261579037 CEST535359100192.3.165.37192.168.2.14
    Oct 8, 2024 20:21:42.263192892 CEST4444653192.168.2.14192.3.165.37
    Oct 8, 2024 20:21:42.368673086 CEST5344446192.3.165.37192.168.2.14
    Oct 8, 2024 20:21:42.369926929 CEST4029453192.168.2.148.8.8.8
    Oct 8, 2024 20:21:42.376421928 CEST53402948.8.8.8192.168.2.14
    Oct 8, 2024 20:21:42.377404928 CEST5227253192.168.2.148.8.8.8
    Oct 8, 2024 20:21:42.383863926 CEST53522728.8.8.8192.168.2.14
    Oct 8, 2024 20:21:42.384810925 CEST5453153192.168.2.148.8.8.8
    Oct 8, 2024 20:21:42.390993118 CEST53545318.8.8.8192.168.2.14
    Oct 8, 2024 20:21:42.391942024 CEST5663453192.168.2.148.8.8.8
    Oct 8, 2024 20:21:42.398338079 CEST53566348.8.8.8192.168.2.14
    Oct 8, 2024 20:21:42.399290085 CEST5090153192.168.2.148.8.8.8
    Oct 8, 2024 20:21:42.406636000 CEST53509018.8.8.8192.168.2.14
    Oct 8, 2024 20:21:42.407660961 CEST3858553192.168.2.148.8.8.8
    Oct 8, 2024 20:21:42.414947987 CEST53385858.8.8.8192.168.2.14
    Oct 8, 2024 20:21:42.415918112 CEST3332653192.168.2.148.8.8.8
    Oct 8, 2024 20:21:42.423352957 CEST53333268.8.8.8192.168.2.14
    Oct 8, 2024 20:21:42.424295902 CEST5943653192.168.2.148.8.8.8
    Oct 8, 2024 20:21:42.432316065 CEST53594368.8.8.8192.168.2.14
    Oct 8, 2024 20:21:42.433295965 CEST4126753192.168.2.148.8.8.8
    Oct 8, 2024 20:21:42.439754009 CEST53412678.8.8.8192.168.2.14
    Oct 8, 2024 20:21:42.440684080 CEST4222953192.168.2.148.8.8.8
    Oct 8, 2024 20:21:42.447081089 CEST53422298.8.8.8192.168.2.14
    Oct 8, 2024 20:21:43.932143927 CEST545155353192.168.2.1454.36.111.116
    Oct 8, 2024 20:21:48.938949108 CEST4489553192.168.2.14130.61.64.122
    Oct 8, 2024 20:21:48.947310925 CEST5344895130.61.64.122192.168.2.14
    Oct 8, 2024 20:21:48.948759079 CEST566725353192.168.2.14130.61.69.123
    Oct 8, 2024 20:21:53.952384949 CEST450915353192.168.2.14116.203.104.203
    Oct 8, 2024 20:21:54.529213905 CEST535345091116.203.104.203192.168.2.14
    Oct 8, 2024 20:21:54.530980110 CEST5829853192.168.2.14185.84.81.194
    Oct 8, 2024 20:21:54.541337013 CEST5358298185.84.81.194192.168.2.14
    Oct 8, 2024 20:21:54.542673111 CEST371035353192.168.2.1454.36.111.116
    Oct 8, 2024 20:21:59.549328089 CEST457965353192.168.2.14130.61.64.122
    Oct 8, 2024 20:22:04.554044008 CEST331575353192.168.2.1454.36.111.116
    Oct 8, 2024 20:22:09.560681105 CEST3990253192.168.2.14130.61.69.123
    Oct 8, 2024 20:22:09.567987919 CEST5339902130.61.69.123192.168.2.14
    Oct 8, 2024 20:22:09.569088936 CEST4528453192.168.2.1463.231.92.27
    Oct 8, 2024 20:22:09.716829062 CEST534528463.231.92.27192.168.2.14
    Oct 8, 2024 20:22:09.718280077 CEST5263453192.168.2.14185.84.81.194
    Oct 8, 2024 20:22:09.729362011 CEST5352634185.84.81.194192.168.2.14
    Oct 8, 2024 20:22:09.730479956 CEST579505353192.168.2.14162.243.19.47
    Oct 8, 2024 20:22:14.734802961 CEST5656653192.168.2.148.8.8.8
    Oct 8, 2024 20:22:14.741763115 CEST53565668.8.8.8192.168.2.14
    Oct 8, 2024 20:22:14.742727041 CEST4005853192.168.2.148.8.8.8
    Oct 8, 2024 20:22:14.750847101 CEST53400588.8.8.8192.168.2.14
    Oct 8, 2024 20:22:14.751638889 CEST3961753192.168.2.148.8.8.8
    Oct 8, 2024 20:22:14.759644985 CEST53396178.8.8.8192.168.2.14
    Oct 8, 2024 20:22:14.760427952 CEST4971953192.168.2.148.8.8.8
    Oct 8, 2024 20:22:14.767240047 CEST53497198.8.8.8192.168.2.14
    Oct 8, 2024 20:22:14.768131971 CEST5005453192.168.2.148.8.8.8
    Oct 8, 2024 20:22:14.774918079 CEST53500548.8.8.8192.168.2.14
    Oct 8, 2024 20:22:14.775957108 CEST4984653192.168.2.148.8.8.8
    Oct 8, 2024 20:22:14.782553911 CEST53498468.8.8.8192.168.2.14
    Oct 8, 2024 20:22:14.783574104 CEST4633953192.168.2.148.8.8.8
    Oct 8, 2024 20:22:14.790153027 CEST53463398.8.8.8192.168.2.14
    Oct 8, 2024 20:22:14.791421890 CEST4557853192.168.2.148.8.8.8
    Oct 8, 2024 20:22:14.799017906 CEST53455788.8.8.8192.168.2.14
    Oct 8, 2024 20:22:14.800326109 CEST4740253192.168.2.148.8.8.8
    Oct 8, 2024 20:22:14.807483912 CEST53474028.8.8.8192.168.2.14
    Oct 8, 2024 20:22:14.808465958 CEST5881453192.168.2.148.8.8.8
    Oct 8, 2024 20:22:14.814989090 CEST53588148.8.8.8192.168.2.14
    Oct 8, 2024 20:22:16.282881021 CEST3449253192.168.2.14116.203.104.203
    Oct 8, 2024 20:22:16.293931007 CEST5334492116.203.104.203192.168.2.14
    Oct 8, 2024 20:22:16.295285940 CEST5812553192.168.2.14130.61.69.123
    Oct 8, 2024 20:22:16.303002119 CEST5358125130.61.69.123192.168.2.14
    Oct 8, 2024 20:22:16.304280996 CEST5169253192.168.2.1454.36.111.116
    Oct 8, 2024 20:22:16.311481953 CEST4122153192.168.2.14130.61.64.122
    Oct 8, 2024 20:22:16.318576097 CEST5341221130.61.64.122192.168.2.14
    Oct 8, 2024 20:22:16.319652081 CEST3872353192.168.2.14116.203.104.203
    Oct 8, 2024 20:22:16.330110073 CEST5338723116.203.104.203192.168.2.14
    Oct 8, 2024 20:22:16.331590891 CEST5272353192.168.2.1454.36.111.116
    Oct 8, 2024 20:22:16.341183901 CEST572755353192.168.2.14130.61.69.123
    Oct 8, 2024 20:22:20.754434109 CEST4436853192.168.2.148.8.8.8
    Oct 8, 2024 20:22:20.754586935 CEST3420953192.168.2.148.8.8.8
    Oct 8, 2024 20:22:20.761200905 CEST53443688.8.8.8192.168.2.14
    Oct 8, 2024 20:22:20.761496067 CEST53342098.8.8.8192.168.2.14
    Oct 8, 2024 20:22:21.348764896 CEST3646253192.168.2.14161.97.219.84
    Oct 8, 2024 20:22:21.536858082 CEST5336462161.97.219.84192.168.2.14
    Oct 8, 2024 20:22:21.543078899 CEST527705353192.168.2.14130.61.69.123
    Oct 8, 2024 20:22:26.545972109 CEST3868053192.168.2.1454.36.111.116
    Oct 8, 2024 20:22:26.552232981 CEST500465353192.168.2.14116.203.104.203
    Oct 8, 2024 20:22:27.114208937 CEST535350046116.203.104.203192.168.2.14
    Oct 8, 2024 20:22:27.115492105 CEST521235353192.168.2.14162.243.19.47
    Oct 8, 2024 20:22:32.118746996 CEST5049853192.168.2.148.8.8.8
    Oct 8, 2024 20:22:32.125714064 CEST53504988.8.8.8192.168.2.14
    Oct 8, 2024 20:22:32.127082109 CEST5062353192.168.2.148.8.8.8
    Oct 8, 2024 20:22:32.134011030 CEST53506238.8.8.8192.168.2.14
    Oct 8, 2024 20:22:32.135212898 CEST5105753192.168.2.148.8.8.8
    Oct 8, 2024 20:22:32.143198967 CEST53510578.8.8.8192.168.2.14
    Oct 8, 2024 20:22:32.144542933 CEST5004853192.168.2.148.8.8.8
    Oct 8, 2024 20:22:32.153439999 CEST53500488.8.8.8192.168.2.14
    Oct 8, 2024 20:22:32.154838085 CEST3920253192.168.2.148.8.8.8
    Oct 8, 2024 20:22:32.162220001 CEST53392028.8.8.8192.168.2.14
    Oct 8, 2024 20:22:32.163469076 CEST4908353192.168.2.148.8.8.8
    Oct 8, 2024 20:22:32.171412945 CEST53490838.8.8.8192.168.2.14
    Oct 8, 2024 20:22:32.173027039 CEST3500753192.168.2.148.8.8.8
    Oct 8, 2024 20:22:32.180496931 CEST53350078.8.8.8192.168.2.14
    Oct 8, 2024 20:22:32.181912899 CEST3785753192.168.2.148.8.8.8
    Oct 8, 2024 20:22:32.189418077 CEST53378578.8.8.8192.168.2.14
    Oct 8, 2024 20:22:32.190607071 CEST3432553192.168.2.148.8.8.8
    Oct 8, 2024 20:22:32.197966099 CEST53343258.8.8.8192.168.2.14
    Oct 8, 2024 20:22:32.198987007 CEST3370153192.168.2.148.8.8.8
    Oct 8, 2024 20:22:32.206382990 CEST53337018.8.8.8192.168.2.14
    Oct 8, 2024 20:22:33.220758915 CEST4037053192.168.2.14116.203.104.203
    Oct 8, 2024 20:22:33.233248949 CEST5340370116.203.104.203192.168.2.14
    Oct 8, 2024 20:22:33.234226942 CEST458305353192.168.2.14192.3.165.37
    Oct 8, 2024 20:22:33.697509050 CEST535345830192.3.165.37192.168.2.14
    Oct 8, 2024 20:22:33.699328899 CEST435195353192.168.2.14162.243.19.47
    Oct 8, 2024 20:22:38.706227064 CEST4303253192.168.2.14130.61.69.123
    Oct 8, 2024 20:22:38.712991953 CEST5343032130.61.69.123192.168.2.14
    Oct 8, 2024 20:22:38.714258909 CEST4902353192.168.2.14116.203.104.203
    Oct 8, 2024 20:22:38.723984003 CEST5349023116.203.104.203192.168.2.14
    Oct 8, 2024 20:22:38.725347042 CEST3899153192.168.2.14116.203.104.203
    Oct 8, 2024 20:22:38.735179901 CEST5338991116.203.104.203192.168.2.14
    Oct 8, 2024 20:22:38.736512899 CEST568885353192.168.2.14116.203.104.203
    Oct 8, 2024 20:22:39.296905994 CEST535356888116.203.104.203192.168.2.14
    Oct 8, 2024 20:22:39.298621893 CEST335705353192.168.2.14185.84.81.194
    Oct 8, 2024 20:22:39.845391035 CEST535333570185.84.81.194192.168.2.14
    Oct 8, 2024 20:22:39.847116947 CEST478815353192.168.2.14192.3.165.37
    Oct 8, 2024 20:22:40.306348085 CEST535347881192.3.165.37192.168.2.14
    Oct 8, 2024 20:22:40.308465958 CEST4558853192.168.2.1463.231.92.27
    Oct 8, 2024 20:22:40.455329895 CEST534558863.231.92.27192.168.2.14
    Oct 8, 2024 20:22:40.457556963 CEST4498253192.168.2.14192.3.165.37
    Oct 8, 2024 20:22:40.558485985 CEST5344982192.3.165.37192.168.2.14
    Oct 8, 2024 20:22:40.561372995 CEST470125353192.168.2.14162.243.19.47
    Oct 8, 2024 20:22:45.568222046 CEST4318253192.168.2.148.8.8.8
    Oct 8, 2024 20:22:45.575251102 CEST53431828.8.8.8192.168.2.14
    Oct 8, 2024 20:22:45.576523066 CEST6018553192.168.2.148.8.8.8
    Oct 8, 2024 20:22:45.584537029 CEST53601858.8.8.8192.168.2.14
    Oct 8, 2024 20:22:45.585745096 CEST3579553192.168.2.148.8.8.8
    Oct 8, 2024 20:22:45.592187881 CEST53357958.8.8.8192.168.2.14
    Oct 8, 2024 20:22:45.593265057 CEST5149053192.168.2.148.8.8.8
    Oct 8, 2024 20:22:45.600178957 CEST53514908.8.8.8192.168.2.14
    Oct 8, 2024 20:22:45.601440907 CEST3468353192.168.2.148.8.8.8
    Oct 8, 2024 20:22:45.607706070 CEST53346838.8.8.8192.168.2.14
    Oct 8, 2024 20:22:45.608937979 CEST4381353192.168.2.148.8.8.8
    Oct 8, 2024 20:22:45.616080999 CEST53438138.8.8.8192.168.2.14
    Oct 8, 2024 20:22:45.617265940 CEST5936153192.168.2.148.8.8.8
    Oct 8, 2024 20:22:45.623949051 CEST53593618.8.8.8192.168.2.14
    Oct 8, 2024 20:22:45.625127077 CEST4430553192.168.2.148.8.8.8
    Oct 8, 2024 20:22:45.631994963 CEST53443058.8.8.8192.168.2.14
    Oct 8, 2024 20:22:45.633183002 CEST5200453192.168.2.148.8.8.8
    Oct 8, 2024 20:22:45.640497923 CEST53520048.8.8.8192.168.2.14
    Oct 8, 2024 20:22:45.641671896 CEST4672353192.168.2.148.8.8.8
    Oct 8, 2024 20:22:45.648638964 CEST53467238.8.8.8192.168.2.14
    Oct 8, 2024 20:22:47.124106884 CEST5868953192.168.2.14185.84.81.194
    Oct 8, 2024 20:22:47.134983063 CEST5358689185.84.81.194192.168.2.14
    Oct 8, 2024 20:22:47.136147976 CEST5653953192.168.2.14116.203.104.203
    Oct 8, 2024 20:22:47.146492004 CEST5356539116.203.104.203192.168.2.14
    Oct 8, 2024 20:22:47.147855997 CEST4926053192.168.2.14161.97.219.84
    Oct 8, 2024 20:22:47.335040092 CEST5349260161.97.219.84192.168.2.14
    Oct 8, 2024 20:22:47.337193012 CEST440335353192.168.2.14130.61.64.122
    Oct 8, 2024 20:22:52.343523979 CEST5400853192.168.2.14130.61.64.122
    Oct 8, 2024 20:22:52.351399899 CEST5354008130.61.64.122192.168.2.14
    Oct 8, 2024 20:22:52.352430105 CEST3347253192.168.2.14185.84.81.194
    Oct 8, 2024 20:22:52.366350889 CEST5333472185.84.81.194192.168.2.14
    Oct 8, 2024 20:22:52.367400885 CEST5816153192.168.2.14185.84.81.194
    Oct 8, 2024 20:22:52.379476070 CEST5358161185.84.81.194192.168.2.14
    Oct 8, 2024 20:22:52.380722046 CEST6091353192.168.2.14130.61.64.122
    Oct 8, 2024 20:22:52.389607906 CEST5360913130.61.64.122192.168.2.14
    Oct 8, 2024 20:22:52.390939951 CEST582045353192.168.2.14130.61.69.123
    Oct 8, 2024 20:22:57.397502899 CEST362675353192.168.2.14130.61.69.123
    Oct 8, 2024 20:23:02.403951883 CEST599015353192.168.2.14130.61.64.122
    Oct 8, 2024 20:23:07.410006046 CEST564135353192.168.2.14116.203.104.203
    Oct 8, 2024 20:23:07.959861994 CEST535356413116.203.104.203192.168.2.14
    Oct 8, 2024 20:23:07.962085009 CEST4876653192.168.2.148.8.8.8
    Oct 8, 2024 20:23:07.969052076 CEST53487668.8.8.8192.168.2.14
    Oct 8, 2024 20:23:07.970398903 CEST4769153192.168.2.148.8.8.8
    Oct 8, 2024 20:23:07.977313042 CEST53476918.8.8.8192.168.2.14
    Oct 8, 2024 20:23:07.978710890 CEST4272253192.168.2.148.8.8.8
    Oct 8, 2024 20:23:07.985136032 CEST53427228.8.8.8192.168.2.14
    Oct 8, 2024 20:23:07.986160994 CEST5069853192.168.2.148.8.8.8
    Oct 8, 2024 20:23:07.992619991 CEST53506988.8.8.8192.168.2.14
    Oct 8, 2024 20:23:07.993621111 CEST4879553192.168.2.148.8.8.8
    Oct 8, 2024 20:23:08.000884056 CEST53487958.8.8.8192.168.2.14
    Oct 8, 2024 20:23:08.002306938 CEST4236853192.168.2.148.8.8.8
    Oct 8, 2024 20:23:08.009398937 CEST53423688.8.8.8192.168.2.14
    Oct 8, 2024 20:23:08.010793924 CEST6066253192.168.2.148.8.8.8
    Oct 8, 2024 20:23:08.020190954 CEST53606628.8.8.8192.168.2.14
    Oct 8, 2024 20:23:08.021522045 CEST5881153192.168.2.148.8.8.8
    Oct 8, 2024 20:23:08.028004885 CEST53588118.8.8.8192.168.2.14
    Oct 8, 2024 20:23:08.029375076 CEST4827053192.168.2.148.8.8.8
    Oct 8, 2024 20:23:08.036195993 CEST53482708.8.8.8192.168.2.14
    Oct 8, 2024 20:23:08.037600040 CEST4461553192.168.2.148.8.8.8
    Oct 8, 2024 20:23:08.045350075 CEST53446158.8.8.8192.168.2.14
    Oct 8, 2024 20:23:09.533267975 CEST5795153192.168.2.14116.203.104.203
    Oct 8, 2024 20:23:09.546632051 CEST5357951116.203.104.203192.168.2.14
    Oct 8, 2024 20:23:09.548034906 CEST4701753192.168.2.1454.36.111.116
    Oct 8, 2024 20:23:09.557205915 CEST4893853192.168.2.14162.243.19.47
    Oct 8, 2024 20:23:09.642429113 CEST5348938162.243.19.47192.168.2.14
    Oct 8, 2024 20:23:09.644006968 CEST3929653192.168.2.14116.203.104.203
    Oct 8, 2024 20:23:09.655893087 CEST5339296116.203.104.203192.168.2.14
    Oct 8, 2024 20:23:09.657084942 CEST533985353192.168.2.14162.243.19.47
    Oct 8, 2024 20:23:14.665608883 CEST556305353192.168.2.1454.36.111.116
    TimestampSource IPDest IPChecksumCodeType
    Oct 8, 2024 20:20:11.540188074 CEST54.36.111.116192.168.2.146584(Port unreachable)Destination Unreachable
    Oct 8, 2024 20:20:43.678117037 CEST54.36.111.116192.168.2.146585(Port unreachable)Destination Unreachable
    Oct 8, 2024 20:21:23.446410894 CEST54.36.111.116192.168.2.146584(Port unreachable)Destination Unreachable
    Oct 8, 2024 20:21:41.619246960 CEST54.36.111.116192.168.2.146587(Port unreachable)Destination Unreachable
    Oct 8, 2024 20:22:16.310312986 CEST54.36.111.116192.168.2.146586(Port unreachable)Destination Unreachable
    Oct 8, 2024 20:22:16.340018034 CEST54.36.111.116192.168.2.146585(Port unreachable)Destination Unreachable
    Oct 8, 2024 20:22:26.551542997 CEST54.36.111.116192.168.2.146586(Port unreachable)Destination Unreachable
    Oct 8, 2024 20:23:09.555955887 CEST54.36.111.116192.168.2.146587(Port unreachable)Destination Unreachable
    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
    Oct 8, 2024 20:22:20.754434109 CEST192.168.2.148.8.8.80x2745Standard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
    Oct 8, 2024 20:22:20.754586935 CEST192.168.2.148.8.8.80xd145Standard query (0)daisy.ubuntu.com28IN (0x0001)false
    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
    Oct 8, 2024 20:19:40.699297905 CEST192.3.165.37192.168.2.140xc22aFormat error (1)subcarrace.indynonenoneA (IP address)IN (0x0001)false
    Oct 8, 2024 20:19:42.074065924 CEST116.203.104.203192.168.2.140xeb34Format error (1)75cents.librenonenoneA (IP address)IN (0x0001)false
    Oct 8, 2024 20:19:59.697520018 CEST116.203.104.203192.168.2.140x217eFormat error (1)fortyfivehundred.dynnonenoneA (IP address)IN (0x0001)false
    Oct 8, 2024 20:20:25.458728075 CEST63.231.92.27192.168.2.140xa0faFormat error (1)kr2ddnsnet.dynnonenoneA (IP address)IN (0x0001)false
    Oct 8, 2024 20:20:27.552789927 CEST116.203.104.203192.168.2.140x4171Format error (1)r3racegame.indynonenoneA (IP address)IN (0x0001)false
    Oct 8, 2024 20:20:56.715090036 CEST192.3.165.37192.168.2.140xb86Format error (1)subcarrace.indynonenoneA (IP address)IN (0x0001)false
    Oct 8, 2024 20:20:56.809453011 CEST192.3.165.37192.168.2.140xcde3Format error (1)subcarrace.indynonenoneA (IP address)IN (0x0001)false
    Oct 8, 2024 20:21:01.732405901 CEST162.243.19.47192.168.2.140x2783Format error (1)kr3ddnsnet1.indynonenoneA (IP address)IN (0x0001)false
    Oct 8, 2024 20:21:41.612451077 CEST192.3.165.37192.168.2.140x3753Format error (1)75cents.librenonenoneA (IP address)IN (0x0001)false
    Oct 8, 2024 20:21:42.368673086 CEST192.3.165.37192.168.2.140xd0a2Format error (1)subcarrace.indynonenoneA (IP address)IN (0x0001)false
    Oct 8, 2024 20:21:48.947310925 CEST130.61.64.122192.168.2.140x1aeaFormat error (1)r3racegame.indynonenoneA (IP address)IN (0x0001)false
    Oct 8, 2024 20:22:09.716829062 CEST63.231.92.27192.168.2.140x8edeFormat error (1)kr2ddnsnet.dynnonenoneA (IP address)IN (0x0001)false
    Oct 8, 2024 20:22:20.761200905 CEST8.8.8.8192.168.2.140x2745No error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
    Oct 8, 2024 20:22:20.761200905 CEST8.8.8.8192.168.2.140x2745No error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
    Oct 8, 2024 20:22:38.723984003 CEST116.203.104.203192.168.2.140xdb8aFormat error (1)nineteen.librenonenoneA (IP address)IN (0x0001)false
    Oct 8, 2024 20:22:38.735179901 CEST116.203.104.203192.168.2.140x6312Format error (1)eighteen.piratenonenoneA (IP address)IN (0x0001)false
    Oct 8, 2024 20:22:40.455329895 CEST63.231.92.27192.168.2.140x7b3bFormat error (1)eighteen.piratenonenoneA (IP address)IN (0x0001)false
    Oct 8, 2024 20:22:52.351399899 CEST130.61.64.122192.168.2.140x548dFormat error (1)r3racegame.indynonenoneA (IP address)IN (0x0001)false
    Oct 8, 2024 20:23:09.655893087 CEST116.203.104.203192.168.2.140xaac3Format error (1)subcarrace.indynonenoneA (IP address)IN (0x0001)false
    Session IDSource IPSource PortDestination IPDestination Port
    0192.168.2.1433104199.59.243.22780
    TimestampBytes transferredDirectionData
    Oct 8, 2024 20:19:47.373347998 CEST20OUTData Raw: 66 75 63 6b 01 32 ff ff
    Data Ascii: fuck2
    Oct 8, 2024 20:19:47.843147993 CEST219INHTTP/1.1 400 Bad request
    Content-length: 90
    Cache-Control: no-cache
    Connection: close
    Content-Type: text/html
    Data Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 72 65 71 75 65 73 74 3c 2f 68 31 3e 0a 59 6f 75 72 20 62 72 6f 77 73 65 72 20 73 65 6e 74 20 61 6e 20 69 6e 76 61 6c 69 64 20 72 65 71 75 65 73 74 2e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
    Data Ascii: <html><body><h1>400 Bad request</h1>Your browser sent an invalid request.</body></html>


    Session IDSource IPSource PortDestination IPDestination Port
    1192.168.2.1433106199.59.243.22780
    TimestampBytes transferredDirectionData
    Oct 8, 2024 20:20:11.695779085 CEST20OUTData Raw: 66 75 63 6b 01 32 ff ff
    Data Ascii: fuck2
    Oct 8, 2024 20:20:12.173404932 CEST219INHTTP/1.1 400 Bad request
    Content-length: 90
    Cache-Control: no-cache
    Connection: close
    Content-Type: text/html
    Data Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 72 65 71 75 65 73 74 3c 2f 68 31 3e 0a 59 6f 75 72 20 62 72 6f 77 73 65 72 20 73 65 6e 74 20 61 6e 20 69 6e 76 61 6c 69 64 20 72 65 71 75 65 73 74 2e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
    Data Ascii: <html><body><h1>400 Bad request</h1>Your browser sent an invalid request.</body></html>


    Session IDSource IPSource PortDestination IPDestination Port
    2192.168.2.1433108199.59.243.22780
    TimestampBytes transferredDirectionData
    Oct 8, 2024 20:20:26.059340000 CEST20OUTData Raw: 66 75 63 6b 01 32 ff ff
    Data Ascii: fuck2
    Oct 8, 2024 20:20:26.526227951 CEST219INHTTP/1.1 400 Bad request
    Content-length: 90
    Cache-Control: no-cache
    Connection: close
    Content-Type: text/html
    Data Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 72 65 71 75 65 73 74 3c 2f 68 31 3e 0a 59 6f 75 72 20 62 72 6f 77 73 65 72 20 73 65 6e 74 20 61 6e 20 69 6e 76 61 6c 69 64 20 72 65 71 75 65 73 74 2e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
    Data Ascii: <html><body><h1>400 Bad request</h1>Your browser sent an invalid request.</body></html>


    Session IDSource IPSource PortDestination IPDestination Port
    3192.168.2.1433110199.59.243.22780
    TimestampBytes transferredDirectionData
    Oct 8, 2024 20:20:49.866497993 CEST20OUTData Raw: 66 75 63 6b 01 32 ff ff
    Data Ascii: fuck2
    Oct 8, 2024 20:20:50.344234943 CEST219INHTTP/1.1 400 Bad request
    Content-length: 90
    Cache-Control: no-cache
    Connection: close
    Content-Type: text/html
    Data Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 72 65 71 75 65 73 74 3c 2f 68 31 3e 0a 59 6f 75 72 20 62 72 6f 77 73 65 72 20 73 65 6e 74 20 61 6e 20 69 6e 76 61 6c 69 64 20 72 65 71 75 65 73 74 2e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
    Data Ascii: <html><body><h1>400 Bad request</h1>Your browser sent an invalid request.</body></html>


    Session IDSource IPSource PortDestination IPDestination Port
    4192.168.2.1433112199.59.243.22780
    TimestampBytes transferredDirectionData
    Oct 8, 2024 20:20:59.109082937 CEST20OUTData Raw: 66 75 63 6b 01 32 ff ff
    Data Ascii: fuck2
    Oct 8, 2024 20:20:59.797863007 CEST219INHTTP/1.1 400 Bad request
    Content-length: 90
    Cache-Control: no-cache
    Connection: close
    Content-Type: text/html
    Data Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 72 65 71 75 65 73 74 3c 2f 68 31 3e 0a 59 6f 75 72 20 62 72 6f 77 73 65 72 20 73 65 6e 74 20 61 6e 20 69 6e 76 61 6c 69 64 20 72 65 71 75 65 73 74 2e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
    Data Ascii: <html><body><h1>400 Bad request</h1>Your browser sent an invalid request.</body></html>


    Session IDSource IPSource PortDestination IPDestination Port
    5192.168.2.1433114199.59.243.22780
    TimestampBytes transferredDirectionData
    Oct 8, 2024 20:21:13.680114985 CEST20OUTData Raw: 66 75 63 6b 01 32 ff ff
    Data Ascii: fuck2
    Oct 8, 2024 20:21:14.162556887 CEST219INHTTP/1.1 400 Bad request
    Content-length: 90
    Cache-Control: no-cache
    Connection: close
    Content-Type: text/html
    Data Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 72 65 71 75 65 73 74 3c 2f 68 31 3e 0a 59 6f 75 72 20 62 72 6f 77 73 65 72 20 73 65 6e 74 20 61 6e 20 69 6e 76 61 6c 69 64 20 72 65 71 75 65 73 74 2e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
    Data Ascii: <html><body><h1>400 Bad request</h1>Your browser sent an invalid request.</body></html>


    Session IDSource IPSource PortDestination IPDestination Port
    6192.168.2.1433116199.59.243.22780
    TimestampBytes transferredDirectionData
    Oct 8, 2024 20:21:30.048418045 CEST20OUTData Raw: 66 75 63 6b 01 32 ff ff
    Data Ascii: fuck2


    Session IDSource IPSource PortDestination IPDestination Port
    7192.168.2.1433118199.59.243.22780
    TimestampBytes transferredDirectionData
    Oct 8, 2024 20:21:42.453486919 CEST20OUTData Raw: 66 75 63 6b 01 32 ff ff
    Data Ascii: fuck2
    Oct 8, 2024 20:21:42.927510977 CEST219INHTTP/1.1 400 Bad request
    Content-length: 90
    Cache-Control: no-cache
    Connection: close
    Content-Type: text/html
    Data Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 72 65 71 75 65 73 74 3c 2f 68 31 3e 0a 59 6f 75 72 20 62 72 6f 77 73 65 72 20 73 65 6e 74 20 61 6e 20 69 6e 76 61 6c 69 64 20 72 65 71 75 65 73 74 2e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
    Data Ascii: <html><body><h1>400 Bad request</h1>Your browser sent an invalid request.</body></html>


    Session IDSource IPSource PortDestination IPDestination Port
    8192.168.2.1433120199.59.243.22780
    TimestampBytes transferredDirectionData
    Oct 8, 2024 20:22:14.822201967 CEST20OUTData Raw: 66 75 63 6b 01 32 ff ff
    Data Ascii: fuck2
    Oct 8, 2024 20:22:15.279346943 CEST219INHTTP/1.1 400 Bad request
    Content-length: 90
    Cache-Control: no-cache
    Connection: close
    Content-Type: text/html
    Data Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 72 65 71 75 65 73 74 3c 2f 68 31 3e 0a 59 6f 75 72 20 62 72 6f 77 73 65 72 20 73 65 6e 74 20 61 6e 20 69 6e 76 61 6c 69 64 20 72 65 71 75 65 73 74 2e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
    Data Ascii: <html><body><h1>400 Bad request</h1>Your browser sent an invalid request.</body></html>


    Session IDSource IPSource PortDestination IPDestination Port
    9192.168.2.1433122199.59.243.22780
    TimestampBytes transferredDirectionData
    Oct 8, 2024 20:22:32.213443995 CEST20OUTData Raw: 66 75 63 6b 01 32 ff ff
    Data Ascii: fuck2


    Session IDSource IPSource PortDestination IPDestination Port
    10192.168.2.1433124199.59.243.22780
    TimestampBytes transferredDirectionData
    Oct 8, 2024 20:22:45.655659914 CEST20OUTData Raw: 66 75 63 6b 01 32 ff ff
    Data Ascii: fuck2
    Oct 8, 2024 20:22:46.120522976 CEST219INHTTP/1.1 400 Bad request
    Content-length: 90
    Cache-Control: no-cache
    Connection: close
    Content-Type: text/html
    Data Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 72 65 71 75 65 73 74 3c 2f 68 31 3e 0a 59 6f 75 72 20 62 72 6f 77 73 65 72 20 73 65 6e 74 20 61 6e 20 69 6e 76 61 6c 69 64 20 72 65 71 75 65 73 74 2e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
    Data Ascii: <html><body><h1>400 Bad request</h1>Your browser sent an invalid request.</body></html>


    Session IDSource IPSource PortDestination IPDestination Port
    11192.168.2.1433126199.59.243.22780
    TimestampBytes transferredDirectionData
    Oct 8, 2024 20:23:08.052462101 CEST20OUTData Raw: 66 75 63 6b 01 32 ff ff
    Data Ascii: fuck2
    Oct 8, 2024 20:23:08.529373884 CEST219INHTTP/1.1 400 Bad request
    Content-length: 90
    Cache-Control: no-cache
    Connection: close
    Content-Type: text/html
    Data Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 72 65 71 75 65 73 74 3c 2f 68 31 3e 0a 59 6f 75 72 20 62 72 6f 77 73 65 72 20 73 65 6e 74 20 61 6e 20 69 6e 76 61 6c 69 64 20 72 65 71 75 65 73 74 2e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
    Data Ascii: <html><body><h1>400 Bad request</h1>Your browser sent an invalid request.</body></html>


    System Behavior

    Start time (UTC):18:19:34
    Start date (UTC):08/10/2024
    Path:/tmp/5FteLLQ1oY.elf
    Arguments:/tmp/5FteLLQ1oY.elf
    File size:5773336 bytes
    MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

    Start time (UTC):18:19:39
    Start date (UTC):08/10/2024
    Path:/tmp/5FteLLQ1oY.elf
    Arguments:-
    File size:5773336 bytes
    MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

    Start time (UTC):18:19:39
    Start date (UTC):08/10/2024
    Path:/tmp/5FteLLQ1oY.elf
    Arguments:-
    File size:5773336 bytes
    MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

    Start time (UTC):18:20:09
    Start date (UTC):08/10/2024
    Path:/usr/libexec/gnome-session-binary
    Arguments:-
    File size:334664 bytes
    MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

    Start time (UTC):18:20:09
    Start date (UTC):08/10/2024
    Path:/bin/sh
    Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/bin/gnome-shell
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):18:20:09
    Start date (UTC):08/10/2024
    Path:/usr/bin/gnome-shell
    Arguments:/usr/bin/gnome-shell
    File size:23168 bytes
    MD5 hash:da7a257239677622fe4b3a65972c9e87

    Start time (UTC):18:20:09
    Start date (UTC):08/10/2024
    Path:/usr/libexec/gnome-session-binary
    Arguments:-
    File size:334664 bytes
    MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

    Start time (UTC):18:20:09
    Start date (UTC):08/10/2024
    Path:/bin/sh
    Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):18:20:09
    Start date (UTC):08/10/2024
    Path:/usr/libexec/gsd-sharing
    Arguments:/usr/libexec/gsd-sharing
    File size:35424 bytes
    MD5 hash:e29d9025d98590fbb69f89fdbd4438b3

    Start time (UTC):18:20:10
    Start date (UTC):08/10/2024
    Path:/usr/sbin/gdm3
    Arguments:-
    File size:453296 bytes
    MD5 hash:2492e2d8d34f9377e3e530a61a15674f

    Start time (UTC):18:20:10
    Start date (UTC):08/10/2024
    Path:/etc/gdm3/PrimeOff/Default
    Arguments:/etc/gdm3/PrimeOff/Default
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):18:20:10
    Start date (UTC):08/10/2024
    Path:/usr/sbin/gdm3
    Arguments:-
    File size:453296 bytes
    MD5 hash:2492e2d8d34f9377e3e530a61a15674f

    Start time (UTC):18:20:10
    Start date (UTC):08/10/2024
    Path:/etc/gdm3/PrimeOff/Default
    Arguments:/etc/gdm3/PrimeOff/Default
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):18:20:21
    Start date (UTC):08/10/2024
    Path:/usr/lib/systemd/systemd
    Arguments:-
    File size:1620224 bytes
    MD5 hash:9b2bec7092a40488108543f9334aab75

    Start time (UTC):18:20:21
    Start date (UTC):08/10/2024
    Path:/lib/systemd/systemd-user-runtime-dir
    Arguments:/lib/systemd/systemd-user-runtime-dir stop 127
    File size:22672 bytes
    MD5 hash:d55f4b0847f88131dbcfb07435178e54