Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
WiT9fhQAMr.elf

Overview

General Information

Sample name:WiT9fhQAMr.elf
renamed because original name is a hash value
Original sample name:a6bd82aa4c66f9facb66c4c9260e3630.elf
Analysis ID:1532247
MD5:a6bd82aa4c66f9facb66c4c9260e3630
SHA1:b8547aebf037105f6915ad362fc8cf0b57eedf89
SHA256:0315df0d81d031364c86fec58531c58da99cb249fb0c0f34331e2498f9d24a73
Tags:64elfmirai
Infos:

Detection

Score:72
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Machine Learning detection for sample
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1532247
Start date and time:2024-10-12 22:48:12 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 27s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:WiT9fhQAMr.elf
renamed because original name is a hash value
Original Sample Name:a6bd82aa4c66f9facb66c4c9260e3630.elf
Detection:MAL
Classification:mal72.evad.linELF@0/0@46/0
Command:/tmp/WiT9fhQAMr.elf
PID:5486
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
listening to fbot
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
WiT9fhQAMr.elfLinux_Trojan_Gafgyt_9e9530a7unknownunknown
  • 0x68ac:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
WiT9fhQAMr.elfLinux_Trojan_Gafgyt_d4227dbfunknownunknown
  • 0x5ff6:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
  • 0x605a:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
  • 0x6125:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
WiT9fhQAMr.elfLinux_Trojan_Gafgyt_620087b9unknownunknown
  • 0x6c8d:$a: 48 89 D8 48 83 C8 01 EB 04 48 8B 76 10 48 3B 46 08 72 F6 48 8B
WiT9fhQAMr.elfLinux_Trojan_Gafgyt_33b4111aunknownunknown
  • 0x6f83:$a: C1 83 E1 0F 74 1A B8 10 00 00 00 48 29 C8 48 8D 0C 02 48 89 DA 48
WiT9fhQAMr.elfLinux_Trojan_Mirai_564b8edaunknownunknown
  • 0x37e2:$a: 83 FE 01 76 12 0F B7 07 83 EE 02 48 83 C7 02 48 01 C1 83 FE 01
SourceRuleDescriptionAuthorStrings
5486.1.0000000000400000.000000000040c000.r-x.sdmpLinux_Trojan_Gafgyt_9e9530a7unknownunknown
  • 0x68ac:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
5486.1.0000000000400000.000000000040c000.r-x.sdmpLinux_Trojan_Gafgyt_d4227dbfunknownunknown
  • 0x5ff6:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
  • 0x605a:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
  • 0x6125:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
5486.1.0000000000400000.000000000040c000.r-x.sdmpLinux_Trojan_Gafgyt_620087b9unknownunknown
  • 0x6c8d:$a: 48 89 D8 48 83 C8 01 EB 04 48 8B 76 10 48 3B 46 08 72 F6 48 8B
5486.1.0000000000400000.000000000040c000.r-x.sdmpLinux_Trojan_Gafgyt_33b4111aunknownunknown
  • 0x6f83:$a: C1 83 E1 0F 74 1A B8 10 00 00 00 48 29 C8 48 8D 0C 02 48 89 DA 48
5486.1.0000000000400000.000000000040c000.r-x.sdmpLinux_Trojan_Mirai_564b8edaunknownunknown
  • 0x37e2:$a: 83 FE 01 76 12 0F B7 07 83 EE 02 48 83 C7 02 48 01 C1 83 FE 01
Click to see the 10 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: WiT9fhQAMr.elfAvira: detected
Source: WiT9fhQAMr.elfReversingLabs: Detection: 57%
Source: WiT9fhQAMr.elfVirustotal: Detection: 39%Perma Link
Source: WiT9fhQAMr.elfJoe Sandbox ML: detected
Source: global trafficTCP traffic: 192.168.2.14:36722 -> 93.123.85.140:31337
Source: /tmp/WiT9fhQAMr.elf (PID: 5486)Socket: 127.0.0.1:21762Jump to behavior
Source: global trafficDNS traffic detected: DNS query: drumev.eu

System Summary

barindex
Source: WiT9fhQAMr.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
Source: WiT9fhQAMr.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
Source: WiT9fhQAMr.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
Source: WiT9fhQAMr.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
Source: WiT9fhQAMr.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_564b8eda Author: unknown
Source: 5486.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
Source: 5486.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
Source: 5486.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
Source: 5486.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
Source: 5486.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda Author: unknown
Source: 5489.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
Source: 5489.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
Source: 5489.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
Source: 5489.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
Source: 5489.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda Author: unknown
Source: 5487.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
Source: 5487.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
Source: 5487.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
Source: 5487.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
Source: 5487.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda Author: unknown
Source: ELF static info symbol of initial sample.symtab present: no
Source: WiT9fhQAMr.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
Source: WiT9fhQAMr.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
Source: WiT9fhQAMr.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
Source: WiT9fhQAMr.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
Source: WiT9fhQAMr.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_564b8eda reference_sample = ff04921d7bf9ca01ae33a9fc0743dce9ca250e42a33547c5665b1c9a0b5260ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 63a9e43902e7db0b7a20498b5a860e36201bacc407e9e336faca0b7cfbc37819, id = 564b8eda-6f0e-45b8-bef6-d61b0f090a36, last_modified = 2021-09-16
Source: 5486.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
Source: 5486.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
Source: 5486.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
Source: 5486.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
Source: 5486.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda reference_sample = ff04921d7bf9ca01ae33a9fc0743dce9ca250e42a33547c5665b1c9a0b5260ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 63a9e43902e7db0b7a20498b5a860e36201bacc407e9e336faca0b7cfbc37819, id = 564b8eda-6f0e-45b8-bef6-d61b0f090a36, last_modified = 2021-09-16
Source: 5489.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
Source: 5489.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
Source: 5489.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
Source: 5489.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
Source: 5489.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda reference_sample = ff04921d7bf9ca01ae33a9fc0743dce9ca250e42a33547c5665b1c9a0b5260ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 63a9e43902e7db0b7a20498b5a860e36201bacc407e9e336faca0b7cfbc37819, id = 564b8eda-6f0e-45b8-bef6-d61b0f090a36, last_modified = 2021-09-16
Source: 5487.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
Source: 5487.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
Source: 5487.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
Source: 5487.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
Source: 5487.1.0000000000400000.000000000040c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda reference_sample = ff04921d7bf9ca01ae33a9fc0743dce9ca250e42a33547c5665b1c9a0b5260ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 63a9e43902e7db0b7a20498b5a860e36201bacc407e9e336faca0b7cfbc37819, id = 564b8eda-6f0e-45b8-bef6-d61b0f090a36, last_modified = 2021-09-16
Source: classification engineClassification label: mal72.evad.linELF@0/0@46/0

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/WiT9fhQAMr.elf (PID: 5486)File: /tmp/WiT9fhQAMr.elfJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1532247 Sample: WiT9fhQAMr.elf Startdate: 12/10/2024 Architecture: LINUX Score: 72 17 drumev.eu 93.123.85.140, 31337, 36722, 36724 NET1-ASBG Bulgaria 2->17 19 Malicious sample detected (through community Yara rule) 2->19 21 Antivirus / Scanner detection for submitted sample 2->21 23 Multi AV Scanner detection for submitted file 2->23 25 Machine Learning detection for sample 2->25 8 WiT9fhQAMr.elf 2->8         started        signatures3 process4 signatures5 27 Sample deletes itself 8->27 11 WiT9fhQAMr.elf 8->11         started        13 WiT9fhQAMr.elf 8->13         started        process6 process7 15 WiT9fhQAMr.elf 11->15         started       
SourceDetectionScannerLabelLink
WiT9fhQAMr.elf58%ReversingLabsLinux.Trojan.LnxMirai
WiT9fhQAMr.elf39%VirustotalBrowse
WiT9fhQAMr.elf100%AviraEXP/ELF.Mirai.M
WiT9fhQAMr.elf100%Joe Sandbox ML
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
drumev.eu
93.123.85.140
truefalse
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    93.123.85.140
    drumev.euBulgaria
    43561NET1-ASBGfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    93.123.85.140cVtkSwoYAC.elfGet hashmaliciousGafgyt, MiraiBrowse
      5smI0bod9g.elfGet hashmaliciousGafgyt, MiraiBrowse
        YEyJiVhE6B.elfGet hashmaliciousGafgyt, MiraiBrowse
          mf3iQi8rW7.elfGet hashmaliciousGafgyt, MiraiBrowse
            RyELGNtI56.elfGet hashmaliciousGafgyt, MiraiBrowse
              QsD8ELgChf.elfGet hashmaliciousGafgyt, MiraiBrowse
                7m1uCqHKh2.elfGet hashmaliciousGafgyt, MiraiBrowse
                  52ErF0zM1V.elfGet hashmaliciousGafgyt, MiraiBrowse
                    6HDv4ZDGd5.elfGet hashmaliciousUnknownBrowse
                      3CT22jEVgR.elfGet hashmaliciousUnknownBrowse
                        No context
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        NET1-ASBGna.elfGet hashmaliciousGafgyt, MiraiBrowse
                        • 93.123.85.7
                        na.elfGet hashmaliciousMiraiBrowse
                        • 93.123.85.144
                        na.elfGet hashmaliciousMiraiBrowse
                        • 93.123.85.144
                        na.elfGet hashmaliciousMiraiBrowse
                        • 93.123.85.144
                        N0xJhHp6pc.elfGet hashmaliciousMiraiBrowse
                        • 93.123.85.144
                        x0gGYx3yGe.elfGet hashmaliciousMiraiBrowse
                        • 93.123.85.144
                        OxsKbRJ60C.elfGet hashmaliciousMiraiBrowse
                        • 93.123.85.144
                        boatnet.arm.elfGet hashmaliciousMiraiBrowse
                        • 93.123.85.144
                        boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                        • 93.123.85.144
                        boatnet.x86.elfGet hashmaliciousMiraiBrowse
                        • 93.123.85.144
                        No context
                        No context
                        No created / dropped files found
                        File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped
                        Entropy (8bit):5.545593131021595
                        TrID:
                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                        File name:WiT9fhQAMr.elf
                        File size:54'208 bytes
                        MD5:a6bd82aa4c66f9facb66c4c9260e3630
                        SHA1:b8547aebf037105f6915ad362fc8cf0b57eedf89
                        SHA256:0315df0d81d031364c86fec58531c58da99cb249fb0c0f34331e2498f9d24a73
                        SHA512:130be3f834606bd57a31e15428a2b4f99bbb6d97b5f542fac073f4a921120e1fc29506bb574baf056fed9d0738f6432f8a9104f89c891b6cab2dfb2ac4aa8136
                        SSDEEP:1536:j/Yu5/+O8LDRIeCTwjvJbiIItHlQ7Ycws:zYu5/+tLD6eCsjvJbiIc2o
                        TLSH:40330B07AA4180FDC9AEC23446BBB139D433783D1279769B6BD8FD22AE56D301F2D944
                        File Content Preview:.ELF..............>.......@.....@.......@...........@.8...@.......................@.......@....................... .......................`.......`............../........ .....Q.td....................................................H...._........H........

                        ELF header

                        Class:ELF64
                        Data:2's complement, little endian
                        Version:1 (current)
                        Machine:Advanced Micro Devices X86-64
                        Version Number:0x1
                        Type:EXEC (Executable file)
                        OS/ABI:UNIX - System V
                        ABI Version:0
                        Entry Point Address:0x400194
                        Flags:0x0
                        ELF Header Size:64
                        Program Header Offset:64
                        Program Header Size:56
                        Number of Program Headers:3
                        Section Header Offset:53568
                        Section Header Size:64
                        Number of Section Headers:10
                        Header String Table Index:9
                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                        NULL0x00x00x00x00x0000
                        .initPROGBITS0x4000e80xe80x130x00x6AX001
                        .textPROGBITS0x4001000x1000xa1b20x00x6AX0016
                        .finiPROGBITS0x40a2b20xa2b20xe0x00x6AX001
                        .rodataPROGBITS0x40a2c00xa2c00x10c80x00x2A0016
                        .ctorsPROGBITS0x60cd080xcd080x100x00x3WA008
                        .dtorsPROGBITS0x60cd180xcd180x100x00x3WA008
                        .dataPROGBITS0x60cd300xcd300x3d00x00x3WA0016
                        .bssNOBITS0x60d1000xd1000x2b880x00x3WA0032
                        .shstrtabSTRTAB0x00xd1000x3e0x00x0001
                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                        LOAD0x00x4000000x4000000xb3880xb3886.13490x5R E0x200000.init .text .fini .rodata
                        LOAD0xcd080x60cd080x60cd080x3f80x2f802.38790x6RW 0x200000.ctors .dtors .data .bss
                        GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
                        TimestampSource PortDest PortSource IPDest IP
                        Oct 12, 2024 22:49:01.508594036 CEST3672231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:01.513844967 CEST313373672293.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:01.513989925 CEST3672231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:01.514940977 CEST3672231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:01.520070076 CEST313373672293.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:01.520333052 CEST3672231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:01.525866032 CEST313373672293.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:03.175610065 CEST313373672293.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:03.176043987 CEST3672231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:03.181431055 CEST313373672293.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:04.195311069 CEST3672431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:04.200928926 CEST313373672493.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:04.201050997 CEST3672431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:04.202296972 CEST3672431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:04.208321095 CEST313373672493.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:04.208621025 CEST3672431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:04.214227915 CEST313373672493.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:05.848963976 CEST313373672493.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:05.849574089 CEST3672431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:05.855303049 CEST313373672493.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:06.866185904 CEST3672631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:06.871155977 CEST313373672693.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:06.871293068 CEST3672631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:06.872653961 CEST3672631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:06.877914906 CEST313373672693.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:06.878258944 CEST3672631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:06.883456945 CEST313373672693.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:08.522245884 CEST313373672693.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:08.522713900 CEST3672631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:08.528211117 CEST313373672693.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:09.568577051 CEST3672831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:09.573376894 CEST313373672893.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:09.573478937 CEST3672831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:09.574546099 CEST3672831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:09.579344034 CEST313373672893.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:09.579413891 CEST3672831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:09.584497929 CEST313373672893.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:11.209692955 CEST313373672893.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:11.210374117 CEST3672831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:11.215697050 CEST313373672893.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:12.225509882 CEST3673031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:12.230998039 CEST313373673093.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:12.231338978 CEST3673031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:12.233386993 CEST3673031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:12.238759995 CEST313373673093.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:12.239216089 CEST3673031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:12.244601965 CEST313373673093.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:13.860523939 CEST313373673093.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:13.861285925 CEST3673031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:13.866756916 CEST313373673093.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:14.876900911 CEST3673231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:14.882008076 CEST313373673293.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:14.882267952 CEST3673231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:14.884674072 CEST3673231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:14.889611006 CEST313373673293.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:14.889859915 CEST3673231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:14.894824028 CEST313373673293.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:16.538311958 CEST313373673293.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:16.539241076 CEST3673231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:16.544845104 CEST313373673293.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:17.553555965 CEST3673431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:17.558744907 CEST313373673493.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:17.558959007 CEST3673431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:17.560396910 CEST3673431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:17.565788984 CEST313373673493.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:17.566014051 CEST3673431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:17.571568012 CEST313373673493.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:19.190057993 CEST313373673493.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:19.190332890 CEST3673431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:19.195143938 CEST313373673493.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:20.205241919 CEST3673631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:20.210144043 CEST313373673693.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:20.210340977 CEST3673631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:20.211749077 CEST3673631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:20.216567039 CEST313373673693.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:20.216747999 CEST3673631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:20.221610069 CEST313373673693.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:21.854485989 CEST313373673693.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:21.854789019 CEST3673631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:21.860506058 CEST313373673693.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:22.871634007 CEST3673831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:22.876836061 CEST313373673893.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:22.877147913 CEST3673831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:22.878557920 CEST3673831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:22.883505106 CEST313373673893.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:22.883578062 CEST3673831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:22.888633966 CEST313373673893.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:24.501929045 CEST313373673893.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:24.502403021 CEST3673831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:24.507433891 CEST313373673893.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:25.516787052 CEST3674031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:25.744343042 CEST313373674093.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:25.744561911 CEST3674031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:25.746323109 CEST3674031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:25.751302004 CEST313373674093.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:25.751363039 CEST3674031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:25.756949902 CEST313373674093.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:27.377988100 CEST313373674093.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:27.378482103 CEST3674031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:27.383510113 CEST313373674093.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:28.389861107 CEST3674231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:28.394855022 CEST313373674293.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:28.394927025 CEST3674231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:28.396461964 CEST3674231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:28.401243925 CEST313373674293.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:28.401462078 CEST3674231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:28.406235933 CEST313373674293.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:30.112464905 CEST313373674293.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:30.112948895 CEST3674231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:30.118946075 CEST313373674293.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:31.310055017 CEST3674431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:31.315012932 CEST313373674493.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:31.315119982 CEST3674431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:31.315927029 CEST3674431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:31.320756912 CEST313373674493.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:31.320842028 CEST3674431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:31.325692892 CEST313373674493.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:32.987740993 CEST313373674493.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:32.988374949 CEST3674431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:32.993490934 CEST313373674493.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:34.002115011 CEST3674631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:34.007230043 CEST313373674693.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:34.007492065 CEST3674631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:34.009001017 CEST3674631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:34.014250994 CEST313373674693.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:34.014559031 CEST3674631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:34.020539045 CEST313373674693.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:35.642337084 CEST313373674693.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:35.642898083 CEST3674631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:35.648005962 CEST313373674693.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:36.655705929 CEST3674831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:36.661139965 CEST313373674893.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:36.661287069 CEST3674831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:36.662992001 CEST3674831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:36.668411016 CEST313373674893.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:36.668565035 CEST3674831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:36.673949003 CEST313373674893.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:38.282618999 CEST313373674893.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:38.283124924 CEST3674831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:38.288443089 CEST313373674893.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:39.297682047 CEST3675031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:39.303142071 CEST313373675093.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:39.303407907 CEST3675031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:39.305105925 CEST3675031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:39.310192108 CEST313373675093.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:39.310547113 CEST3675031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:39.316013098 CEST313373675093.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:40.923945904 CEST313373675093.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:40.924601078 CEST3675031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:40.930035114 CEST313373675093.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:41.940084934 CEST3675231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:41.945461988 CEST313373675293.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:41.945729971 CEST3675231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:41.947225094 CEST3675231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:41.952416897 CEST313373675293.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:41.952634096 CEST3675231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:41.957956076 CEST313373675293.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:43.582707882 CEST313373675293.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:43.583276033 CEST3675231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:43.588321924 CEST313373675293.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:44.597866058 CEST3675431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:44.603024960 CEST313373675493.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:44.603123903 CEST3675431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:44.605093002 CEST3675431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:44.610605955 CEST313373675493.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:44.610891104 CEST3675431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:44.616244078 CEST313373675493.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:46.236516953 CEST313373675493.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:46.237184048 CEST3675431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:46.244540930 CEST313373675493.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:47.252263069 CEST3675631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:47.257260084 CEST313373675693.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:47.257513046 CEST3675631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:47.259712934 CEST3675631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:47.265505075 CEST313373675693.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:47.265747070 CEST3675631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:47.270688057 CEST313373675693.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:48.877289057 CEST313373675693.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:48.877696991 CEST3675631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:48.882813931 CEST313373675693.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:49.891676903 CEST3675831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:49.896889925 CEST313373675893.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:49.896946907 CEST3675831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:49.898818016 CEST3675831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:49.903903008 CEST313373675893.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:49.904007912 CEST3675831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:49.909487963 CEST313373675893.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:51.695178986 CEST313373675893.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:51.695894003 CEST3675831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:51.700942039 CEST313373675893.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:52.709238052 CEST3676031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:52.714170933 CEST313373676093.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:52.714391947 CEST3676031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:52.715796947 CEST3676031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:52.720779896 CEST313373676093.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:52.721122026 CEST3676031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:52.726016998 CEST313373676093.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:54.346357107 CEST313373676093.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:54.347105026 CEST3676031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:54.352757931 CEST313373676093.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:55.364538908 CEST3676231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:55.370058060 CEST313373676293.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:55.370491028 CEST3676231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:55.373302937 CEST3676231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:55.378591061 CEST313373676293.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:55.379138947 CEST3676231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:55.384965897 CEST313373676293.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:57.839184046 CEST313373676293.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:57.839632988 CEST313373676293.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:57.839776039 CEST3676231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:57.840023994 CEST3676231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:57.840078115 CEST313373676293.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:57.840303898 CEST3676231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:57.848588943 CEST313373676293.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:57.848675013 CEST3676231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:57.854914904 CEST313373676293.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:58.855926991 CEST3676431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:58.864092112 CEST313373676493.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:58.864165068 CEST3676431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:58.866247892 CEST3676431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:58.871289015 CEST313373676493.123.85.140192.168.2.14
                        Oct 12, 2024 22:49:58.871350050 CEST3676431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:49:58.876260042 CEST313373676493.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:00.504599094 CEST313373676493.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:00.504971027 CEST3676431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:00.510464907 CEST313373676493.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:01.521092892 CEST3676631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:01.526886940 CEST313373676693.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:01.527004004 CEST3676631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:01.529340029 CEST3676631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:01.534382105 CEST313373676693.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:01.534554005 CEST3676631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:01.539609909 CEST313373676693.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:03.161663055 CEST313373676693.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:03.162026882 CEST3676631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:03.167265892 CEST313373676693.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:04.175542116 CEST3676831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:04.180851936 CEST313373676893.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:04.181096077 CEST3676831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:04.182327032 CEST3676831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:04.187402964 CEST313373676893.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:04.187480927 CEST3676831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:04.192739964 CEST313373676893.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:05.817549944 CEST313373676893.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:05.818049908 CEST3676831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:05.824204922 CEST313373676893.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:06.833256960 CEST3677031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:06.838399887 CEST313373677093.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:06.838682890 CEST3677031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:06.840126991 CEST3677031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:06.845165014 CEST313373677093.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:06.845349073 CEST3677031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:06.851187944 CEST313373677093.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:08.471451044 CEST313373677093.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:08.471942902 CEST3677031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:08.477323055 CEST313373677093.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:10.119891882 CEST3677231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:10.129323959 CEST313373677293.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:10.129426003 CEST3677231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:10.130580902 CEST3677231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:10.135360003 CEST313373677293.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:10.135433912 CEST3677231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:10.140786886 CEST313373677293.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:11.752446890 CEST313373677293.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:11.753220081 CEST3677231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:11.758604050 CEST313373677293.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:13.531127930 CEST3677431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:13.542896986 CEST313373677493.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:13.542967081 CEST3677431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:13.544677973 CEST3677431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:13.549612045 CEST313373677493.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:13.549673080 CEST3677431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:13.555039883 CEST313373677493.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:15.175694942 CEST313373677493.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:15.176048994 CEST3677431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:15.181045055 CEST313373677493.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:16.187011003 CEST3677631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:16.191849947 CEST313373677693.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:16.191951036 CEST3677631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:16.192955017 CEST3677631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:16.197890997 CEST313373677693.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:16.197962046 CEST3677631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:16.203012943 CEST313373677693.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:17.836244106 CEST313373677693.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:17.836620092 CEST3677631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:17.842118025 CEST313373677693.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:18.853120089 CEST3677831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:18.864383936 CEST313373677893.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:18.864476919 CEST3677831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:18.866091967 CEST3677831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:18.875849962 CEST313373677893.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:18.875925064 CEST3677831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:18.881252050 CEST313373677893.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:20.504945993 CEST313373677893.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:20.505454063 CEST3677831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:20.510524035 CEST313373677893.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:21.631827116 CEST3678031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:21.637541056 CEST313373678093.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:21.637897015 CEST3678031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:21.639885902 CEST3678031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:21.645260096 CEST313373678093.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:21.645477057 CEST3678031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:21.650935888 CEST313373678093.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:23.269565105 CEST313373678093.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:23.270283937 CEST3678031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:23.275492907 CEST313373678093.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:24.285083055 CEST3678231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:24.290455103 CEST313373678293.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:24.290750980 CEST3678231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:24.291825056 CEST3678231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:24.296933889 CEST313373678293.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:24.297002077 CEST3678231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:24.302270889 CEST313373678293.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:25.924719095 CEST313373678293.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:25.925246954 CEST3678231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:25.930587053 CEST313373678293.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:26.938702106 CEST3678431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:26.944219112 CEST313373678493.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:26.944650888 CEST3678431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:26.945967913 CEST3678431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:26.951282024 CEST313373678493.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:26.951378107 CEST3678431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:26.956505060 CEST313373678493.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:28.565236092 CEST313373678493.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:28.565525055 CEST3678431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:28.570554018 CEST313373678493.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:29.578785896 CEST3678631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:29.584280968 CEST313373678693.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:29.584374905 CEST3678631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:29.585809946 CEST3678631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:29.590857983 CEST313373678693.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:29.590919971 CEST3678631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:29.597858906 CEST313373678693.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:31.221725941 CEST313373678693.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:31.221999884 CEST3678631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:31.227363110 CEST313373678693.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:32.235088110 CEST3678831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:32.240547895 CEST313373678893.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:32.240755081 CEST3678831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:32.242259026 CEST3678831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:32.247519970 CEST313373678893.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:32.247756958 CEST3678831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:32.253196955 CEST313373678893.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:33.880714893 CEST313373678893.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:33.881406069 CEST3678831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:33.887593985 CEST313373678893.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:34.894742966 CEST3679031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:34.900196075 CEST313373679093.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:34.900449038 CEST3679031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:34.902090073 CEST3679031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:34.906934977 CEST313373679093.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:34.907075882 CEST3679031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:34.911938906 CEST313373679093.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:36.538924932 CEST313373679093.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:36.539526939 CEST3679031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:36.544863939 CEST313373679093.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:37.553606033 CEST3679231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:37.560077906 CEST313373679293.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:37.560151100 CEST3679231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:37.561496019 CEST3679231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:37.566370010 CEST313373679293.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:37.566433907 CEST3679231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:37.571528912 CEST313373679293.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:39.238703012 CEST313373679293.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:39.239202023 CEST3679231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:39.244441986 CEST313373679293.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:40.257188082 CEST3679431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:40.262680054 CEST313373679493.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:40.263103008 CEST3679431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:40.264874935 CEST3679431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:40.270416021 CEST313373679493.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:40.270775080 CEST3679431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:40.275985956 CEST313373679493.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:41.922209024 CEST313373679493.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:41.922698975 CEST3679431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:41.928556919 CEST313373679493.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:42.937453032 CEST3679631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:42.943002939 CEST313373679693.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:42.943372965 CEST3679631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:42.945101023 CEST3679631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:42.950177908 CEST313373679693.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:42.950402975 CEST3679631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:42.955815077 CEST313373679693.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:44.566096067 CEST313373679693.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:44.566565037 CEST3679631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:44.572947025 CEST313373679693.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:45.580718994 CEST3679831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:45.585741997 CEST313373679893.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:45.586030006 CEST3679831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:45.588438034 CEST3679831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:45.593306065 CEST313373679893.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:45.593534946 CEST3679831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:45.598474026 CEST313373679893.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:47.205549955 CEST313373679893.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:47.206147909 CEST3679831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:47.211437941 CEST313373679893.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:48.220247030 CEST3680031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:48.225152016 CEST313373680093.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:48.225269079 CEST3680031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:48.227143049 CEST3680031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:48.231971979 CEST313373680093.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:48.232100010 CEST3680031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:48.236984015 CEST313373680093.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:49.864376068 CEST313373680093.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:49.865178108 CEST3680031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:49.877949953 CEST313373680093.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:50.883028984 CEST3680231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:50.888714075 CEST313373680293.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:50.889007092 CEST3680231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:50.891053915 CEST3680231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:50.896389961 CEST313373680293.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:50.896640062 CEST3680231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:50.902302027 CEST313373680293.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:52.519126892 CEST313373680293.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:52.519820929 CEST3680231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:52.525357008 CEST313373680293.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:53.535306931 CEST3680431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:53.540857077 CEST313373680493.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:53.541091919 CEST3680431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:53.542623997 CEST3680431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:53.548188925 CEST313373680493.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:53.548530102 CEST3680431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:53.554094076 CEST313373680493.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:55.225754976 CEST313373680493.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:55.225944042 CEST3680431337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:55.230756998 CEST313373680493.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:56.236886024 CEST3680631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:56.241754055 CEST313373680693.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:56.241842031 CEST3680631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:56.242702961 CEST3680631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:56.247555971 CEST313373680693.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:56.247628927 CEST3680631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:56.252501965 CEST313373680693.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:57.862699032 CEST313373680693.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:57.862942934 CEST3680631337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:57.867810965 CEST313373680693.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:58.874445915 CEST3680831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:58.879703045 CEST313373680893.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:58.879864931 CEST3680831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:58.880980015 CEST3680831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:58.886123896 CEST313373680893.123.85.140192.168.2.14
                        Oct 12, 2024 22:50:58.886269093 CEST3680831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:50:58.891650915 CEST313373680893.123.85.140192.168.2.14
                        Oct 12, 2024 22:51:00.503478050 CEST313373680893.123.85.140192.168.2.14
                        Oct 12, 2024 22:51:00.503678083 CEST3680831337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:51:00.509181023 CEST313373680893.123.85.140192.168.2.14
                        Oct 12, 2024 22:51:01.518090010 CEST3681031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:51:01.523199081 CEST313373681093.123.85.140192.168.2.14
                        Oct 12, 2024 22:51:01.523350954 CEST3681031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:51:01.524703979 CEST3681031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:51:01.529902935 CEST313373681093.123.85.140192.168.2.14
                        Oct 12, 2024 22:51:01.530085087 CEST3681031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:51:01.535315990 CEST313373681093.123.85.140192.168.2.14
                        Oct 12, 2024 22:51:03.161659956 CEST313373681093.123.85.140192.168.2.14
                        Oct 12, 2024 22:51:03.161899090 CEST3681031337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:51:03.167305946 CEST313373681093.123.85.140192.168.2.14
                        Oct 12, 2024 22:51:04.173530102 CEST3681231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:51:04.178446054 CEST313373681293.123.85.140192.168.2.14
                        Oct 12, 2024 22:51:04.178529024 CEST3681231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:51:04.179748058 CEST3681231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:51:04.184848070 CEST313373681293.123.85.140192.168.2.14
                        Oct 12, 2024 22:51:04.184958935 CEST3681231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:51:04.190165043 CEST313373681293.123.85.140192.168.2.14
                        Oct 12, 2024 22:51:05.804176092 CEST313373681293.123.85.140192.168.2.14
                        Oct 12, 2024 22:51:05.804600000 CEST3681231337192.168.2.1493.123.85.140
                        Oct 12, 2024 22:51:05.809750080 CEST313373681293.123.85.140192.168.2.14
                        TimestampSource PortDest PortSource IPDest IP
                        Oct 12, 2024 22:49:01.493798971 CEST4760453192.168.2.148.8.8.8
                        Oct 12, 2024 22:49:01.508229017 CEST53476048.8.8.8192.168.2.14
                        Oct 12, 2024 22:49:04.181977987 CEST3872153192.168.2.148.8.8.8
                        Oct 12, 2024 22:49:04.193500996 CEST53387218.8.8.8192.168.2.14
                        Oct 12, 2024 22:49:06.853869915 CEST4393353192.168.2.148.8.8.8
                        Oct 12, 2024 22:49:06.864970922 CEST53439338.8.8.8192.168.2.14
                        Oct 12, 2024 22:49:09.529042959 CEST5970153192.168.2.148.8.8.8
                        Oct 12, 2024 22:49:09.567796946 CEST53597018.8.8.8192.168.2.14
                        Oct 12, 2024 22:49:12.215903044 CEST3676753192.168.2.148.8.8.8
                        Oct 12, 2024 22:49:12.223472118 CEST53367678.8.8.8192.168.2.14
                        Oct 12, 2024 22:49:14.866298914 CEST4086953192.168.2.148.8.8.8
                        Oct 12, 2024 22:49:14.874804974 CEST53408698.8.8.8192.168.2.14
                        Oct 12, 2024 22:49:17.544490099 CEST5264753192.168.2.148.8.8.8
                        Oct 12, 2024 22:49:17.552062988 CEST53526478.8.8.8192.168.2.14
                        Oct 12, 2024 22:49:20.193612099 CEST4772953192.168.2.148.8.8.8
                        Oct 12, 2024 22:49:20.203829050 CEST53477298.8.8.8192.168.2.14
                        Oct 12, 2024 22:49:22.858659029 CEST5628153192.168.2.148.8.8.8
                        Oct 12, 2024 22:49:22.870280027 CEST53562818.8.8.8192.168.2.14
                        Oct 12, 2024 22:49:25.507134914 CEST4827653192.168.2.148.8.8.8
                        Oct 12, 2024 22:49:25.514997959 CEST53482768.8.8.8192.168.2.14
                        Oct 12, 2024 22:49:28.382015944 CEST6044053192.168.2.148.8.8.8
                        Oct 12, 2024 22:49:28.388782978 CEST53604408.8.8.8192.168.2.14
                        Oct 12, 2024 22:49:31.115767002 CEST4711053192.168.2.148.8.8.8
                        Oct 12, 2024 22:49:31.309113026 CEST53471108.8.8.8192.168.2.14
                        Oct 12, 2024 22:49:33.993515968 CEST4864653192.168.2.148.8.8.8
                        Oct 12, 2024 22:49:34.000741959 CEST53486468.8.8.8192.168.2.14
                        Oct 12, 2024 22:49:36.646553993 CEST4911753192.168.2.148.8.8.8
                        Oct 12, 2024 22:49:36.654503107 CEST53491178.8.8.8192.168.2.14
                        Oct 12, 2024 22:49:39.288552046 CEST5016853192.168.2.148.8.8.8
                        Oct 12, 2024 22:49:39.296159029 CEST53501688.8.8.8192.168.2.14
                        Oct 12, 2024 22:49:41.930053949 CEST3542853192.168.2.148.8.8.8
                        Oct 12, 2024 22:49:41.938786030 CEST53354288.8.8.8192.168.2.14
                        Oct 12, 2024 22:49:44.588808060 CEST4332353192.168.2.148.8.8.8
                        Oct 12, 2024 22:49:44.596270084 CEST53433238.8.8.8192.168.2.14
                        Oct 12, 2024 22:49:47.242717028 CEST4598253192.168.2.148.8.8.8
                        Oct 12, 2024 22:49:47.250494003 CEST53459828.8.8.8192.168.2.14
                        Oct 12, 2024 22:49:49.882700920 CEST3323253192.168.2.148.8.8.8
                        Oct 12, 2024 22:49:49.890322924 CEST53332328.8.8.8192.168.2.14
                        Oct 12, 2024 22:49:52.700681925 CEST4657353192.168.2.148.8.8.8
                        Oct 12, 2024 22:49:52.707534075 CEST53465738.8.8.8192.168.2.14
                        Oct 12, 2024 22:49:55.353980064 CEST5901853192.168.2.148.8.8.8
                        Oct 12, 2024 22:49:55.361728907 CEST53590188.8.8.8192.168.2.14
                        Oct 12, 2024 22:49:58.846187115 CEST5282353192.168.2.148.8.8.8
                        Oct 12, 2024 22:49:58.853954077 CEST53528238.8.8.8192.168.2.14
                        Oct 12, 2024 22:50:01.511183977 CEST6044853192.168.2.148.8.8.8
                        Oct 12, 2024 22:50:01.519375086 CEST53604488.8.8.8192.168.2.14
                        Oct 12, 2024 22:50:04.166373014 CEST3990453192.168.2.148.8.8.8
                        Oct 12, 2024 22:50:04.173985004 CEST53399048.8.8.8192.168.2.14
                        Oct 12, 2024 22:50:06.823551893 CEST6056153192.168.2.148.8.8.8
                        Oct 12, 2024 22:50:06.831572056 CEST53605618.8.8.8192.168.2.14
                        Oct 12, 2024 22:50:09.476716995 CEST5316253192.168.2.148.8.8.8
                        Oct 12, 2024 22:50:10.118598938 CEST53531628.8.8.8192.168.2.14
                        Oct 12, 2024 22:50:12.757141113 CEST5605353192.168.2.148.8.8.8
                        Oct 12, 2024 22:50:13.529529095 CEST53560538.8.8.8192.168.2.14
                        Oct 12, 2024 22:50:16.179338932 CEST5642853192.168.2.148.8.8.8
                        Oct 12, 2024 22:50:16.186372042 CEST53564288.8.8.8192.168.2.14
                        Oct 12, 2024 22:50:18.840068102 CEST5524053192.168.2.148.8.8.8
                        Oct 12, 2024 22:50:18.852381945 CEST53552408.8.8.8192.168.2.14
                        Oct 12, 2024 22:50:21.510623932 CEST4335153192.168.2.148.8.8.8
                        Oct 12, 2024 22:50:21.629584074 CEST53433518.8.8.8192.168.2.14
                        Oct 12, 2024 22:50:24.276349068 CEST5574553192.168.2.148.8.8.8
                        Oct 12, 2024 22:50:24.284256935 CEST53557458.8.8.8192.168.2.14
                        Oct 12, 2024 22:50:26.929759979 CEST4491353192.168.2.148.8.8.8
                        Oct 12, 2024 22:50:26.936795950 CEST53449138.8.8.8192.168.2.14
                        Oct 12, 2024 22:50:29.569571018 CEST5946053192.168.2.148.8.8.8
                        Oct 12, 2024 22:50:29.577397108 CEST53594608.8.8.8192.168.2.14
                        Oct 12, 2024 22:50:32.225961924 CEST3583253192.168.2.148.8.8.8
                        Oct 12, 2024 22:50:32.233638048 CEST53358328.8.8.8192.168.2.14
                        Oct 12, 2024 22:50:34.886286020 CEST5422153192.168.2.148.8.8.8
                        Oct 12, 2024 22:50:34.893390894 CEST53542218.8.8.8192.168.2.14
                        Oct 12, 2024 22:50:37.545196056 CEST4818653192.168.2.148.8.8.8
                        Oct 12, 2024 22:50:37.552651882 CEST53481868.8.8.8192.168.2.14
                        Oct 12, 2024 22:50:40.244091988 CEST5450153192.168.2.148.8.8.8
                        Oct 12, 2024 22:50:40.254508972 CEST53545018.8.8.8192.168.2.14
                        Oct 12, 2024 22:50:42.927617073 CEST3383353192.168.2.148.8.8.8
                        Oct 12, 2024 22:50:42.935642004 CEST53338338.8.8.8192.168.2.14
                        Oct 12, 2024 22:50:45.570962906 CEST5420853192.168.2.148.8.8.8
                        Oct 12, 2024 22:50:45.578502893 CEST53542088.8.8.8192.168.2.14
                        Oct 12, 2024 22:50:48.212424994 CEST5533953192.168.2.148.8.8.8
                        Oct 12, 2024 22:50:48.218878031 CEST53553398.8.8.8192.168.2.14
                        Oct 12, 2024 22:50:50.873311996 CEST5713153192.168.2.148.8.8.8
                        Oct 12, 2024 22:50:50.881084919 CEST53571318.8.8.8192.168.2.14
                        Oct 12, 2024 22:50:53.526068926 CEST6009153192.168.2.148.8.8.8
                        Oct 12, 2024 22:50:53.533768892 CEST53600918.8.8.8192.168.2.14
                        Oct 12, 2024 22:50:56.228988886 CEST3372253192.168.2.148.8.8.8
                        Oct 12, 2024 22:50:56.236330986 CEST53337228.8.8.8192.168.2.14
                        Oct 12, 2024 22:50:58.866013050 CEST5101753192.168.2.148.8.8.8
                        Oct 12, 2024 22:50:58.873589039 CEST53510178.8.8.8192.168.2.14
                        Oct 12, 2024 22:51:01.509308100 CEST5095453192.168.2.148.8.8.8
                        Oct 12, 2024 22:51:01.516704082 CEST53509548.8.8.8192.168.2.14
                        Oct 12, 2024 22:51:04.165205002 CEST3976153192.168.2.148.8.8.8
                        Oct 12, 2024 22:51:04.172770023 CEST53397618.8.8.8192.168.2.14
                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                        Oct 12, 2024 22:49:01.493798971 CEST192.168.2.148.8.8.80x3040Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:04.181977987 CEST192.168.2.148.8.8.80x1196Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:06.853869915 CEST192.168.2.148.8.8.80x3fc1Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:09.529042959 CEST192.168.2.148.8.8.80x49d6Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:12.215903044 CEST192.168.2.148.8.8.80x7885Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:14.866298914 CEST192.168.2.148.8.8.80x3638Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:17.544490099 CEST192.168.2.148.8.8.80x4553Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:20.193612099 CEST192.168.2.148.8.8.80xfd91Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:22.858659029 CEST192.168.2.148.8.8.80xa618Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:25.507134914 CEST192.168.2.148.8.8.80x4716Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:28.382015944 CEST192.168.2.148.8.8.80xb974Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:31.115767002 CEST192.168.2.148.8.8.80xc2dStandard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:33.993515968 CEST192.168.2.148.8.8.80x3e75Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:36.646553993 CEST192.168.2.148.8.8.80x6c52Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:39.288552046 CEST192.168.2.148.8.8.80x1571Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:41.930053949 CEST192.168.2.148.8.8.80x8edaStandard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:44.588808060 CEST192.168.2.148.8.8.80x4579Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:47.242717028 CEST192.168.2.148.8.8.80xe615Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:49.882700920 CEST192.168.2.148.8.8.80x4ab8Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:52.700681925 CEST192.168.2.148.8.8.80x88fStandard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:55.353980064 CEST192.168.2.148.8.8.80x6bd2Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:58.846187115 CEST192.168.2.148.8.8.80xf97cStandard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:01.511183977 CEST192.168.2.148.8.8.80x192Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:04.166373014 CEST192.168.2.148.8.8.80x2edbStandard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:06.823551893 CEST192.168.2.148.8.8.80xd2b1Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:09.476716995 CEST192.168.2.148.8.8.80x1714Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:12.757141113 CEST192.168.2.148.8.8.80x89f2Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:16.179338932 CEST192.168.2.148.8.8.80x7a3bStandard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:18.840068102 CEST192.168.2.148.8.8.80x844bStandard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:21.510623932 CEST192.168.2.148.8.8.80x9099Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:24.276349068 CEST192.168.2.148.8.8.80x2bfaStandard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:26.929759979 CEST192.168.2.148.8.8.80x986Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:29.569571018 CEST192.168.2.148.8.8.80x62aStandard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:32.225961924 CEST192.168.2.148.8.8.80xbc02Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:34.886286020 CEST192.168.2.148.8.8.80xbbcaStandard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:37.545196056 CEST192.168.2.148.8.8.80xba52Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:40.244091988 CEST192.168.2.148.8.8.80x8c68Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:42.927617073 CEST192.168.2.148.8.8.80xbf66Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:45.570962906 CEST192.168.2.148.8.8.80x60c9Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:48.212424994 CEST192.168.2.148.8.8.80x8782Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:50.873311996 CEST192.168.2.148.8.8.80x971aStandard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:53.526068926 CEST192.168.2.148.8.8.80x78c6Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:56.228988886 CEST192.168.2.148.8.8.80x34Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:58.866013050 CEST192.168.2.148.8.8.80x6811Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:51:01.509308100 CEST192.168.2.148.8.8.80x8a83Standard query (0)drumev.euA (IP address)IN (0x0001)false
                        Oct 12, 2024 22:51:04.165205002 CEST192.168.2.148.8.8.80x287eStandard query (0)drumev.euA (IP address)IN (0x0001)false
                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                        Oct 12, 2024 22:49:01.508229017 CEST8.8.8.8192.168.2.140x3040No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:04.193500996 CEST8.8.8.8192.168.2.140x1196No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:06.864970922 CEST8.8.8.8192.168.2.140x3fc1No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:09.567796946 CEST8.8.8.8192.168.2.140x49d6No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:12.223472118 CEST8.8.8.8192.168.2.140x7885No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:14.874804974 CEST8.8.8.8192.168.2.140x3638No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:17.552062988 CEST8.8.8.8192.168.2.140x4553No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:20.203829050 CEST8.8.8.8192.168.2.140xfd91No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:22.870280027 CEST8.8.8.8192.168.2.140xa618No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:25.514997959 CEST8.8.8.8192.168.2.140x4716No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:28.388782978 CEST8.8.8.8192.168.2.140xb974No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:31.309113026 CEST8.8.8.8192.168.2.140xc2dNo error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:34.000741959 CEST8.8.8.8192.168.2.140x3e75No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:36.654503107 CEST8.8.8.8192.168.2.140x6c52No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:39.296159029 CEST8.8.8.8192.168.2.140x1571No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:41.938786030 CEST8.8.8.8192.168.2.140x8edaNo error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:44.596270084 CEST8.8.8.8192.168.2.140x4579No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:47.250494003 CEST8.8.8.8192.168.2.140xe615No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:49.890322924 CEST8.8.8.8192.168.2.140x4ab8No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:52.707534075 CEST8.8.8.8192.168.2.140x88fNo error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:55.361728907 CEST8.8.8.8192.168.2.140x6bd2No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:49:58.853954077 CEST8.8.8.8192.168.2.140xf97cNo error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:01.519375086 CEST8.8.8.8192.168.2.140x192No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:04.173985004 CEST8.8.8.8192.168.2.140x2edbNo error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:06.831572056 CEST8.8.8.8192.168.2.140xd2b1No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:10.118598938 CEST8.8.8.8192.168.2.140x1714No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:13.529529095 CEST8.8.8.8192.168.2.140x89f2No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:16.186372042 CEST8.8.8.8192.168.2.140x7a3bNo error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:18.852381945 CEST8.8.8.8192.168.2.140x844bNo error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:21.629584074 CEST8.8.8.8192.168.2.140x9099No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:24.284256935 CEST8.8.8.8192.168.2.140x2bfaNo error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:26.936795950 CEST8.8.8.8192.168.2.140x986No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:29.577397108 CEST8.8.8.8192.168.2.140x62aNo error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:32.233638048 CEST8.8.8.8192.168.2.140xbc02No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:34.893390894 CEST8.8.8.8192.168.2.140xbbcaNo error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:37.552651882 CEST8.8.8.8192.168.2.140xba52No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:40.254508972 CEST8.8.8.8192.168.2.140x8c68No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:42.935642004 CEST8.8.8.8192.168.2.140xbf66No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:45.578502893 CEST8.8.8.8192.168.2.140x60c9No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:48.218878031 CEST8.8.8.8192.168.2.140x8782No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:50.881084919 CEST8.8.8.8192.168.2.140x971aNo error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:53.533768892 CEST8.8.8.8192.168.2.140x78c6No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:56.236330986 CEST8.8.8.8192.168.2.140x34No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:50:58.873589039 CEST8.8.8.8192.168.2.140x6811No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:51:01.516704082 CEST8.8.8.8192.168.2.140x8a83No error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false
                        Oct 12, 2024 22:51:04.172770023 CEST8.8.8.8192.168.2.140x287eNo error (0)drumev.eu93.123.85.140A (IP address)IN (0x0001)false

                        System Behavior

                        Start time (UTC):20:49:00
                        Start date (UTC):12/10/2024
                        Path:/tmp/WiT9fhQAMr.elf
                        Arguments:/tmp/WiT9fhQAMr.elf
                        File size:54208 bytes
                        MD5 hash:a6bd82aa4c66f9facb66c4c9260e3630

                        Start time (UTC):20:49:00
                        Start date (UTC):12/10/2024
                        Path:/tmp/WiT9fhQAMr.elf
                        Arguments:-
                        File size:54208 bytes
                        MD5 hash:a6bd82aa4c66f9facb66c4c9260e3630

                        Start time (UTC):20:49:00
                        Start date (UTC):12/10/2024
                        Path:/tmp/WiT9fhQAMr.elf
                        Arguments:-
                        File size:54208 bytes
                        MD5 hash:a6bd82aa4c66f9facb66c4c9260e3630

                        Start time (UTC):20:49:00
                        Start date (UTC):12/10/2024
                        Path:/tmp/WiT9fhQAMr.elf
                        Arguments:-
                        File size:54208 bytes
                        MD5 hash:a6bd82aa4c66f9facb66c4c9260e3630