Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
tc2iriCZdi.elf

Overview

General Information

Sample name:tc2iriCZdi.elf
renamed because original name is a hash value
Original sample name:bc65b67b9d7b698cc14e918d061cc75f.elf
Analysis ID:1532760
MD5:bc65b67b9d7b698cc14e918d061cc75f
SHA1:0e5708a090c4ff4c0ca14d8f5814956e48ca1681
SHA256:62e2f7da81a6ce76239af480ef1dc843085c4df0d10d232d6a15b142e218ad2e
Tags:64elfgafgyt
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Machine Learning detection for sample
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Sample contains only a LOAD segment without any section mappings
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1532760
Start date and time:2024-10-13 21:50:34 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 23s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:tc2iriCZdi.elf
renamed because original name is a hash value
Original Sample Name:bc65b67b9d7b698cc14e918d061cc75f.elf
Detection:MAL
Classification:mal64.evad.linELF@0/0@0/0
  • VT rate limit hit for: tc2iriCZdi.elf
Command:/tmp/tc2iriCZdi.elf
PID:5454
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
5456.1.0000000000400000.0000000000413000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xfeb8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfecc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfee0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfef4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff08:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff1c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffa8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffbc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffd0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffe4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfff8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1000c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10020:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10034:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10048:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5456.1.0000000000400000.0000000000413000.r-x.sdmpLinux_Trojan_Mirai_564b8edaunknownunknown
  • 0x49b2:$a: 83 FE 01 76 12 0F B7 07 83 EE 02 48 83 C7 02 48 01 C1 83 FE 01
5455.1.0000000000400000.0000000000413000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xfeb8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfecc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfee0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfef4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff08:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff1c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffa8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffbc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffd0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffe4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfff8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1000c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10020:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10034:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10048:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5455.1.0000000000400000.0000000000413000.r-x.sdmpLinux_Trojan_Mirai_564b8edaunknownunknown
  • 0x49b2:$a: 83 FE 01 76 12 0F B7 07 83 EE 02 48 83 C7 02 48 01 C1 83 FE 01
5454.1.0000000000400000.0000000000413000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xfeb8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfecc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfee0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfef4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff08:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff1c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffa8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffbc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffd0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffe4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfff8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1000c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10020:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10034:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10048:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Click to see the 7 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: tc2iriCZdi.elfReversingLabs: Detection: 36%
Source: tc2iriCZdi.elfJoe Sandbox ML: detected
Source: global trafficTCP traffic: 192.168.2.13:37462 -> 45.131.65.138:3778
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: unknownTCP traffic detected without corresponding DNS query: 45.131.65.138
Source: tc2iriCZdi.elfString found in binary or memory: http://upx.sf.net

System Summary

barindex
Source: 5456.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5456.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda Author: unknown
Source: 5455.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5455.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda Author: unknown
Source: 5454.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5454.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda Author: unknown
Source: 5460.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5460.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda Author: unknown
Source: Process Memory Space: tc2iriCZdi.elf PID: 5454, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: tc2iriCZdi.elf PID: 5455, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: tc2iriCZdi.elf PID: 5456, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: tc2iriCZdi.elf PID: 5460, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: LOAD without section mappingsProgram segment: 0x400000
Source: 5456.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5456.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda reference_sample = ff04921d7bf9ca01ae33a9fc0743dce9ca250e42a33547c5665b1c9a0b5260ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 63a9e43902e7db0b7a20498b5a860e36201bacc407e9e336faca0b7cfbc37819, id = 564b8eda-6f0e-45b8-bef6-d61b0f090a36, last_modified = 2021-09-16
Source: 5455.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5455.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda reference_sample = ff04921d7bf9ca01ae33a9fc0743dce9ca250e42a33547c5665b1c9a0b5260ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 63a9e43902e7db0b7a20498b5a860e36201bacc407e9e336faca0b7cfbc37819, id = 564b8eda-6f0e-45b8-bef6-d61b0f090a36, last_modified = 2021-09-16
Source: 5454.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5454.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda reference_sample = ff04921d7bf9ca01ae33a9fc0743dce9ca250e42a33547c5665b1c9a0b5260ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 63a9e43902e7db0b7a20498b5a860e36201bacc407e9e336faca0b7cfbc37819, id = 564b8eda-6f0e-45b8-bef6-d61b0f090a36, last_modified = 2021-09-16
Source: 5460.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5460.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda reference_sample = ff04921d7bf9ca01ae33a9fc0743dce9ca250e42a33547c5665b1c9a0b5260ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 63a9e43902e7db0b7a20498b5a860e36201bacc407e9e336faca0b7cfbc37819, id = 564b8eda-6f0e-45b8-bef6-d61b0f090a36, last_modified = 2021-09-16
Source: Process Memory Space: tc2iriCZdi.elf PID: 5454, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: tc2iriCZdi.elf PID: 5455, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: tc2iriCZdi.elf PID: 5456, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: tc2iriCZdi.elf PID: 5460, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal64.evad.linELF@0/0@0/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/230/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/110/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/231/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/111/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/232/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/112/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/233/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/113/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/234/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/114/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/235/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/115/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/236/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/116/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/237/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/117/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/238/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/118/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/239/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/119/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/914/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/10/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/917/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/11/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/12/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/13/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/14/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/5396/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/15/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/16/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/17/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/18/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/19/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/240/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/3095/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/120/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/241/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/121/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/242/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/1/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/122/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/243/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/2/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/123/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/244/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/3/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/124/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/245/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/1588/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/125/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/4/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/246/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/126/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/5/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/247/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/127/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/6/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/248/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/128/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/7/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/249/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/129/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/8/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/800/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/9/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/1906/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/802/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/803/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/20/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/3768/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/21/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/22/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/23/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/24/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/25/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/26/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/27/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/28/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/29/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/3420/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/1482/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/490/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/1480/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/250/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/371/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/130/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/251/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/131/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/252/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/132/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/253/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/254/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/1238/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/134/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/255/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/256/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/257/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/378/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/3413/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/258/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/259/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/1475/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/936/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/30/statusJump to behavior
Source: /tmp/tc2iriCZdi.elf (PID: 5454)File opened: /proc/816/statusJump to behavior
Source: tc2iriCZdi.elfSubmission file: segment LOAD with 7.9636 entropy (max. 8.0)
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
1
OS Credential Dumping
System Service DiscoveryRemote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1532760 Sample: tc2iriCZdi.elf Startdate: 13/10/2024 Architecture: LINUX Score: 64 20 45.131.65.138, 37462, 37464, 37466 LOVESERVERSGB Germany 2->20 22 Malicious sample detected (through community Yara rule) 2->22 24 Multi AV Scanner detection for submitted file 2->24 26 Machine Learning detection for sample 2->26 28 Sample is packed with UPX 2->28 8 tc2iriCZdi.elf 2->8         started        signatures3 process4 process5 10 tc2iriCZdi.elf 8->10         started        12 tc2iriCZdi.elf 8->12         started        14 tc2iriCZdi.elf 8->14         started        process6 16 tc2iriCZdi.elf 10->16         started        18 tc2iriCZdi.elf 10->18         started       
SourceDetectionScannerLabelLink
tc2iriCZdi.elf37%ReversingLabsLinux.Backdoor.Mirai
tc2iriCZdi.elf100%Joe Sandbox ML
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://upx.sf.net0%URL Reputationsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.nettc2iriCZdi.elftrue
  • URL Reputation: safe
unknown
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
45.131.65.138
unknownGermany
47987LOVESERVERSGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
45.131.65.138LM762mO6Jt.elfGet hashmaliciousUnknownBrowse
    No context
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    LOVESERVERSGBLM762mO6Jt.elfGet hashmaliciousUnknownBrowse
    • 45.131.65.138
    M88FIQFvyo.elfGet hashmaliciousMiraiBrowse
    • 45.150.101.154
    i7b3uBlM8k.elfGet hashmaliciousMiraiBrowse
    • 45.150.101.181
    TV7RLVOmvl.elfGet hashmaliciousMiraiBrowse
    • 45.150.101.140
    dDPKtLvVp6.elfGet hashmaliciousMirai, MoobotBrowse
    • 85.9.214.159
    yCUczQYIGe.elfGet hashmaliciousMiraiBrowse
    • 45.150.101.148
    a75e3f3e506051b9e4313a407c2a993f9d662a142f2ec.exeGet hashmaliciousRHADAMANTHYS, SmokeLoader, Stealc, VidarBrowse
    • 45.131.66.61
    50GoeHHxhs.exeGet hashmaliciousDarkTortilla, Phobos, RHADAMANTHYS, SmokeLoader, SystemBCBrowse
    • 45.131.66.222
    SyuiUx2mcV.exeGet hashmaliciousDarkTortilla, Phobos, RHADAMANTHYS, SmokeLoader, SystemBCBrowse
    • 45.131.66.222
    Z8B3qXUXHu.exeGet hashmaliciousDarkTortilla, Phobos, RHADAMANTHYS, SmokeLoader, SystemBCBrowse
    • 45.131.66.222
    No context
    No context
    No created / dropped files found
    File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header
    Entropy (8bit):7.961640397781978
    TrID:
    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
    File name:tc2iriCZdi.elf
    File size:37'540 bytes
    MD5:bc65b67b9d7b698cc14e918d061cc75f
    SHA1:0e5708a090c4ff4c0ca14d8f5814956e48ca1681
    SHA256:62e2f7da81a6ce76239af480ef1dc843085c4df0d10d232d6a15b142e218ad2e
    SHA512:0b83139cef0eada4054aaa9da6ece36d4906cd1508c1abf1103b5aa1b56abcc6a36ffbdd7ccbdc96161851a278913aaf87780842d882e974f9c4729cb4e86480
    SSDEEP:768:P+4qtvWUAASjjLMGz7/tjBQd4Mt8nEPH3GgurEF4lZWx0M:29tvWrASjjL17/9BODtoPgumV
    TLSH:7CF2E1828BBDAAB4C1339B7144C785A0B73270A3DE0615BF15C835BF1979A413A33F92
    File Content Preview:.ELF..............>.....`.@.....@...................@.8...@.......................@.......@....................... ......................Ka......Ka.............................Q.td.....................................................I..UPX!D.......8:..8:.

    ELF header

    Class:ELF64
    Data:2's complement, little endian
    Version:1 (current)
    Machine:Advanced Micro Devices X86-64
    Version Number:0x1
    Type:EXEC (Executable file)
    OS/ABI:UNIX - System V
    ABI Version:0
    Entry Point Address:0x408060
    Flags:0x0
    ELF Header Size:64
    Program Header Offset:64
    Program Header Size:56
    Number of Program Headers:3
    Section Header Offset:0
    Section Header Size:64
    Number of Section Headers:0
    Header String Table Index:0
    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
    LOAD0x00x4000000x4000000x919c0x919c7.96360x5R E0x200000
    LOAD0xb000x614b000x614b000x00x00.00000x6RW 0x1000
    GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
    TimestampSource PortDest PortSource IPDest IP
    Oct 13, 2024 21:51:16.589745045 CEST374623778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:16.594858885 CEST37783746245.131.65.138192.168.2.13
    Oct 13, 2024 21:51:16.594917059 CEST374623778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:16.597178936 CEST374623778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:16.602063894 CEST37783746245.131.65.138192.168.2.13
    Oct 13, 2024 21:51:16.602118015 CEST374623778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:16.607120037 CEST37783746245.131.65.138192.168.2.13
    Oct 13, 2024 21:51:17.251174927 CEST37783746245.131.65.138192.168.2.13
    Oct 13, 2024 21:51:17.251538038 CEST374623778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:17.251538992 CEST374623778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:17.252144098 CEST374643778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:17.257194996 CEST37783746445.131.65.138192.168.2.13
    Oct 13, 2024 21:51:17.257319927 CEST374643778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:17.258141041 CEST374643778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:17.263025999 CEST37783746445.131.65.138192.168.2.13
    Oct 13, 2024 21:51:17.263205051 CEST374643778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:17.268464088 CEST37783746445.131.65.138192.168.2.13
    Oct 13, 2024 21:51:17.891325951 CEST37783746445.131.65.138192.168.2.13
    Oct 13, 2024 21:51:17.891702890 CEST374643778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:17.891776085 CEST374643778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:17.892704964 CEST374663778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:17.899877071 CEST37783746645.131.65.138192.168.2.13
    Oct 13, 2024 21:51:17.900044918 CEST374663778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:17.902096033 CEST374663778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:17.908366919 CEST37783746645.131.65.138192.168.2.13
    Oct 13, 2024 21:51:17.908549070 CEST374663778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:17.913938046 CEST37783746645.131.65.138192.168.2.13
    Oct 13, 2024 21:51:18.540689945 CEST37783746645.131.65.138192.168.2.13
    Oct 13, 2024 21:51:18.540947914 CEST374663778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:18.540949106 CEST374663778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:18.541666985 CEST374683778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:18.546681881 CEST37783746845.131.65.138192.168.2.13
    Oct 13, 2024 21:51:18.546802044 CEST374683778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:18.547679901 CEST374683778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:18.552781105 CEST37783746845.131.65.138192.168.2.13
    Oct 13, 2024 21:51:18.552845955 CEST374683778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:18.557686090 CEST37783746845.131.65.138192.168.2.13
    Oct 13, 2024 21:51:19.165736914 CEST37783746845.131.65.138192.168.2.13
    Oct 13, 2024 21:51:19.165966034 CEST374683778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:19.166029930 CEST374683778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:19.166702032 CEST374703778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:19.171688080 CEST37783747045.131.65.138192.168.2.13
    Oct 13, 2024 21:51:19.171755075 CEST374703778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:19.172589064 CEST374703778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:19.177939892 CEST37783747045.131.65.138192.168.2.13
    Oct 13, 2024 21:51:19.177989006 CEST374703778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:19.183203936 CEST37783747045.131.65.138192.168.2.13
    Oct 13, 2024 21:51:22.151951075 CEST374723778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:22.157196045 CEST37783747245.131.65.138192.168.2.13
    Oct 13, 2024 21:51:22.157253027 CEST374723778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:22.158495903 CEST374723778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:22.163605928 CEST37783747245.131.65.138192.168.2.13
    Oct 13, 2024 21:51:22.163667917 CEST374723778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:22.168956995 CEST37783747245.131.65.138192.168.2.13
    Oct 13, 2024 21:51:22.788883924 CEST37783747245.131.65.138192.168.2.13
    Oct 13, 2024 21:51:22.789021015 CEST374723778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:22.789077044 CEST374723778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:22.789757013 CEST374743778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:22.794815063 CEST37783747445.131.65.138192.168.2.13
    Oct 13, 2024 21:51:22.794883966 CEST374743778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:22.795639992 CEST374743778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:22.800548077 CEST37783747445.131.65.138192.168.2.13
    Oct 13, 2024 21:51:22.800600052 CEST374743778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:22.805702925 CEST37783747445.131.65.138192.168.2.13
    Oct 13, 2024 21:51:23.443634987 CEST37783747445.131.65.138192.168.2.13
    Oct 13, 2024 21:51:23.443800926 CEST374743778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:23.443800926 CEST374743778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:23.444428921 CEST374763778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:23.449378967 CEST37783747645.131.65.138192.168.2.13
    Oct 13, 2024 21:51:23.449470043 CEST374763778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:23.450176001 CEST374763778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:23.455457926 CEST37783747645.131.65.138192.168.2.13
    Oct 13, 2024 21:51:23.455522060 CEST374763778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:23.460649014 CEST37783747645.131.65.138192.168.2.13
    Oct 13, 2024 21:51:24.077904940 CEST37783747645.131.65.138192.168.2.13
    Oct 13, 2024 21:51:24.078246117 CEST374763778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:24.078324080 CEST374763778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:24.078990936 CEST374783778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:24.083947897 CEST37783747845.131.65.138192.168.2.13
    Oct 13, 2024 21:51:24.084131002 CEST374783778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:24.084650040 CEST374783778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:24.089467049 CEST37783747845.131.65.138192.168.2.13
    Oct 13, 2024 21:51:24.089628935 CEST374783778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:24.094500065 CEST37783747845.131.65.138192.168.2.13
    Oct 13, 2024 21:51:24.722098112 CEST37783747845.131.65.138192.168.2.13
    Oct 13, 2024 21:51:24.722485065 CEST374783778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:24.722485065 CEST374783778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:24.722935915 CEST374803778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:24.727973938 CEST37783748045.131.65.138192.168.2.13
    Oct 13, 2024 21:51:24.728032112 CEST374803778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:24.728710890 CEST374803778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:24.734883070 CEST37783748045.131.65.138192.168.2.13
    Oct 13, 2024 21:51:24.734935045 CEST374803778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:24.739732027 CEST37783748045.131.65.138192.168.2.13
    Oct 13, 2024 21:51:25.345351934 CEST37783748045.131.65.138192.168.2.13
    Oct 13, 2024 21:51:25.345487118 CEST374803778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:25.345487118 CEST374803778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:25.345990896 CEST374823778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:25.350909948 CEST37783748245.131.65.138192.168.2.13
    Oct 13, 2024 21:51:25.350980997 CEST374823778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:25.351558924 CEST374823778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:25.356362104 CEST37783748245.131.65.138192.168.2.13
    Oct 13, 2024 21:51:25.356415987 CEST374823778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:25.361213923 CEST37783748245.131.65.138192.168.2.13
    Oct 13, 2024 21:51:25.993506908 CEST37783748245.131.65.138192.168.2.13
    Oct 13, 2024 21:51:25.993840933 CEST374823778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:25.993840933 CEST374823778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:25.994304895 CEST374843778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:26.000451088 CEST37783748445.131.65.138192.168.2.13
    Oct 13, 2024 21:51:26.000519037 CEST374843778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:26.001410961 CEST374843778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:26.006225109 CEST37783748445.131.65.138192.168.2.13
    Oct 13, 2024 21:51:26.006324053 CEST374843778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:26.011344910 CEST37783748445.131.65.138192.168.2.13
    Oct 13, 2024 21:51:26.653928995 CEST37783748445.131.65.138192.168.2.13
    Oct 13, 2024 21:51:26.654175043 CEST374843778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:26.654216051 CEST374843778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:26.654800892 CEST374863778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:26.659683943 CEST37783748645.131.65.138192.168.2.13
    Oct 13, 2024 21:51:26.659795046 CEST374863778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:26.660448074 CEST374863778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:26.665550947 CEST37783748645.131.65.138192.168.2.13
    Oct 13, 2024 21:51:26.665620089 CEST374863778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:26.670500994 CEST37783748645.131.65.138192.168.2.13
    Oct 13, 2024 21:51:27.288985968 CEST37783748645.131.65.138192.168.2.13
    Oct 13, 2024 21:51:27.289135933 CEST374863778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:27.289186954 CEST374863778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:27.289820910 CEST374883778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:27.295279026 CEST37783748845.131.65.138192.168.2.13
    Oct 13, 2024 21:51:27.295452118 CEST374883778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:27.296276093 CEST374883778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:27.301249027 CEST37783748845.131.65.138192.168.2.13
    Oct 13, 2024 21:51:27.301417112 CEST374883778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:27.306502104 CEST37783748845.131.65.138192.168.2.13
    Oct 13, 2024 21:51:27.939378023 CEST37783748845.131.65.138192.168.2.13
    Oct 13, 2024 21:51:27.939665079 CEST374883778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:27.939665079 CEST374883778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:27.940592051 CEST374903778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:27.945487022 CEST37783749045.131.65.138192.168.2.13
    Oct 13, 2024 21:51:27.945564032 CEST374903778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:27.946676016 CEST374903778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:27.951580048 CEST37783749045.131.65.138192.168.2.13
    Oct 13, 2024 21:51:27.951639891 CEST374903778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:27.956587076 CEST37783749045.131.65.138192.168.2.13
    Oct 13, 2024 21:51:28.594849110 CEST37783749045.131.65.138192.168.2.13
    Oct 13, 2024 21:51:28.595097065 CEST374903778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:28.595155001 CEST374903778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:28.596276045 CEST374923778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:28.601100922 CEST37783749245.131.65.138192.168.2.13
    Oct 13, 2024 21:51:28.601207972 CEST374923778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:28.602574110 CEST374923778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:28.607443094 CEST37783749245.131.65.138192.168.2.13
    Oct 13, 2024 21:51:28.607501984 CEST374923778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:28.612339020 CEST37783749245.131.65.138192.168.2.13
    Oct 13, 2024 21:51:29.176594019 CEST374703778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:29.181649923 CEST37783747045.131.65.138192.168.2.13
    Oct 13, 2024 21:51:29.243207932 CEST37783749245.131.65.138192.168.2.13
    Oct 13, 2024 21:51:29.243398905 CEST374923778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:29.243473053 CEST374923778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:29.244637012 CEST374943778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:29.249579906 CEST37783749445.131.65.138192.168.2.13
    Oct 13, 2024 21:51:29.249674082 CEST374943778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:29.250946045 CEST374943778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:29.255759001 CEST37783749445.131.65.138192.168.2.13
    Oct 13, 2024 21:51:29.255841017 CEST374943778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:29.260658979 CEST37783749445.131.65.138192.168.2.13
    Oct 13, 2024 21:51:29.361980915 CEST37783747045.131.65.138192.168.2.13
    Oct 13, 2024 21:51:29.362121105 CEST374703778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:29.877686024 CEST37783749445.131.65.138192.168.2.13
    Oct 13, 2024 21:51:29.878083944 CEST374943778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:29.878145933 CEST374943778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:29.879316092 CEST374963778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:29.884301901 CEST37783749645.131.65.138192.168.2.13
    Oct 13, 2024 21:51:29.884396076 CEST374963778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:29.885970116 CEST374963778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:29.890872002 CEST37783749645.131.65.138192.168.2.13
    Oct 13, 2024 21:51:29.890949965 CEST374963778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:29.895884991 CEST37783749645.131.65.138192.168.2.13
    Oct 13, 2024 21:51:30.527133942 CEST37783749645.131.65.138192.168.2.13
    Oct 13, 2024 21:51:30.527425051 CEST374963778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:30.527483940 CEST374963778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:30.528522968 CEST374983778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:30.533960104 CEST37783749845.131.65.138192.168.2.13
    Oct 13, 2024 21:51:30.534024000 CEST374983778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:30.535429955 CEST374983778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:30.540426970 CEST37783749845.131.65.138192.168.2.13
    Oct 13, 2024 21:51:30.540481091 CEST374983778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:30.545398951 CEST37783749845.131.65.138192.168.2.13
    Oct 13, 2024 21:51:31.180871964 CEST37783749845.131.65.138192.168.2.13
    Oct 13, 2024 21:51:31.181061983 CEST374983778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:31.181113958 CEST374983778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:31.182329893 CEST375003778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:31.187774897 CEST37783750045.131.65.138192.168.2.13
    Oct 13, 2024 21:51:31.187879086 CEST375003778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:31.189372063 CEST375003778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:31.194282055 CEST37783750045.131.65.138192.168.2.13
    Oct 13, 2024 21:51:31.194365978 CEST375003778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:31.199330091 CEST37783750045.131.65.138192.168.2.13
    Oct 13, 2024 21:51:31.829487085 CEST37783750045.131.65.138192.168.2.13
    Oct 13, 2024 21:51:31.829657078 CEST375003778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:31.829657078 CEST375003778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:31.830651999 CEST375023778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:31.835597992 CEST37783750245.131.65.138192.168.2.13
    Oct 13, 2024 21:51:31.835676908 CEST375023778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:31.836958885 CEST375023778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:31.841818094 CEST37783750245.131.65.138192.168.2.13
    Oct 13, 2024 21:51:31.841866016 CEST375023778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:31.846736908 CEST37783750245.131.65.138192.168.2.13
    Oct 13, 2024 21:51:32.464315891 CEST37783750245.131.65.138192.168.2.13
    Oct 13, 2024 21:51:32.464595079 CEST375023778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:32.464595079 CEST375023778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:32.465620995 CEST375043778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:32.471249104 CEST37783750445.131.65.138192.168.2.13
    Oct 13, 2024 21:51:32.471349001 CEST375043778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:32.473634005 CEST375043778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:32.478696108 CEST37783750445.131.65.138192.168.2.13
    Oct 13, 2024 21:51:32.478779078 CEST375043778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:32.483838081 CEST37783750445.131.65.138192.168.2.13
    Oct 13, 2024 21:51:33.134236097 CEST37783750445.131.65.138192.168.2.13
    Oct 13, 2024 21:51:33.134697914 CEST375043778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:33.134699106 CEST375043778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:33.136111975 CEST375063778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:33.141597986 CEST37783750645.131.65.138192.168.2.13
    Oct 13, 2024 21:51:33.141824961 CEST375063778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:33.142949104 CEST375063778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:33.148139954 CEST37783750645.131.65.138192.168.2.13
    Oct 13, 2024 21:51:33.148336887 CEST375063778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:33.153726101 CEST37783750645.131.65.138192.168.2.13
    Oct 13, 2024 21:51:33.782974958 CEST37783750645.131.65.138192.168.2.13
    Oct 13, 2024 21:51:33.783452034 CEST375063778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:33.783452034 CEST375063778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:33.783858061 CEST375083778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:33.789040089 CEST37783750845.131.65.138192.168.2.13
    Oct 13, 2024 21:51:33.789103031 CEST375083778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:33.789716959 CEST375083778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:33.795440912 CEST37783750845.131.65.138192.168.2.13
    Oct 13, 2024 21:51:33.795510054 CEST375083778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:33.800471067 CEST37783750845.131.65.138192.168.2.13
    Oct 13, 2024 21:51:43.800132036 CEST375083778192.168.2.1345.131.65.138
    Oct 13, 2024 21:51:43.805840015 CEST37783750845.131.65.138192.168.2.13
    Oct 13, 2024 21:51:44.027533054 CEST37783750845.131.65.138192.168.2.13
    Oct 13, 2024 21:51:44.027964115 CEST375083778192.168.2.1345.131.65.138
    Oct 13, 2024 21:52:29.414238930 CEST374703778192.168.2.1345.131.65.138
    Oct 13, 2024 21:52:29.420213938 CEST37783747045.131.65.138192.168.2.13
    Oct 13, 2024 21:52:29.599756002 CEST37783747045.131.65.138192.168.2.13
    Oct 13, 2024 21:52:29.600359917 CEST374703778192.168.2.1345.131.65.138
    Oct 13, 2024 21:52:44.084881067 CEST375083778192.168.2.1345.131.65.138
    Oct 13, 2024 21:52:44.090786934 CEST37783750845.131.65.138192.168.2.13
    Oct 13, 2024 21:52:44.275983095 CEST37783750845.131.65.138192.168.2.13
    Oct 13, 2024 21:52:44.276418924 CEST375083778192.168.2.1345.131.65.138

    System Behavior

    Start time (UTC):19:51:15
    Start date (UTC):13/10/2024
    Path:/tmp/tc2iriCZdi.elf
    Arguments:/tmp/tc2iriCZdi.elf
    File size:37540 bytes
    MD5 hash:bc65b67b9d7b698cc14e918d061cc75f

    Start time (UTC):19:51:15
    Start date (UTC):13/10/2024
    Path:/tmp/tc2iriCZdi.elf
    Arguments:-
    File size:37540 bytes
    MD5 hash:bc65b67b9d7b698cc14e918d061cc75f

    Start time (UTC):19:51:15
    Start date (UTC):13/10/2024
    Path:/tmp/tc2iriCZdi.elf
    Arguments:-
    File size:37540 bytes
    MD5 hash:bc65b67b9d7b698cc14e918d061cc75f

    Start time (UTC):19:51:15
    Start date (UTC):13/10/2024
    Path:/tmp/tc2iriCZdi.elf
    Arguments:-
    File size:37540 bytes
    MD5 hash:bc65b67b9d7b698cc14e918d061cc75f

    Start time (UTC):19:51:21
    Start date (UTC):13/10/2024
    Path:/tmp/tc2iriCZdi.elf
    Arguments:-
    File size:37540 bytes
    MD5 hash:bc65b67b9d7b698cc14e918d061cc75f

    Start time (UTC):19:51:21
    Start date (UTC):13/10/2024
    Path:/tmp/tc2iriCZdi.elf
    Arguments:-
    File size:37540 bytes
    MD5 hash:bc65b67b9d7b698cc14e918d061cc75f