Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
vqkjf64.elf

Overview

General Information

Sample name:vqkjf64.elf
Analysis ID:1541233
MD5:c82fae90d5afa7faa234118494709c0f
SHA1:e0fe4479e4c72e31bfccb0e1fa87b9b3eddeeaf4
SHA256:f7f2d8c4291f14dbc5332b69ad19b4e7972a96d9a17b9b1d5aa909eec486e324
Tags:user-elfdigest
Infos:

Detection

Gafgyt, Mirai, Okiru
Score:96
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Gafgyt
Yara detected Mirai
Yara detected Okiru
Machine Learning detection for sample
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1541233
Start date and time:2024-10-24 15:42:03 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 21s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:vqkjf64.elf
Detection:MAL
Classification:mal96.troj.evad.linELF@0/0@66/0
  • VT rate limit hit for: vqkjf64.elf
Command:/tmp/vqkjf64.elf
PID:5434
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
about to cum inside a femboy btw
Standard Error:
  • system is lnxubuntu20
  • vqkjf64.elf (PID: 5434, Parent: 5358, MD5: c82fae90d5afa7faa234118494709c0f) Arguments: /tmp/vqkjf64.elf
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
Bashlite, GafgytBashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS). Originally it was also known under the name Bashdoor, but this term now refers to the exploit method used by the malware. It has been used to launch attacks of up to 400 Gbps.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.bashlite
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
vqkjf64.elfJoeSecurity_GafgytYara detected GafgytJoe Security
    vqkjf64.elfJoeSecurity_OkiruYara detected OkiruJoe Security
      vqkjf64.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
        vqkjf64.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
        • 0x18a98:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x18aac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x18ac0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x18ad4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x18ae8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x18afc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x18b10:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x18b24:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x18b38:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x18b4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x18b60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x18b74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x18b88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x18b9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x18bb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x18bc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x18bd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x18bec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x18c00:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x18c14:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x18c28:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        vqkjf64.elfLinux_Trojan_Gafgyt_9e9530a7unknownunknown
        • 0xf148:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
        Click to see the 11 entries
        SourceRuleDescriptionAuthorStrings
        5434.1.0000000000400000.000000000041c000.r-x.sdmpJoeSecurity_GafgytYara detected GafgytJoe Security
          5434.1.0000000000400000.000000000041c000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
            5434.1.0000000000400000.000000000041c000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
              5434.1.0000000000400000.000000000041c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
              • 0x18a98:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x18aac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x18ac0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x18ad4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x18ae8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x18afc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x18b10:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x18b24:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x18b38:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x18b4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x18b60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x18b74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x18b88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x18b9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x18bb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x18bc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x18bd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x18bec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x18c00:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x18c14:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x18c28:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              5434.1.0000000000400000.000000000041c000.r-x.sdmpLinux_Trojan_Gafgyt_9e9530a7unknownunknown
              • 0xf148:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
              Click to see the 14 entries
              No Suricata rule has matched

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: vqkjf64.elfAvira: detected
              Source: vqkjf64.elfReversingLabs: Detection: 47%
              Source: vqkjf64.elfJoe Sandbox ML: detected
              Source: vqkjf64.elfString: A/proc/proc/%d/cmdlinenetstatwgetcurl/bin/busybox/proc//proc/%s/exe/proc/self/exevar/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdvar/tmp/soniahicorestm_hi3511_dvr/usr/lib/systemd/systemdshellmnt/sys/boot/media/srv/var/run/sbin/lib/etc/dev/home/Davincitelnetsshwatchdog/var/spool/var/Sofiasshd/usr/compress/bin//compress/bin/compress/usr/bashhttpdtelnetddropbearencodersystem/root/dvr_gui//root/dvr_app//anko-app//opt/anko-app/ankosample _8182T_1104/usr/libexec/openssh/sftp-serverraw.eye-network.ruabcdefghijklmnopqrstuvwxyz/proc/%d/proc/self/usr/sbin/reboot/usr/bin/reboot/usr/sbin/shutdown/usr/bin/shutdown/usr/sbin/poweroff/usr/bin/poweroff/usr/sbin/halt/usr/bin/halt
              Source: global trafficTCP traffic: 192.168.2.13:36322 -> 213.232.235.18:33966
              Source: global trafficDNS traffic detected: DNS query: raw.eye-network.ru

              System Summary

              barindex
              Source: vqkjf64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: vqkjf64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
              Source: vqkjf64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
              Source: vqkjf64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
              Source: vqkjf64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
              Source: vqkjf64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d0c57a2e Author: unknown
              Source: vqkjf64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
              Source: vqkjf64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown
              Source: vqkjf64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
              Source: vqkjf64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown
              Source: vqkjf64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_520deeb8 Author: unknown
              Source: vqkjf64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_01e4a728 Author: unknown
              Source: vqkjf64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
              Source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
              Source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
              Source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
              Source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
              Source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d0c57a2e Author: unknown
              Source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
              Source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown
              Source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
              Source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown
              Source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_520deeb8 Author: unknown
              Source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_01e4a728 Author: unknown
              Source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
              Source: Process Memory Space: vqkjf64.elf PID: 5434, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: Initial sampleString containing 'busybox' found: /bin/busybox
              Source: Initial sampleString containing 'busybox' found: A/proc/proc/%d/cmdlinenetstatwgetcurl/bin/busybox/proc//proc/%s/exe/proc/self/exevar/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdvar/tmp/soniahicorestm_hi3511_dvr/usr/lib/systemd/systemdshellmnt/sys/boot/media/srv/var/run/sbin/lib/etc/dev/home/Davincitelnetsshwatchdog/var/spool/var/Sofiasshd/usr/compress/bin//compress/bin/compress/usr/bashhttpdtelnetddropbearencodersystem/root/dvr_gui//root/dvr_app//anko-app//opt/anko-app/ankosample _8182T_1104/usr/libexec/openssh/sftp-serverraw.eye-network.ruabcdefghijklmnopqrstuvwxyz/proc/%d/proc/self/usr/sbin/reboot/usr/bin/reboot/usr/sbin/shutdown/usr/bin/shutdown/usr/sbin/poweroff/usr/bin/poweroff/usr/sbin/halt/usr/bin/halt
              Source: ELF static info symbol of initial sample.symtab present: no
              Source: vqkjf64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: vqkjf64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
              Source: vqkjf64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
              Source: vqkjf64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
              Source: vqkjf64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
              Source: vqkjf64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d0c57a2e os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ee7d3a33575ed3aa7431489a8fb18bf30cfd5d6c776066ab2a27f93303124b6, id = d0c57a2e-c10c-436c-be13-50a269326cf2, last_modified = 2021-09-16
              Source: vqkjf64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
              Source: vqkjf64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16
              Source: vqkjf64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
              Source: vqkjf64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16
              Source: vqkjf64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_520deeb8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f4dfd1d76e07ff875eedfe0ef4f861bee1e4d8e66d68385f602f29cc35e30cca, id = 520deeb8-cbc0-4225-8d23-adba5e040471, last_modified = 2021-09-16
              Source: vqkjf64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_01e4a728 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = d90477364982bdc6cd22079c245d866454475749f762620273091f2fab73c196, id = 01e4a728-7c1c-479b-aed0-cb76d64dbb02, last_modified = 2021-09-16
              Source: vqkjf64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
              Source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
              Source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
              Source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
              Source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
              Source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d0c57a2e os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ee7d3a33575ed3aa7431489a8fb18bf30cfd5d6c776066ab2a27f93303124b6, id = d0c57a2e-c10c-436c-be13-50a269326cf2, last_modified = 2021-09-16
              Source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
              Source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16
              Source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
              Source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16
              Source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_520deeb8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f4dfd1d76e07ff875eedfe0ef4f861bee1e4d8e66d68385f602f29cc35e30cca, id = 520deeb8-cbc0-4225-8d23-adba5e040471, last_modified = 2021-09-16
              Source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_01e4a728 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = d90477364982bdc6cd22079c245d866454475749f762620273091f2fab73c196, id = 01e4a728-7c1c-479b-aed0-cb76d64dbb02, last_modified = 2021-09-16
              Source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
              Source: Process Memory Space: vqkjf64.elf PID: 5434, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: classification engineClassification label: mal96.troj.evad.linELF@0/0@66/0
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/5382/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/230/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/110/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/231/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/111/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/232/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/112/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/233/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/113/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/234/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/114/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/235/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/115/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/236/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/116/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/237/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/117/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/238/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/118/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/239/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/119/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/914/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/3634/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/10/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/917/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/11/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/12/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/13/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/14/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/15/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/16/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/17/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/5278/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/18/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/19/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/240/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/3095/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/120/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/241/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/121/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/242/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/1/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/122/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/243/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/2/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/123/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/244/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/3/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/124/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/245/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/1588/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/125/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/4/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/246/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/126/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/5/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/247/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/127/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/6/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/248/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/128/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/7/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/249/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/129/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/8/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/800/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/9/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/1906/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/802/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/803/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/20/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/21/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/22/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/23/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/24/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/25/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/26/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/27/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/28/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/29/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/3420/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/1482/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/490/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/1480/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/250/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/371/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/130/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/251/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/131/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/252/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/132/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/253/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/254/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/1238/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/134/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/255/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/256/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/257/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/378/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/3413/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/258/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/259/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/1475/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/936/cmdlineJump to behavior
              Source: /tmp/vqkjf64.elf (PID: 5436)File opened: /proc/30/cmdlineJump to behavior

              Hooking and other Techniques for Hiding and Protection

              barindex
              Source: /tmp/vqkjf64.elf (PID: 5435)File: /tmp/vqkjf64.elfJump to behavior

              Stealing of Sensitive Information

              barindex
              Source: Yara matchFile source: vqkjf64.elf, type: SAMPLE
              Source: Yara matchFile source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: vqkjf64.elf, type: SAMPLE
              Source: Yara matchFile source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: vqkjf64.elf PID: 5434, type: MEMORYSTR
              Source: Yara matchFile source: vqkjf64.elf, type: SAMPLE
              Source: Yara matchFile source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: vqkjf64.elf PID: 5434, type: MEMORYSTR

              Remote Access Functionality

              barindex
              Source: Yara matchFile source: vqkjf64.elf, type: SAMPLE
              Source: Yara matchFile source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: vqkjf64.elf, type: SAMPLE
              Source: Yara matchFile source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: vqkjf64.elf PID: 5434, type: MEMORYSTR
              Source: Yara matchFile source: vqkjf64.elf, type: SAMPLE
              Source: Yara matchFile source: 5434.1.0000000000400000.000000000041c000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: vqkjf64.elf PID: 5434, type: MEMORYSTR
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity Information1
              Scripting
              Valid AccountsWindows Management Instrumentation1
              Scripting
              Path Interception1
              File Deletion
              1
              OS Credential Dumping
              System Service DiscoveryRemote ServicesData from Local System1
              Non-Standard Port
              Exfiltration Over Other Network MediumAbuse Accessibility Features
              CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
              Non-Application Layer Protocol
              Exfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
              Application Layer Protocol
              Automated ExfiltrationData Encrypted for Impact
              No configs have been found
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Number of created Files
              • Is malicious
              • Internet
              SourceDetectionScannerLabelLink
              vqkjf64.elf47%ReversingLabsLinux.Backdoor.Mirai
              vqkjf64.elf100%AviraEXP/ELF.Mirai.Z.A
              vqkjf64.elf100%Joe Sandbox ML
              No Antivirus matches
              No Antivirus matches
              No Antivirus matches
              NameIPActiveMaliciousAntivirus DetectionReputation
              raw.eye-network.ru
              213.232.235.18
              truefalse
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                213.232.235.18
                raw.eye-network.ruRussian Federation
                39824ALMANET-ASKZfalse
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                213.232.235.18vwkjebwi686.elfGet hashmaliciousMirai, OkiruBrowse
                  dvwkja7.elfGet hashmaliciousMirai, OkiruBrowse
                    wheiuwa4.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                      qkbfi86.elfGet hashmaliciousMirai, OkiruBrowse
                        vsbeps.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                          qkbfi86.elfGet hashmaliciousMiraiBrowse
                            vsbeps.elfGet hashmaliciousMiraiBrowse
                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                              raw.eye-network.ruvsbeps.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                              • 213.232.235.18
                              vsbeps.elfGet hashmaliciousMiraiBrowse
                              • 213.232.235.18
                              mhmdm9Hb6i.elfGet hashmaliciousMiraiBrowse
                              • 213.130.144.69
                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                              ALMANET-ASKZvwkjebwi686.elfGet hashmaliciousMirai, OkiruBrowse
                              • 213.232.235.18
                              dvwkja7.elfGet hashmaliciousMirai, OkiruBrowse
                              • 213.232.235.18
                              wheiuwa4.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                              • 213.232.235.18
                              qkbfi86.elfGet hashmaliciousMirai, OkiruBrowse
                              • 213.232.235.18
                              vsbeps.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                              • 213.232.235.18
                              qkbfi86.elfGet hashmaliciousMiraiBrowse
                              • 213.232.235.18
                              vsbeps.elfGet hashmaliciousMiraiBrowse
                              • 213.232.235.18
                              192.142.103.80-x86-2024-08-09T11_47_41.elfGet hashmaliciousUnknownBrowse
                              • 185.102.119.37
                              WE4VRokml7.elfGet hashmaliciousMirai, MoobotBrowse
                              • 185.100.226.244
                              No context
                              No context
                              No created / dropped files found
                              File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped
                              Entropy (8bit):5.285790896410619
                              TrID:
                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                              File name:vqkjf64.elf
                              File size:151'096 bytes
                              MD5:c82fae90d5afa7faa234118494709c0f
                              SHA1:e0fe4479e4c72e31bfccb0e1fa87b9b3eddeeaf4
                              SHA256:f7f2d8c4291f14dbc5332b69ad19b4e7972a96d9a17b9b1d5aa909eec486e324
                              SHA512:919a7573a00723b3bb6d79e888663bf3b61e26c2f76e06954867ecb52bd2a5fcbdd257147f4774be66ab1f5c8b95f032d26843f8a07c4f4e668575ccf8c8373d
                              SSDEEP:3072:Py0EBBhEjt9M9WZBR2bvmYdGCNCyCFO+A/OMyP9h3/bV/Hp:Py0EBBhEjt9M9WPmX2Mg/R/Hp
                              TLSH:F0E33A07B5C188FDC4DAC1B44BAEB53AED31F89D1138B26B27D4AE261E4DE305E1DA04
                              File Content Preview:.ELF..............>.......@.....@........K..........@.8...@.......................@.......@...............................................Q.......Q.............................Q.td....................................................H...._........H........

                              ELF header

                              Class:ELF64
                              Data:2's complement, little endian
                              Version:1 (current)
                              Machine:Advanced Micro Devices X86-64
                              Version Number:0x1
                              Type:EXEC (Executable file)
                              OS/ABI:UNIX - System V
                              ABI Version:0
                              Entry Point Address:0x400194
                              Flags:0x0
                              ELF Header Size:64
                              Program Header Offset:64
                              Program Header Size:56
                              Number of Program Headers:3
                              Section Header Offset:150456
                              Section Header Size:64
                              Number of Section Headers:10
                              Header String Table Index:9
                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                              NULL0x00x00x00x00x0000
                              .initPROGBITS0x4000e80xe80x130x00x6AX001
                              .textPROGBITS0x4001000x1000x182060x00x6AX0016
                              .finiPROGBITS0x4183060x183060xe0x00x6AX001
                              .rodataPROGBITS0x4183200x183200x39a00x00x2A0032
                              .ctorsPROGBITS0x51bcc80x1bcc80x180x00x3WA008
                              .dtorsPROGBITS0x51bce00x1bce00x100x00x3WA008
                              .dataPROGBITS0x51bd000x1bd000x8e780x00x3WA0032
                              .bssNOBITS0x524b800x24b780x72600x00x3WA0032
                              .shstrtabSTRTAB0x00x24b780x3e0x00x0001
                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                              LOAD0x00x4000000x4000000x1bcc00x1bcc06.35430x5R E0x100000.init .text .fini .rodata
                              LOAD0x1bcc80x51bcc80x51bcc80x8eb00x101180.25610x6RW 0x100000.ctors .dtors .data .bss
                              GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
                              TimestampSource PortDest PortSource IPDest IP
                              Oct 24, 2024 15:42:52.258344889 CEST3632233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:52.263849974 CEST3396636322213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:52.263905048 CEST3632233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:52.264764071 CEST3632233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:52.270077944 CEST3396636322213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:52.270119905 CEST3632233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:52.275509119 CEST3396636322213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:53.159514904 CEST3396636322213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:53.159589052 CEST3632233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:53.159589052 CEST3632233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:53.185859919 CEST3632433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:53.191190004 CEST3396636324213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:53.191246986 CEST3632433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:53.195002079 CEST3632433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:53.200294018 CEST3396636324213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:53.200354099 CEST3632433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:53.205888033 CEST3396636324213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:54.093585968 CEST3396636324213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:54.093641996 CEST3632433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:54.093673944 CEST3632433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:54.117412090 CEST3632633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:54.122838974 CEST3396636326213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:54.122884989 CEST3632633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:54.124897003 CEST3632633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:54.130342007 CEST3396636326213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:54.130383968 CEST3632633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:54.135672092 CEST3396636326213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:55.018275023 CEST3396636326213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:55.018393040 CEST3632633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:55.018393040 CEST3632633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:55.058635950 CEST3632833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:55.064276934 CEST3396636328213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:55.064352036 CEST3632833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:55.068056107 CEST3632833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:55.073385000 CEST3396636328213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:55.073442936 CEST3632833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:55.078846931 CEST3396636328213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:55.972295046 CEST3396636328213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:55.972373009 CEST3632833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:55.972373962 CEST3632833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:55.993311882 CEST3633033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:55.998651981 CEST3396636330213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:55.998716116 CEST3633033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:55.999553919 CEST3633033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:56.005613089 CEST3396636330213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:56.005662918 CEST3633033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:56.011034966 CEST3396636330213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:56.883754015 CEST3396636330213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:56.883836031 CEST3633033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:56.883836031 CEST3633033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:56.907535076 CEST3633233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:56.912878036 CEST3396636332213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:56.912965059 CEST3633233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:56.914951086 CEST3633233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:56.920308113 CEST3396636332213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:56.920475960 CEST3633233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:56.925786972 CEST3396636332213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:57.817627907 CEST3396636332213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:57.817687035 CEST3633233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:57.817687035 CEST3633233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:57.839766979 CEST3633433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:57.845231056 CEST3396636334213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:57.845290899 CEST3633433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:57.846221924 CEST3633433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:57.851690054 CEST3396636334213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:57.851726055 CEST3633433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:57.857112885 CEST3396636334213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:58.743995905 CEST3396636334213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:58.744183064 CEST3633433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:58.744184017 CEST3633433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:58.768352985 CEST3633633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:58.773788929 CEST3396636336213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:58.773844957 CEST3633633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:58.776263952 CEST3633633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:58.781708002 CEST3396636336213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:58.781763077 CEST3633633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:58.787389040 CEST3396636336213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:59.682718992 CEST3396636336213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:59.683607101 CEST3633633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:59.683608055 CEST3633633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:59.818834066 CEST3633833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:59.824667931 CEST3396636338213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:59.824728012 CEST3633833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:59.825295925 CEST3633833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:59.831288099 CEST3396636338213.232.235.18192.168.2.13
                              Oct 24, 2024 15:42:59.831345081 CEST3633833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:42:59.836708069 CEST3396636338213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:00.718930960 CEST3396636338213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:00.719211102 CEST3633833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:00.719211102 CEST3633833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:00.741208076 CEST3634033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:00.746778965 CEST3396636340213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:00.746834993 CEST3634033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:00.747766018 CEST3634033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:00.753220081 CEST3396636340213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:00.753261089 CEST3634033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:00.758558989 CEST3396636340213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:01.642435074 CEST3396636340213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:01.642725945 CEST3634033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:01.642726898 CEST3634033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:01.672979116 CEST3634233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:01.678428888 CEST3396636342213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:01.678500891 CEST3634233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:01.679594994 CEST3634233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:01.685168982 CEST3396636342213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:01.685240030 CEST3634233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:01.691814899 CEST3396636342213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:02.582264900 CEST3396636342213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:02.582433939 CEST3634233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:02.582433939 CEST3634233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:02.599895954 CEST3634433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:02.605274916 CEST3396636344213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:02.605328083 CEST3634433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:02.605988026 CEST3634433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:02.611938000 CEST3396636344213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:02.611989021 CEST3634433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:02.617425919 CEST3396636344213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:03.490220070 CEST3396636344213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:03.490509987 CEST3634433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:03.490509987 CEST3634433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:03.510030031 CEST3634633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:03.518166065 CEST3396636346213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:03.518227100 CEST3634633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:03.519443989 CEST3634633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:03.526434898 CEST3396636346213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:03.526488066 CEST3634633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:03.532699108 CEST3396636346213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:04.416553974 CEST3396636346213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:04.416776896 CEST3634633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:04.416778088 CEST3634633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:04.432524920 CEST3634833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:04.437839031 CEST3396636348213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:04.437891006 CEST3634833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:04.438483953 CEST3634833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:04.444498062 CEST3396636348213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:04.444545984 CEST3634833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:04.449855089 CEST3396636348213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:05.322093964 CEST3396636348213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:05.322343111 CEST3634833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:05.322343111 CEST3634833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:05.340934992 CEST3635033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:05.346477032 CEST3396636350213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:05.346591949 CEST3635033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:06.355285883 CEST3635033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:06.360985994 CEST3396636350213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:06.361085892 CEST3635033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:06.361855030 CEST3635033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:06.367369890 CEST3396636350213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:06.367451906 CEST3635033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:06.372805119 CEST3396636350213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:07.263632059 CEST3396636350213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:07.263880014 CEST3635033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:07.263880968 CEST3635033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:07.281399012 CEST3635233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:07.286963940 CEST3396636352213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:07.287041903 CEST3635233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:07.287828922 CEST3635233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:07.293661118 CEST3396636352213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:07.293742895 CEST3635233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:07.299108028 CEST3396636352213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:08.191668034 CEST3396636352213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:08.192060947 CEST3635233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:08.192061901 CEST3635233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:08.209137917 CEST3635433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:08.214528084 CEST3396636354213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:08.214605093 CEST3635433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:08.215218067 CEST3635433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:08.220669985 CEST3396636354213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:08.220757008 CEST3635433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:08.226160049 CEST3396636354213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:09.413801908 CEST3396636354213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:09.413917065 CEST3396636354213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:09.414047956 CEST3635433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:09.414047956 CEST3635433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:09.414047956 CEST3635433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:09.431653023 CEST3635633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:09.437160969 CEST3396636356213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:09.437237978 CEST3635633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:09.437815905 CEST3635633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:09.443085909 CEST3396636356213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:09.443136930 CEST3635633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:09.448491096 CEST3396636356213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:10.332556963 CEST3396636356213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:10.332801104 CEST3635633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:10.332801104 CEST3635633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:10.352662086 CEST3635833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:10.358067989 CEST3396636358213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:10.358139038 CEST3635833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:10.359091997 CEST3635833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:10.364490986 CEST3396636358213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:10.364561081 CEST3635833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:10.370038986 CEST3396636358213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:11.856072903 CEST3396636358213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:11.856101036 CEST3396636358213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:11.856302023 CEST3396636358213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:11.856376886 CEST3635833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:11.856376886 CEST3635833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:11.856376886 CEST3635833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:11.856378078 CEST3635833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:11.874032974 CEST3636033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:11.879461050 CEST3396636360213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:11.879513979 CEST3636033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:11.880186081 CEST3636033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:11.885591030 CEST3396636360213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:11.885685921 CEST3636033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:11.891078949 CEST3396636360213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:12.810642958 CEST3396636360213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:12.810903072 CEST3636033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:12.810903072 CEST3636033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:12.829413891 CEST3636233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:12.834899902 CEST3396636362213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:12.834969044 CEST3636233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:12.835995913 CEST3636233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:12.841373920 CEST3396636362213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:12.841427088 CEST3636233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:12.846780062 CEST3396636362213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:13.728673935 CEST3396636362213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:13.728846073 CEST3636233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:13.728879929 CEST3636233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:13.971750975 CEST3396636362213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:13.971899986 CEST3636233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:13.983366013 CEST3636433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:13.988753080 CEST3396636364213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:13.988796949 CEST3636433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:13.989790916 CEST3636433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:13.995052099 CEST3396636364213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:13.995093107 CEST3636433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:14.000427008 CEST3396636364213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:14.881835938 CEST3396636364213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:14.882028103 CEST3636433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:14.882072926 CEST3636433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:14.900825024 CEST3636633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:14.906760931 CEST3396636366213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:14.906829119 CEST3636633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:14.907814980 CEST3636633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:14.913502932 CEST3396636366213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:14.913567066 CEST3636633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:14.918920994 CEST3396636366213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:15.792412996 CEST3396636366213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:15.792558908 CEST3636633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:15.792598963 CEST3636633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:15.812505960 CEST3636833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:15.817971945 CEST3396636368213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:15.818193913 CEST3636833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:15.818958044 CEST3636833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:15.824374914 CEST3396636368213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:15.824421883 CEST3636833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:15.829941034 CEST3396636368213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:16.713381052 CEST3396636368213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:16.713566065 CEST3636833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:16.713567019 CEST3636833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:16.732366085 CEST3637033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:16.737714052 CEST3396636370213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:16.737798929 CEST3637033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:16.738738060 CEST3637033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:16.744040012 CEST3396636370213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:16.744112015 CEST3637033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:16.749501944 CEST3396636370213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:17.622725964 CEST3396636370213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:17.623012066 CEST3637033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:17.623012066 CEST3637033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:17.644036055 CEST3637233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:17.649605989 CEST3396636372213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:17.649693966 CEST3637233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:17.650825024 CEST3637233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:17.658598900 CEST3396636372213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:17.658674955 CEST3637233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:17.664707899 CEST3396636372213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:52.203329086 CEST3396636372213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:52.203598976 CEST3637233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:52.209445953 CEST3396636372213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:53.225296974 CEST3637433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:53.230710030 CEST3396636374213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:53.230964899 CEST3637433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:53.232907057 CEST3637433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:53.239531994 CEST3396636374213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:53.239893913 CEST3637433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:53.245243073 CEST3396636374213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:54.134358883 CEST3396636374213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:54.134587049 CEST3637433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:54.134587049 CEST3637433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:54.155766010 CEST3637633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:54.161395073 CEST3396636376213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:54.161480904 CEST3637633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:54.162460089 CEST3637633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:54.167814016 CEST3396636376213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:54.167882919 CEST3637633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:54.173294067 CEST3396636376213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:55.066627026 CEST3396636376213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:55.066771030 CEST3637633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:55.066822052 CEST3637633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:55.085077047 CEST3637833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:55.090564013 CEST3396636378213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:55.090624094 CEST3637833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:55.091398954 CEST3637833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:55.299216986 CEST3637833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:55.511163950 CEST3637833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:55.923233986 CEST3637833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:56.145905018 CEST3396636378213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:56.145973921 CEST3396636378213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:56.145988941 CEST3396636378213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:56.146028996 CEST3396636378213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:56.414367914 CEST3396636378213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:56.414520979 CEST3637833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:56.414585114 CEST3637833966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:56.434524059 CEST3638033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:56.439989090 CEST3396636380213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:56.440048933 CEST3638033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:56.440993071 CEST3638033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:56.446794987 CEST3396636380213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:56.446836948 CEST3638033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:56.452255964 CEST3396636380213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:57.344930887 CEST3396636380213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:57.345026970 CEST3638033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:57.345057964 CEST3638033966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:57.369574070 CEST3638233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:57.376919985 CEST3396636382213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:57.377027035 CEST3638233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:57.378470898 CEST3638233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:57.386071920 CEST3396636382213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:57.386137009 CEST3638233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:57.394577026 CEST3396636382213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:58.265945911 CEST3396636382213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:58.266088963 CEST3638233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:58.266125917 CEST3638233966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:58.285912037 CEST3638433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:58.291382074 CEST3396636384213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:58.291450024 CEST3638433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:58.292682886 CEST3638433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:58.298048973 CEST3396636384213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:58.298110008 CEST3638433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:58.303559065 CEST3396636384213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:59.196083069 CEST3396636384213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:59.196183920 CEST3638433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:59.196183920 CEST3638433966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:59.215523958 CEST3638633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:59.220840931 CEST3396636386213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:59.220896006 CEST3638633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:59.221649885 CEST3638633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:59.227000952 CEST3396636386213.232.235.18192.168.2.13
                              Oct 24, 2024 15:43:59.227041960 CEST3638633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:43:59.232489109 CEST3396636386213.232.235.18192.168.2.13
                              Oct 24, 2024 15:44:39.255156994 CEST3638633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:44:39.353827000 CEST3396636386213.232.235.18192.168.2.13
                              Oct 24, 2024 15:44:49.263310909 CEST3638633966192.168.2.13213.232.235.18
                              Oct 24, 2024 15:44:49.268973112 CEST3396636386213.232.235.18192.168.2.13
                              TimestampSource PortDest PortSource IPDest IP
                              Oct 24, 2024 15:42:52.231347084 CEST4170553192.168.2.138.8.8.8
                              Oct 24, 2024 15:42:52.244014025 CEST53417058.8.8.8192.168.2.13
                              Oct 24, 2024 15:42:52.245270967 CEST3783553192.168.2.138.8.8.8
                              Oct 24, 2024 15:42:52.257906914 CEST53378358.8.8.8192.168.2.13
                              Oct 24, 2024 15:42:53.163311005 CEST3954853192.168.2.138.8.8.8
                              Oct 24, 2024 15:42:53.171456099 CEST53395488.8.8.8192.168.2.13
                              Oct 24, 2024 15:42:53.175975084 CEST3285853192.168.2.138.8.8.8
                              Oct 24, 2024 15:42:53.183697939 CEST53328588.8.8.8192.168.2.13
                              Oct 24, 2024 15:42:54.095134020 CEST4492553192.168.2.138.8.8.8
                              Oct 24, 2024 15:42:54.102937937 CEST53449258.8.8.8192.168.2.13
                              Oct 24, 2024 15:42:54.104414940 CEST5371453192.168.2.138.8.8.8
                              Oct 24, 2024 15:42:54.116523981 CEST53537148.8.8.8192.168.2.13
                              Oct 24, 2024 15:42:55.021867037 CEST3953653192.168.2.138.8.8.8
                              Oct 24, 2024 15:42:55.033356905 CEST53395368.8.8.8192.168.2.13
                              Oct 24, 2024 15:42:55.037456989 CEST4144053192.168.2.138.8.8.8
                              Oct 24, 2024 15:42:55.056629896 CEST53414408.8.8.8192.168.2.13
                              Oct 24, 2024 15:42:55.973225117 CEST4320953192.168.2.138.8.8.8
                              Oct 24, 2024 15:42:55.984003067 CEST53432098.8.8.8192.168.2.13
                              Oct 24, 2024 15:42:55.984935045 CEST3643353192.168.2.138.8.8.8
                              Oct 24, 2024 15:42:55.992866039 CEST53364338.8.8.8192.168.2.13
                              Oct 24, 2024 15:42:56.886888981 CEST6067353192.168.2.138.8.8.8
                              Oct 24, 2024 15:42:56.895148039 CEST53606738.8.8.8192.168.2.13
                              Oct 24, 2024 15:42:56.897613049 CEST3688153192.168.2.138.8.8.8
                              Oct 24, 2024 15:42:56.906444073 CEST53368818.8.8.8192.168.2.13
                              Oct 24, 2024 15:42:57.818639994 CEST4704453192.168.2.138.8.8.8
                              Oct 24, 2024 15:42:57.826971054 CEST53470448.8.8.8192.168.2.13
                              Oct 24, 2024 15:42:57.827961922 CEST5286553192.168.2.138.8.8.8
                              Oct 24, 2024 15:42:57.839339018 CEST53528658.8.8.8192.168.2.13
                              Oct 24, 2024 15:42:58.747404099 CEST5732953192.168.2.138.8.8.8
                              Oct 24, 2024 15:42:58.756072044 CEST53573298.8.8.8192.168.2.13
                              Oct 24, 2024 15:42:58.759134054 CEST5589653192.168.2.138.8.8.8
                              Oct 24, 2024 15:42:58.767079115 CEST53558968.8.8.8192.168.2.13
                              Oct 24, 2024 15:42:59.781527996 CEST4691853192.168.2.138.8.8.8
                              Oct 24, 2024 15:42:59.789129019 CEST53469188.8.8.8192.168.2.13
                              Oct 24, 2024 15:42:59.810477972 CEST6033753192.168.2.138.8.8.8
                              Oct 24, 2024 15:42:59.818525076 CEST53603378.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:00.720905066 CEST4212053192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:00.728601933 CEST53421208.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:00.729605913 CEST4100153192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:00.740582943 CEST53410018.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:01.644519091 CEST3505953192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:01.663587093 CEST53350598.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:01.664870977 CEST3895053192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:01.672482014 CEST53389508.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:02.583420992 CEST3633053192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:02.591118097 CEST53363308.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:02.592006922 CEST4818753192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:02.599481106 CEST53481878.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:03.491539955 CEST3385453192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:03.499144077 CEST53338548.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:03.500068903 CEST3377553192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:03.509427071 CEST53337758.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:04.417592049 CEST3692153192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:04.424348116 CEST53369218.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:04.425019026 CEST5852353192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:04.432154894 CEST53585238.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:05.323556900 CEST5118353192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:05.331299067 CEST53511838.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:05.332448959 CEST4404453192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:05.340483904 CEST53440448.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:07.264745951 CEST5367853192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:07.271974087 CEST53536788.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:07.272979021 CEST4573653192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:07.280868053 CEST53457368.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:08.193042040 CEST4830953192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:08.200167894 CEST53483098.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:08.201303005 CEST5995553192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:08.208682060 CEST53599558.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:09.414866924 CEST3975053192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:09.422883987 CEST53397508.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:09.423743963 CEST4380553192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:09.431247950 CEST53438058.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:10.333842993 CEST4399353192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:10.342000961 CEST53439938.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:10.342832088 CEST4214753192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:10.351969957 CEST53421478.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:11.857491016 CEST5964653192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:11.865030050 CEST53596468.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:11.865752935 CEST3884653192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:11.873584986 CEST53388468.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:12.812171936 CEST3921153192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:12.819641113 CEST53392118.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:12.820770025 CEST5992453192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:12.828789949 CEST53599248.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:13.730065107 CEST4012953192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:13.974031925 CEST53401298.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:13.975332975 CEST3354053192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:13.982773066 CEST53335408.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:14.883229971 CEST5722953192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:14.891211987 CEST53572298.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:14.892314911 CEST3529653192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:14.900357962 CEST53352968.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:15.793734074 CEST4614653192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:15.801826000 CEST53461468.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:15.802809954 CEST3402253192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:15.811964035 CEST53340228.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:16.715183020 CEST5659753192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:16.722609997 CEST53565978.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:16.723692894 CEST3967153192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:16.731740952 CEST53396718.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:17.624437094 CEST5163053192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:17.634563923 CEST53516308.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:17.635773897 CEST4832053192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:17.643218040 CEST53483208.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:53.206588030 CEST5491353192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:53.214303017 CEST53549138.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:53.216459990 CEST5457753192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:53.223773956 CEST53545778.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:54.135695934 CEST6089353192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:54.143008947 CEST53608938.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:54.144072056 CEST4753353192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:54.155002117 CEST53475338.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:55.068078995 CEST4422353192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:55.075721025 CEST53442238.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:55.076708078 CEST4934253192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:55.084650040 CEST53493428.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:56.415951014 CEST5387053192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:56.425201893 CEST53538708.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:56.426436901 CEST5702853192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:56.434050083 CEST53570288.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:57.345844984 CEST5194353192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:57.358062029 CEST53519438.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:57.359456062 CEST5679453192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:57.368350983 CEST53567948.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:58.267426014 CEST4434453192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:58.276309013 CEST53443448.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:58.277329922 CEST6019653192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:58.285409927 CEST53601968.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:59.197374105 CEST4937253192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:59.204547882 CEST53493728.8.8.8192.168.2.13
                              Oct 24, 2024 15:43:59.205360889 CEST3567353192.168.2.138.8.8.8
                              Oct 24, 2024 15:43:59.215034962 CEST53356738.8.8.8192.168.2.13
                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                              Oct 24, 2024 15:42:52.231347084 CEST192.168.2.138.8.8.80x73b1Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:52.245270967 CEST192.168.2.138.8.8.80xc50aStandard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:53.163311005 CEST192.168.2.138.8.8.80xda9cStandard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:53.175975084 CEST192.168.2.138.8.8.80xca8eStandard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:54.095134020 CEST192.168.2.138.8.8.80x45b4Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:54.104414940 CEST192.168.2.138.8.8.80x8fd8Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:55.021867037 CEST192.168.2.138.8.8.80x91aStandard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:55.037456989 CEST192.168.2.138.8.8.80x7072Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:55.973225117 CEST192.168.2.138.8.8.80xd290Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:55.984935045 CEST192.168.2.138.8.8.80xee2Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:56.886888981 CEST192.168.2.138.8.8.80x6139Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:56.897613049 CEST192.168.2.138.8.8.80xd76Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:57.818639994 CEST192.168.2.138.8.8.80xdb65Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:57.827961922 CEST192.168.2.138.8.8.80x38acStandard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:58.747404099 CEST192.168.2.138.8.8.80x9221Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:58.759134054 CEST192.168.2.138.8.8.80xb7b4Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:59.781527996 CEST192.168.2.138.8.8.80x398cStandard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:59.810477972 CEST192.168.2.138.8.8.80x9344Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:00.720905066 CEST192.168.2.138.8.8.80xa654Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:00.729605913 CEST192.168.2.138.8.8.80x4592Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:01.644519091 CEST192.168.2.138.8.8.80xf499Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:01.664870977 CEST192.168.2.138.8.8.80xef3Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:02.583420992 CEST192.168.2.138.8.8.80x2571Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:02.592006922 CEST192.168.2.138.8.8.80xc455Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:03.491539955 CEST192.168.2.138.8.8.80xaea1Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:03.500068903 CEST192.168.2.138.8.8.80x4d3bStandard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:04.417592049 CEST192.168.2.138.8.8.80xffd2Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:04.425019026 CEST192.168.2.138.8.8.80xfa29Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:05.323556900 CEST192.168.2.138.8.8.80xc047Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:05.332448959 CEST192.168.2.138.8.8.80x9a52Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:07.264745951 CEST192.168.2.138.8.8.80x6414Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:07.272979021 CEST192.168.2.138.8.8.80xcfbcStandard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:08.193042040 CEST192.168.2.138.8.8.80x74c0Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:08.201303005 CEST192.168.2.138.8.8.80xa9bfStandard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:09.414866924 CEST192.168.2.138.8.8.80x8374Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:09.423743963 CEST192.168.2.138.8.8.80x3187Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:10.333842993 CEST192.168.2.138.8.8.80xa467Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:10.342832088 CEST192.168.2.138.8.8.80x1c28Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:11.857491016 CEST192.168.2.138.8.8.80xa771Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:11.865752935 CEST192.168.2.138.8.8.80xced4Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:12.812171936 CEST192.168.2.138.8.8.80xb658Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:12.820770025 CEST192.168.2.138.8.8.80x160Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:13.730065107 CEST192.168.2.138.8.8.80xcf22Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:13.975332975 CEST192.168.2.138.8.8.80x7a75Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:14.883229971 CEST192.168.2.138.8.8.80x110bStandard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:14.892314911 CEST192.168.2.138.8.8.80xfcdcStandard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:15.793734074 CEST192.168.2.138.8.8.80x71b0Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:15.802809954 CEST192.168.2.138.8.8.80xb0baStandard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:16.715183020 CEST192.168.2.138.8.8.80xf191Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:16.723692894 CEST192.168.2.138.8.8.80x4e5dStandard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:17.624437094 CEST192.168.2.138.8.8.80xa622Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:17.635773897 CEST192.168.2.138.8.8.80x2339Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:53.206588030 CEST192.168.2.138.8.8.80x8326Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:53.216459990 CEST192.168.2.138.8.8.80x2ec9Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:54.135695934 CEST192.168.2.138.8.8.80x28b5Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:54.144072056 CEST192.168.2.138.8.8.80x697aStandard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:55.068078995 CEST192.168.2.138.8.8.80x2c50Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:55.076708078 CEST192.168.2.138.8.8.80xf17eStandard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:56.415951014 CEST192.168.2.138.8.8.80xee50Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:56.426436901 CEST192.168.2.138.8.8.80x8267Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:57.345844984 CEST192.168.2.138.8.8.80xbbc2Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:57.359456062 CEST192.168.2.138.8.8.80xd7d6Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:58.267426014 CEST192.168.2.138.8.8.80xf289Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:58.277329922 CEST192.168.2.138.8.8.80x1cfdStandard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:59.197374105 CEST192.168.2.138.8.8.80x7079Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:59.205360889 CEST192.168.2.138.8.8.80x7b26Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                              Oct 24, 2024 15:42:52.244014025 CEST8.8.8.8192.168.2.130x73b1No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:52.257906914 CEST8.8.8.8192.168.2.130xc50aNo error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:53.171456099 CEST8.8.8.8192.168.2.130xda9cNo error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:53.183697939 CEST8.8.8.8192.168.2.130xca8eNo error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:54.102937937 CEST8.8.8.8192.168.2.130x45b4No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:54.116523981 CEST8.8.8.8192.168.2.130x8fd8No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:55.033356905 CEST8.8.8.8192.168.2.130x91aNo error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:55.056629896 CEST8.8.8.8192.168.2.130x7072No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:55.984003067 CEST8.8.8.8192.168.2.130xd290No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:55.992866039 CEST8.8.8.8192.168.2.130xee2No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:56.895148039 CEST8.8.8.8192.168.2.130x6139No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:56.906444073 CEST8.8.8.8192.168.2.130xd76No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:57.826971054 CEST8.8.8.8192.168.2.130xdb65No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:57.839339018 CEST8.8.8.8192.168.2.130x38acNo error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:58.756072044 CEST8.8.8.8192.168.2.130x9221No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:58.767079115 CEST8.8.8.8192.168.2.130xb7b4No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:59.789129019 CEST8.8.8.8192.168.2.130x398cNo error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:42:59.818525076 CEST8.8.8.8192.168.2.130x9344No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:00.728601933 CEST8.8.8.8192.168.2.130xa654No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:00.740582943 CEST8.8.8.8192.168.2.130x4592No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:01.663587093 CEST8.8.8.8192.168.2.130xf499No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:01.672482014 CEST8.8.8.8192.168.2.130xef3No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:02.591118097 CEST8.8.8.8192.168.2.130x2571No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:02.599481106 CEST8.8.8.8192.168.2.130xc455No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:03.499144077 CEST8.8.8.8192.168.2.130xaea1No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:03.509427071 CEST8.8.8.8192.168.2.130x4d3bNo error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:04.424348116 CEST8.8.8.8192.168.2.130xffd2No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:04.432154894 CEST8.8.8.8192.168.2.130xfa29No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:05.331299067 CEST8.8.8.8192.168.2.130xc047No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:05.340483904 CEST8.8.8.8192.168.2.130x9a52No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:07.271974087 CEST8.8.8.8192.168.2.130x6414No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:07.280868053 CEST8.8.8.8192.168.2.130xcfbcNo error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:08.200167894 CEST8.8.8.8192.168.2.130x74c0No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:08.208682060 CEST8.8.8.8192.168.2.130xa9bfNo error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:09.422883987 CEST8.8.8.8192.168.2.130x8374No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:09.431247950 CEST8.8.8.8192.168.2.130x3187No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:10.342000961 CEST8.8.8.8192.168.2.130xa467No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:10.351969957 CEST8.8.8.8192.168.2.130x1c28No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:11.865030050 CEST8.8.8.8192.168.2.130xa771No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:11.873584986 CEST8.8.8.8192.168.2.130xced4No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:12.819641113 CEST8.8.8.8192.168.2.130xb658No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:12.828789949 CEST8.8.8.8192.168.2.130x160No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:13.974031925 CEST8.8.8.8192.168.2.130xcf22No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:13.982773066 CEST8.8.8.8192.168.2.130x7a75No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:14.891211987 CEST8.8.8.8192.168.2.130x110bNo error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:14.900357962 CEST8.8.8.8192.168.2.130xfcdcNo error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:15.801826000 CEST8.8.8.8192.168.2.130x71b0No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:15.811964035 CEST8.8.8.8192.168.2.130xb0baNo error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:16.722609997 CEST8.8.8.8192.168.2.130xf191No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:16.731740952 CEST8.8.8.8192.168.2.130x4e5dNo error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:17.634563923 CEST8.8.8.8192.168.2.130xa622No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:17.643218040 CEST8.8.8.8192.168.2.130x2339No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:53.214303017 CEST8.8.8.8192.168.2.130x8326No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:53.223773956 CEST8.8.8.8192.168.2.130x2ec9No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:54.143008947 CEST8.8.8.8192.168.2.130x28b5No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:54.155002117 CEST8.8.8.8192.168.2.130x697aNo error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:55.075721025 CEST8.8.8.8192.168.2.130x2c50No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:55.084650040 CEST8.8.8.8192.168.2.130xf17eNo error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:56.425201893 CEST8.8.8.8192.168.2.130xee50No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:56.434050083 CEST8.8.8.8192.168.2.130x8267No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:57.358062029 CEST8.8.8.8192.168.2.130xbbc2No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:57.368350983 CEST8.8.8.8192.168.2.130xd7d6No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:58.276309013 CEST8.8.8.8192.168.2.130xf289No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:58.285409927 CEST8.8.8.8192.168.2.130x1cfdNo error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:59.204547882 CEST8.8.8.8192.168.2.130x7079No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false
                              Oct 24, 2024 15:43:59.215034962 CEST8.8.8.8192.168.2.130x7b26No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false

                              System Behavior

                              Start time (UTC):13:42:51
                              Start date (UTC):24/10/2024
                              Path:/tmp/vqkjf64.elf
                              Arguments:/tmp/vqkjf64.elf
                              File size:151096 bytes
                              MD5 hash:c82fae90d5afa7faa234118494709c0f

                              Start time (UTC):13:42:51
                              Start date (UTC):24/10/2024
                              Path:/tmp/vqkjf64.elf
                              Arguments:-
                              File size:151096 bytes
                              MD5 hash:c82fae90d5afa7faa234118494709c0f

                              Start time (UTC):13:42:51
                              Start date (UTC):24/10/2024
                              Path:/tmp/vqkjf64.elf
                              Arguments:-
                              File size:151096 bytes
                              MD5 hash:c82fae90d5afa7faa234118494709c0f