Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
Satan.sh4.elf

Overview

General Information

Sample name:Satan.sh4.elf
Analysis ID:1561567
MD5:07b06943894956ea32a91f710ea8d52f
SHA1:07792e889b4b5ad805a6a3bf396d8d4e1ed28fef
SHA256:bf8509f487041673a7d00e7b117dac810967acb7caa30c1e3cbca2d748370248
Tags:elfuser-abuse_ch
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1561567
Start date and time:2024-11-23 19:52:04 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 50s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Satan.sh4.elf
Detection:MAL
Classification:mal64.linELF@0/0@0/0
  • VT rate limit hit for: Satan.sh4.elf
Command:/tmp/Satan.sh4.elf
PID:6240
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
Satan.sh4.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x11078:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1108c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11104:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11118:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1112c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11140:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11154:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11168:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1117c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11190:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111f4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11208:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
SourceRuleDescriptionAuthorStrings
6240.1.00007f6770400000.00007f6770414000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x11078:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1108c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11104:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11118:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1112c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11140:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11154:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11168:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1117c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11190:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111f4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11208:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
6244.1.00007f6770400000.00007f6770414000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x11078:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1108c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11104:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11118:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1112c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11140:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11154:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11168:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1117c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11190:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111f4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11208:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
6254.1.00007f6770400000.00007f6770414000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x11078:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1108c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11104:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11118:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1112c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11140:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11154:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11168:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1117c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11190:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111f4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11208:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
6242.1.00007f6770400000.00007f6770414000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x11078:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1108c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11104:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11118:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1112c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11140:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11154:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11168:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1117c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11190:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111f4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11208:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: Satan.sh4.elf PID: 6240Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x208f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x20a3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x20b7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x20cb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x20df:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x20f3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2107:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x211b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x212f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2143:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2157:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x216b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x217f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2193:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x21a7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x21bb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x21cf:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x21e3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x21f7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x220b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x221f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Click to see the 3 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Satan.sh4.elfAvira: detected
Source: Satan.sh4.elfReversingLabs: Detection: 65%
Source: global trafficTCP traffic: 192.168.2.23:38370 -> 193.84.71.119:3778
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownTCP traffic detected without corresponding DNS query: 193.84.71.119
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: Satan.sh4.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6240.1.00007f6770400000.00007f6770414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6244.1.00007f6770400000.00007f6770414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6254.1.00007f6770400000.00007f6770414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6242.1.00007f6770400000.00007f6770414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Satan.sh4.elf PID: 6240, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Satan.sh4.elf PID: 6242, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Satan.sh4.elf PID: 6244, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Satan.sh4.elf PID: 6254, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Initial sampleString containing 'busybox' found: /bin/busybox
Source: Initial sampleString containing 'busybox' found: /proc/net/tcp.x86.x86_64.arm.arm5.arm6.arm7.mips.mipsel.sh4.ppc/proc/proc/%d/exe/proc/%s/statusrName:%s/bin/busybox/bin/systemd/usr/bintest/tmp/condi/tmp/zxcr9999/tmp/condinetwork/var/condibot/var/zxcr9999/var/CondiBot/var/condinet/bin/watchdog193.84.71.119
Source: ELF static info symbol of initial sample.symtab present: no
Source: Satan.sh4.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6240.1.00007f6770400000.00007f6770414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6244.1.00007f6770400000.00007f6770414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6254.1.00007f6770400000.00007f6770414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6242.1.00007f6770400000.00007f6770414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Satan.sh4.elf PID: 6240, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Satan.sh4.elf PID: 6242, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Satan.sh4.elf PID: 6244, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Satan.sh4.elf PID: 6254, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal64.linELF@0/0@0/0
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/1582/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/3088/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/230/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/110/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/231/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/111/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/232/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/1579/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/112/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/233/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/1699/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/113/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/234/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/1335/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/1698/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/114/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/235/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/1334/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/1576/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/2302/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/115/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/236/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/116/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/237/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/117/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/118/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/910/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/119/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/6226/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/912/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/10/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/2307/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/11/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/918/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/12/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/6240/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/13/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/14/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/15/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/6245/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/16/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/17/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/18/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/1594/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/120/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/121/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/1349/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/1/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/122/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/243/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/123/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/2/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/124/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/3/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/4/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/125/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/126/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/1344/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/1465/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/1586/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/127/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/6/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/248/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/128/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/249/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/1463/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/800/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/9/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/801/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/20/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/21/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/1900/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/22/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/23/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/24/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/25/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/26/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/27/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/28/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/29/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/491/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/250/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/130/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/251/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/252/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/132/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/253/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/254/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/255/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/4509/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/256/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/1599/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/257/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/1477/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/379/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/258/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/1476/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/259/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/1475/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/936/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/30/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/4504/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/2208/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/35/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)File opened: /proc/1809/statusJump to behavior
Source: /tmp/Satan.sh4.elf (PID: 6240)Queries kernel information via 'uname': Jump to behavior
Source: Satan.sh4.elf, 6240.1.0000563f9f38c000.0000563f9f416000.rw-.sdmp, Satan.sh4.elf, 6242.1.0000563f9f38c000.0000563f9f3ef000.rw-.sdmp, Satan.sh4.elf, 6244.1.0000563f9f38c000.0000563f9f3ef000.rw-.sdmp, Satan.sh4.elf, 6254.1.0000563f9f38c000.0000563f9f416000.rw-.sdmpBinary or memory string: ?V5!/etc/qemu-binfmt/sh4
Source: Satan.sh4.elf, 6240.1.00007ffd370df000.00007ffd37100000.rw-.sdmp, Satan.sh4.elf, 6242.1.00007ffd370df000.00007ffd37100000.rw-.sdmp, Satan.sh4.elf, 6244.1.00007ffd370df000.00007ffd37100000.rw-.sdmp, Satan.sh4.elf, 6254.1.00007ffd370df000.00007ffd37100000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sh4
Source: Satan.sh4.elf, 6240.1.0000563f9f38c000.0000563f9f416000.rw-.sdmp, Satan.sh4.elf, 6242.1.0000563f9f38c000.0000563f9f3ef000.rw-.sdmp, Satan.sh4.elf, 6244.1.0000563f9f38c000.0000563f9f3ef000.rw-.sdmp, Satan.sh4.elf, 6254.1.0000563f9f38c000.0000563f9f416000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sh4
Source: Satan.sh4.elf, 6240.1.00007ffd370df000.00007ffd37100000.rw-.sdmp, Satan.sh4.elf, 6242.1.00007ffd370df000.00007ffd37100000.rw-.sdmp, Satan.sh4.elf, 6244.1.00007ffd370df000.00007ffd37100000.rw-.sdmp, Satan.sh4.elf, 6254.1.00007ffd370df000.00007ffd37100000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-sh4/tmp/Satan.sh4.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Satan.sh4.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume Access1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1561567 Sample: Satan.sh4.elf Startdate: 23/11/2024 Architecture: LINUX Score: 64 20 193.84.71.119, 3778, 38370, 38372 RADIOCABLE-ASES Poland 2->20 22 109.202.202.202, 80 INIT7CH Switzerland 2->22 24 2 other IPs or domains 2->24 26 Malicious sample detected (through community Yara rule) 2->26 28 Antivirus / Scanner detection for submitted sample 2->28 30 Multi AV Scanner detection for submitted file 2->30 8 Satan.sh4.elf 2->8         started        signatures3 process4 process5 10 Satan.sh4.elf 8->10         started        12 Satan.sh4.elf 8->12         started        14 Satan.sh4.elf 8->14         started        process6 16 Satan.sh4.elf 10->16         started        18 Satan.sh4.elf 10->18         started       
SourceDetectionScannerLabelLink
Satan.sh4.elf66%ReversingLabsLinux.Trojan.Mirai
Satan.sh4.elf100%AviraLINUX/Mirai.bonb
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
193.84.71.119
unknownPoland
199478RADIOCABLE-ASESfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
  • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
193.84.71.119Satan.i686.elfGet hashmaliciousUnknownBrowse
    Satan.mpsl.elfGet hashmaliciousUnknownBrowse
      Satan.arm.elfGet hashmaliciousMiraiBrowse
        Satan.sh4.elfGet hashmaliciousUnknownBrowse
          Satan.arm7.elfGet hashmaliciousMiraiBrowse
            Satan.m68k.elfGet hashmaliciousMiraiBrowse
              Satan.ppc.elfGet hashmaliciousUnknownBrowse
                Satan.mips.elfGet hashmaliciousUnknownBrowse
                  Satan.arm6.elfGet hashmaliciousUnknownBrowse
                    Satan.x86_64.elfGet hashmaliciousUnknownBrowse
                      91.189.91.43main_arm.elfGet hashmaliciousMiraiBrowse
                        wheiuwa4.elfGet hashmaliciousUnknownBrowse
                          .i.elfGet hashmaliciousUnknownBrowse
                            sshd.elfGet hashmaliciousUnknownBrowse
                              sshd.elfGet hashmaliciousUnknownBrowse
                                sora.arm6.elfGet hashmaliciousMiraiBrowse
                                  wheiuwa4.elfGet hashmaliciousUnknownBrowse
                                    .i.elfGet hashmaliciousUnknownBrowse
                                      Mozi.m.elfGet hashmaliciousUnknownBrowse
                                        yakuza.m68k.elfGet hashmaliciousMiraiBrowse
                                          91.189.91.42main_ppc.elfGet hashmaliciousMiraiBrowse
                                            main_arm.elfGet hashmaliciousMiraiBrowse
                                              wheiuwa4.elfGet hashmaliciousUnknownBrowse
                                                .i.elfGet hashmaliciousUnknownBrowse
                                                  sshd.elfGet hashmaliciousUnknownBrowse
                                                    sshd.elfGet hashmaliciousUnknownBrowse
                                                      sora.arm6.elfGet hashmaliciousMiraiBrowse
                                                        wheiuwa4.elfGet hashmaliciousUnknownBrowse
                                                          .i.elfGet hashmaliciousUnknownBrowse
                                                            Mozi.m.elfGet hashmaliciousUnknownBrowse
                                                              No context
                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                              RADIOCABLE-ASESSatan.i686.elfGet hashmaliciousUnknownBrowse
                                                              • 193.84.71.119
                                                              Satan.mpsl.elfGet hashmaliciousUnknownBrowse
                                                              • 193.84.71.119
                                                              Satan.arm.elfGet hashmaliciousMiraiBrowse
                                                              • 193.84.71.119
                                                              Satan.sh4.elfGet hashmaliciousUnknownBrowse
                                                              • 193.84.71.119
                                                              Satan.arm7.elfGet hashmaliciousMiraiBrowse
                                                              • 193.84.71.119
                                                              Satan.m68k.elfGet hashmaliciousMiraiBrowse
                                                              • 193.84.71.119
                                                              Satan.ppc.elfGet hashmaliciousUnknownBrowse
                                                              • 193.84.71.119
                                                              Satan.mips.elfGet hashmaliciousUnknownBrowse
                                                              • 193.84.71.119
                                                              Satan.arm6.elfGet hashmaliciousUnknownBrowse
                                                              • 193.84.71.119
                                                              Satan.x86_64.elfGet hashmaliciousUnknownBrowse
                                                              • 193.84.71.119
                                                              CANONICAL-ASGBmain_ppc.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              main_arm.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              wheiuwa4.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              .i.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              sshd.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              sshd.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              sora.arm6.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              wheiuwa4.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              .i.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              Mozi.m.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              CANONICAL-ASGBmain_ppc.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              main_arm.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              wheiuwa4.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              .i.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              sshd.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              sshd.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              sora.arm6.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              wheiuwa4.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              .i.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              Mozi.m.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              INIT7CHmain_ppc.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              main_arm.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              wheiuwa4.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              .i.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              sshd.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              sshd.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              sora.arm6.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              wheiuwa4.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              .i.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              Mozi.m.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              No context
                                                              No context
                                                              No created / dropped files found
                                                              File type:ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
                                                              Entropy (8bit):6.604505444439499
                                                              TrID:
                                                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                              File name:Satan.sh4.elf
                                                              File size:82'652 bytes
                                                              MD5:07b06943894956ea32a91f710ea8d52f
                                                              SHA1:07792e889b4b5ad805a6a3bf396d8d4e1ed28fef
                                                              SHA256:bf8509f487041673a7d00e7b117dac810967acb7caa30c1e3cbca2d748370248
                                                              SHA512:5652ae9ae5b686f2dda8044173f966fe07d54168f465520cdb68d092dcc3800e3633c21499aa31ab7bfa19883f38ac46090817d854d3a30586c05779258665df
                                                              SSDEEP:1536:UR5/Vxvh7ZyIzFZZclZcHXJP/cmPdGkMxkr:q/L57ZyIzFbEmpZQxM
                                                              TLSH:A6839D21F0141CE6C8630674F0E8ED75471369F522A62CB26EEEE9A184F368DF44EF94
                                                              File Content Preview:.ELF..............*.......@.4...LA......4. ...(...............@...@.l4..l4...............@...@B..@B.0...............Q.td..............................././"O.n......#.*@........#.*@l...&O.n.l..................................././.../.a"O.!...n...a.b("...q.

                                                              ELF header

                                                              Class:ELF32
                                                              Data:2's complement, little endian
                                                              Version:1 (current)
                                                              Machine:<unknown>
                                                              Version Number:0x1
                                                              Type:EXEC (Executable file)
                                                              OS/ABI:UNIX - System V
                                                              ABI Version:0
                                                              Entry Point Address:0x4001a0
                                                              Flags:0xc
                                                              ELF Header Size:52
                                                              Program Header Offset:52
                                                              Program Header Size:32
                                                              Number of Program Headers:3
                                                              Section Header Offset:82252
                                                              Section Header Size:40
                                                              Number of Section Headers:10
                                                              Header String Table Index:9
                                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                              NULL0x00x00x00x00x0000
                                                              .initPROGBITS0x4000940x940x2e0x00x6AX004
                                                              .textPROGBITS0x4000e00xe00x10e800x00x6AX0032
                                                              .finiPROGBITS0x410f600x10f600x220x00x6AX004
                                                              .rodataPROGBITS0x410f840x10f840x24e80x00x2A004
                                                              .ctorsPROGBITS0x4240dc0x140dc0x80x00x3WA004
                                                              .dtorsPROGBITS0x4240e40x140e40x80x00x3WA004
                                                              .dataPROGBITS0x4240f00x140f00x1c0x00x3WA004
                                                              .bssNOBITS0x42410c0x1410c0xaec0x00x3WA004
                                                              .shstrtabSTRTAB0x00x1410c0x3e0x00x0001
                                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                              LOAD0x00x4000000x4000000x1346c0x1346c6.77500x5R E0x10000.init .text .fini .rodata
                                                              LOAD0x140dc0x4240dc0x4240dc0x300xb1c2.52850x6RW 0x10000.ctors .dtors .data .bss
                                                              GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Nov 23, 2024 19:52:51.402385950 CET383703778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:52:51.526242018 CET377838370193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:52:51.526330948 CET383703778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:52:51.535614014 CET383703778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:52:51.661292076 CET377838370193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:52:51.661358118 CET383703778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:52:51.788260937 CET377838370193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:52:51.973301888 CET43928443192.168.2.2391.189.91.42
                                                              Nov 23, 2024 19:52:53.885695934 CET377838370193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:52:53.886240005 CET383703778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:52:54.024185896 CET377838370193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:52:54.887795925 CET383723778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:52:55.060094118 CET377838372193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:52:55.060214996 CET383723778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:52:55.061206102 CET383723778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:52:55.310348988 CET377838372193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:52:55.310482025 CET383723778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:52:55.439275026 CET377838372193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:52:57.294713974 CET383743778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:52:57.348507881 CET42836443192.168.2.2391.189.91.43
                                                              Nov 23, 2024 19:52:57.422826052 CET377838374193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:52:57.422885895 CET383743778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:52:57.441612959 CET383743778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:52:57.556001902 CET377838372193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:52:57.556107044 CET383723778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:52:57.599812984 CET377838374193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:52:57.599870920 CET383743778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:52:57.827945948 CET377838372193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:52:57.828843117 CET377838374193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:52:58.557687998 CET383763778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:52:58.628350019 CET4251680192.168.2.23109.202.202.202
                                                              Nov 23, 2024 19:52:58.682259083 CET377838376193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:52:58.682365894 CET383763778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:52:58.683419943 CET383763778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:52:58.920471907 CET377838376193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:52:58.920623064 CET383763778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:52:59.051934004 CET377838376193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:52:59.718673944 CET377838374193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:52:59.719186068 CET383743778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:52:59.844702005 CET377838374193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:00.720752001 CET383783778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:00.860152960 CET377838378193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:00.860388994 CET383783778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:00.861228943 CET383783778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:00.998317957 CET377838378193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:00.998497963 CET383783778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:01.119927883 CET377838378193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:01.196643114 CET377838376193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:01.196960926 CET383763778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:01.316528082 CET377838376193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:02.198577881 CET383803778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:02.321492910 CET377838380193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:02.321739912 CET383803778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:02.322652102 CET383803778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:02.442126989 CET377838380193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:02.442266941 CET383803778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:02.561851025 CET377838380193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:03.172044992 CET377838378193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:03.172523022 CET383783778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:03.300079107 CET377838378193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:04.174022913 CET383823778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:04.301023960 CET377838382193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:04.301198006 CET383823778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:04.302409887 CET383823778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:04.428525925 CET377838382193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:04.428673983 CET383823778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:04.557497978 CET377838382193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:04.640716076 CET377838380193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:04.640985966 CET383803778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:04.761203051 CET377838380193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:05.642573118 CET383843778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:05.782427073 CET377838384193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:05.782705069 CET383843778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:05.783916950 CET383843778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:05.921252012 CET377838384193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:05.921418905 CET383843778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:06.045510054 CET377838384193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:06.593930960 CET377838382193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:06.594271898 CET383823778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:06.715620041 CET377838382193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:07.596282005 CET383863778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:07.787851095 CET377838386193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:07.788093090 CET383863778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:07.789160013 CET383863778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:07.916610003 CET377838386193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:07.916762114 CET383863778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:08.054217100 CET377838386193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:08.149966002 CET377838384193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:08.150278091 CET383843778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:08.283776999 CET377838384193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:09.152139902 CET383883778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:09.307115078 CET377838388193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:09.307346106 CET383883778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:09.308813095 CET383883778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:09.433592081 CET377838388193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:09.433717966 CET383883778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:09.800107002 CET377838388193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:10.118743896 CET377838386193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:10.118974924 CET383863778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:10.285510063 CET377838386193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:11.121721029 CET383903778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:11.344916105 CET377838390193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:11.345175028 CET383903778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:11.346724033 CET383903778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:11.466483116 CET377838390193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:11.466665030 CET383903778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:11.587174892 CET377838390193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:11.609632969 CET377838388193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:11.609993935 CET383883778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:11.755820990 CET377838388193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:12.194642067 CET43928443192.168.2.2391.189.91.42
                                                              Nov 23, 2024 19:53:12.611968040 CET383923778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:12.754168987 CET377838392193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:12.754419088 CET383923778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:12.755829096 CET383923778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:12.894469023 CET377838392193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:12.894579887 CET383923778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:13.027631998 CET377838392193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:13.712527990 CET377838390193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:13.712815046 CET383903778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:13.952941895 CET377838390193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:14.714951992 CET383943778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:14.873183012 CET377838394193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:14.873414993 CET383943778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:14.874939919 CET383943778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:15.030599117 CET377838394193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:15.030730963 CET383943778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:15.118740082 CET377838392193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:15.120311975 CET383923778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:15.194379091 CET377838394193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:15.247245073 CET377838392193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:16.122721910 CET383963778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:16.249438047 CET377838396193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:16.249553919 CET383963778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:16.250561953 CET383963778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:16.403521061 CET377838396193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:16.403769970 CET383963778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:16.539670944 CET377838396193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:17.228230953 CET377838394193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:17.228447914 CET383943778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:17.349565983 CET377838394193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:18.230911016 CET383983778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:18.353249073 CET377838398193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:18.353399038 CET383983778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:18.354850054 CET383983778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:18.476192951 CET377838398193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:18.476321936 CET383983778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:18.596719027 CET377838398193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:18.650033951 CET377838396193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:18.650185108 CET383963778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:18.770311117 CET377838396193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:19.652601957 CET384003778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:19.774899960 CET377838400193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:19.775099993 CET384003778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:19.776603937 CET384003778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:19.896315098 CET377838400193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:19.896553040 CET384003778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:20.017837048 CET377838400193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:20.713054895 CET377838398193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:20.713185072 CET383983778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:20.832720041 CET377838398193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:21.715374947 CET384023778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:21.872236967 CET377838402193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:21.872493029 CET384023778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:21.874156952 CET384023778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:21.999952078 CET377838402193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:22.000199080 CET384023778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:22.094234943 CET377838400193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:22.094475031 CET384003778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:22.119673967 CET377838402193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:22.239584923 CET377838400193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:23.097012997 CET384043778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:23.220838070 CET377838404193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:23.220990896 CET384043778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:23.222280979 CET384043778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:23.348448992 CET377838404193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:23.348561049 CET384043778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:23.470268965 CET377838404193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:24.172312021 CET377838402193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:24.172575951 CET384023778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:24.292260885 CET377838402193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:24.480920076 CET42836443192.168.2.2391.189.91.43
                                                              Nov 23, 2024 19:53:25.174700975 CET384063778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:25.395632982 CET377838406193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:25.395797968 CET384063778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:25.397268057 CET384063778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:25.533721924 CET377838406193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:25.533916950 CET384063778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:25.588568926 CET377838404193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:25.588793993 CET384043778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:25.653484106 CET377838406193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:25.720870972 CET377838404193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:26.590257883 CET384083778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:26.716650009 CET377838408193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:26.716814995 CET384083778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:26.717901945 CET384083778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:26.964747906 CET377838408193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:26.964890003 CET384083778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:27.084706068 CET377838408193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:27.813179016 CET377838406193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:27.813354015 CET384063778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:27.977165937 CET377838406193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:28.576298952 CET4251680192.168.2.23109.202.202.202
                                                              Nov 23, 2024 19:53:28.815080881 CET384103778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:28.937076092 CET377838410193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:28.937186003 CET384103778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:28.938164949 CET384103778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:29.083400011 CET377838410193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:29.083548069 CET384103778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:29.214149952 CET377838408193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:29.214312077 CET384083778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:29.330254078 CET377838410193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:29.345048904 CET377838408193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:30.216227055 CET384123778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:30.360739946 CET377838412193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:30.360867023 CET384123778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:30.361989021 CET384123778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:30.485269070 CET377838412193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:30.485400915 CET384123778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:30.605532885 CET377838412193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:31.323201895 CET377838410193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:31.323550940 CET384103778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:31.470805883 CET377838410193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:32.325716019 CET384143778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:32.446193933 CET377838414193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:32.446329117 CET384143778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:32.447525978 CET384143778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:32.568309069 CET377838414193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:32.568492889 CET384143778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:32.681982040 CET377838412193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:32.682221889 CET384123778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:32.689953089 CET377838414193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:32.803277969 CET377838412193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:33.684636116 CET384163778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:33.844343901 CET377838416193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:33.844846964 CET384163778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:33.846005917 CET384163778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:33.966739893 CET377838416193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:33.967029095 CET384163778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:34.086920977 CET377838416193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:34.813199043 CET377838414193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:34.813499928 CET384143778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:34.933072090 CET377838414193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:35.815623045 CET384183778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:35.935774088 CET377838418193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:35.935919046 CET384183778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:35.937258005 CET384183778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:36.073307991 CET377838418193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:36.073504925 CET384183778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:36.141313076 CET377838416193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:36.141623974 CET384163778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:36.208127022 CET377838418193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:36.263925076 CET377838416193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:37.143779993 CET384203778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:37.302098036 CET377838420193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:37.302283049 CET384203778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:37.303945065 CET384203778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:37.556819916 CET377838420193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:37.557102919 CET384203778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:37.676700115 CET377838420193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:38.275527000 CET377838418193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:38.275800943 CET384183778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:38.395268917 CET377838418193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:39.277959108 CET384223778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:39.401170969 CET377838422193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:39.401431084 CET384223778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:39.402925968 CET384223778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:39.529377937 CET377838422193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:39.529524088 CET384223778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:39.655946016 CET377838422193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:39.876183033 CET377838420193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:39.876447916 CET384203778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:39.996319056 CET377838420193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:40.878249884 CET384243778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:41.004596949 CET377838424193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:41.004827976 CET384243778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:41.006202936 CET384243778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:41.132400036 CET377838424193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:41.132606030 CET384243778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:41.252199888 CET377838424193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:41.705269098 CET377838422193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:41.705601931 CET384223778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:41.831950903 CET377838422193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:42.707773924 CET384263778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:42.828681946 CET377838426193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:42.828835011 CET384263778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:42.830221891 CET384263778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:42.964827061 CET377838426193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:42.965017080 CET384263778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:43.116488934 CET377838426193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:43.338416100 CET377838424193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:43.338634014 CET384243778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:43.471618891 CET377838424193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:44.340576887 CET384283778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:44.460799932 CET377838428193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:44.461060047 CET384283778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:44.462239981 CET384283778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:44.634089947 CET377838428193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:44.634248972 CET384283778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:44.896739960 CET377838428193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:45.169504881 CET377838426193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:45.169785976 CET384263778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:45.295766115 CET377838426193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:46.171885014 CET384303778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:46.457484961 CET377838430193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:46.457799911 CET384303778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:46.459088087 CET384303778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:46.578613997 CET377838430193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:46.578862906 CET384303778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:46.699713945 CET377838430193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:46.838341951 CET377838428193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:46.838794947 CET384283778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:46.963984013 CET377838428193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:47.841025114 CET384323778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:47.967801094 CET377838432193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:47.968153000 CET384323778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:47.969367027 CET384323778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:48.252751112 CET377838432193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:48.253014088 CET384323778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:48.372646093 CET377838432193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:48.854157925 CET377838430193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:48.854688883 CET384303778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:48.986730099 CET377838430193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:49.856635094 CET384343778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:49.998691082 CET377838434193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:49.998959064 CET384343778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:50.000811100 CET384343778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:50.120254993 CET377838434193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:50.120578051 CET384343778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:50.240070105 CET377838434193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:50.427017927 CET377838432193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:50.427475929 CET384323778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:50.570811033 CET377838432193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:51.429708004 CET384363778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:51.549350977 CET377838436193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:51.549479008 CET384363778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:51.550843954 CET384363778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:51.670304060 CET377838436193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:51.670559883 CET384363778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:51.790083885 CET377838436193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:52.401614904 CET377838434193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:52.401856899 CET384343778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:52.542812109 CET377838434193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:53.148952007 CET43928443192.168.2.2391.189.91.42
                                                              Nov 23, 2024 19:53:53.404031038 CET384383778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:53.550380945 CET377838438193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:53.550462961 CET384383778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:53.551630020 CET384383778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:53.711888075 CET377838438193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:53.711978912 CET384383778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:53.831805944 CET377838438193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:53.850620031 CET377838436193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:53.850734949 CET384363778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:53.971069098 CET377838436193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:54.852574110 CET384403778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:54.977758884 CET377838440193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:54.977916002 CET384403778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:54.979108095 CET384403778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:55.099839926 CET377838440193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:55.100013018 CET384403778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:55.219948053 CET377838440193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:55.916517019 CET377838438193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:55.916676044 CET384383778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:56.038239956 CET377838438193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:56.918931007 CET384423778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:57.045428991 CET377838442193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:57.045550108 CET384423778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:57.046781063 CET384423778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:57.212872028 CET377838442193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:57.213062048 CET384423778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:57.313769102 CET377838440193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:57.314146996 CET384403778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:57.350075960 CET377838442193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:57.434959888 CET377838440193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:58.316416025 CET384443778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:58.448781013 CET377838444193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:58.448914051 CET384443778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:58.450254917 CET384443778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:58.771599054 CET377838444193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:58.771862984 CET384443778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:58.893315077 CET377838444193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:59.428841114 CET377838442193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:53:59.429094076 CET384423778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:53:59.592823982 CET377838442193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:00.431045055 CET384463778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:00.571017981 CET377838446193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:00.571204901 CET384463778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:00.572423935 CET384463778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:00.778287888 CET377838446193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:00.778510094 CET384463778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:00.816450119 CET377838444193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:00.816622019 CET384443778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:00.921171904 CET377838446193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:00.941384077 CET377838444193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:01.819040060 CET384483778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:01.962263107 CET377838448193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:01.962405920 CET384483778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:01.964063883 CET384483778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:02.084696054 CET377838448193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:02.084876060 CET384483778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:02.209722996 CET377838448193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:02.985934019 CET377838446193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:02.986201048 CET384463778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:03.121670008 CET377838446193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:03.988394976 CET384503778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:04.256495953 CET377838450193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:04.256613016 CET384503778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:04.258081913 CET384503778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:04.321875095 CET377838448193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:04.322072029 CET384483778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:04.422621012 CET377838450193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:04.422805071 CET384503778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:04.494951963 CET377838448193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:04.616262913 CET377838450193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:05.323967934 CET384523778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:05.443475008 CET377838452193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:05.443687916 CET384523778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:05.445188999 CET384523778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:05.591136932 CET377838452193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:05.591250896 CET384523778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:05.715876102 CET377838452193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:06.548108101 CET377838450193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:06.548504114 CET384503778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:06.689691067 CET377838450193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:07.550501108 CET384543778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:07.670114994 CET377838454193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:07.670207977 CET384543778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:07.671080112 CET384543778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:07.790735006 CET377838454193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:07.790853977 CET384543778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:07.854100943 CET377838452193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:07.854222059 CET384523778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:07.920517921 CET377838454193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:07.975105047 CET377838452193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:08.855990887 CET384563778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:08.982991934 CET377838456193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:08.983088970 CET384563778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:08.984467030 CET384563778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:09.151473045 CET377838456193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:09.151684046 CET384563778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:09.277457952 CET377838456193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:09.985707998 CET377838454193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:09.985918999 CET384543778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:10.105746984 CET377838454193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:10.988518000 CET384583778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:11.108253002 CET377838458193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:11.108400106 CET384583778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:11.109555960 CET384583778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:11.235452890 CET377838458193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:11.235608101 CET384583778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:11.313930035 CET377838456193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:11.314285994 CET384563778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:11.357418060 CET377838458193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:11.474735975 CET377838456193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:12.316740990 CET384603778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:12.466603994 CET377838460193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:12.466861010 CET384603778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:12.468060970 CET384603778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:12.802905083 CET377838460193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:12.803075075 CET384603778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:12.922626019 CET377838460193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:13.510822058 CET377838458193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:13.511188984 CET384583778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:13.682327032 CET377838458193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:14.513223886 CET384623778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:14.636302948 CET377838462193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:14.636531115 CET384623778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:14.637619972 CET384623778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:14.776473999 CET377838462193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:14.776664019 CET384623778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:14.898986101 CET377838462193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:15.041899920 CET377838460193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:15.042274952 CET384603778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:15.162405968 CET377838460193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:16.044821978 CET384643778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:16.164449930 CET377838464193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:16.164767027 CET384643778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:16.166249990 CET384643778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:16.289041042 CET377838464193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:16.289324999 CET384643778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:16.409030914 CET377838464193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:16.958604097 CET377838462193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:16.958930969 CET384623778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:17.081682920 CET377838462193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:17.960560083 CET384663778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:18.101372004 CET377838466193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:18.101486921 CET384663778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:18.102380037 CET384663778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:18.228046894 CET377838466193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:18.228208065 CET384663778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:18.348421097 CET377838466193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:18.497014999 CET377838464193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:18.497234106 CET384643778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:18.616889000 CET377838464193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:19.499588013 CET384683778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:19.629575968 CET377838468193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:19.629889011 CET384683778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:19.631170034 CET384683778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:19.875535011 CET377838468193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:19.875802994 CET384683778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:20.037748098 CET377838468193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:20.409008026 CET377838466193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:20.409337044 CET384663778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:20.535708904 CET377838466193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:21.411309004 CET384703778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:21.530919075 CET377838470193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:21.531348944 CET384703778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:21.532675028 CET384703778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:21.654783010 CET377838470193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:21.655149937 CET384703778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:21.782867908 CET377838470193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:22.100122929 CET377838468193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:22.100434065 CET384683778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:22.220000982 CET377838468193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:23.103030920 CET384723778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:23.229475975 CET377838472193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:23.229722023 CET384723778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:23.231190920 CET384723778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:23.356456995 CET377838472193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:23.356681108 CET384723778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:23.477370977 CET377838472193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:23.993901968 CET377838470193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:23.994357109 CET384703778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:24.120589972 CET377838470193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:24.997015953 CET384743778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:25.116810083 CET377838474193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:25.117053986 CET384743778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:25.118581057 CET384743778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:25.238576889 CET377838474193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:25.238823891 CET384743778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:25.360918045 CET377838474193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:25.682796001 CET377838472193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:25.683199883 CET384723778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:25.809525013 CET377838472193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:26.686333895 CET384763778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:26.809700012 CET377838476193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:26.809870005 CET384763778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:26.811501026 CET384763778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:26.936758041 CET377838476193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:26.936929941 CET384763778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:27.058777094 CET377838476193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:27.439496994 CET377838474193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:27.440098047 CET384743778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:27.562284946 CET377838474193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:28.442195892 CET384783778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:28.562195063 CET377838478193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:28.562396049 CET384783778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:28.564470053 CET384783778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:28.687175035 CET377838478193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:28.687567949 CET384783778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:28.813987017 CET377838478193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:29.245254040 CET377838476193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:29.245757103 CET384763778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:29.371367931 CET377838476193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:30.248490095 CET384803778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:30.370415926 CET377838480193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:30.370763063 CET384803778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:30.372437000 CET384803778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:30.492093086 CET377838480193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:30.492371082 CET384803778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:30.612060070 CET377838480193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:30.917341948 CET377838478193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:30.917679071 CET384783778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:31.044220924 CET377838478193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:31.919578075 CET384823778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:32.046196938 CET377838482193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:32.046322107 CET384823778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:32.047559023 CET384823778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:32.172991991 CET377838482193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:32.173429966 CET384823778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:32.293123960 CET377838482193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:32.690254927 CET377838480193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:32.690861940 CET384803778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:32.816169977 CET377838480193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:33.693377972 CET384843778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:33.815639973 CET377838484193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:33.815929890 CET384843778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:33.817430973 CET384843778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:33.943809986 CET377838484193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:33.944242954 CET384843778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:34.070863962 CET377838484193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:34.346091032 CET377838482193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:34.346507072 CET384823778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:34.466167927 CET377838482193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:35.348622084 CET384863778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:35.472420931 CET377838486193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:35.472769022 CET384863778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:35.473941088 CET384863778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:35.593560934 CET377838486193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:35.594018936 CET384863778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:35.713881016 CET377838486193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:36.128098965 CET377838484193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:36.128701925 CET384843778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:36.249584913 CET377838484193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:37.131447077 CET384883778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:37.258038998 CET377838488193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:37.258275986 CET384883778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:37.260027885 CET384883778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:37.385947943 CET377838488193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:37.386151075 CET384883778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:37.509579897 CET377838488193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:37.808331013 CET377838486193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:37.808720112 CET384863778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:37.930422068 CET377838486193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:38.810900927 CET384903778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:38.930838108 CET377838490193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:38.931137085 CET384903778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:38.932398081 CET384903778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:39.052073002 CET377838490193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:39.052377939 CET384903778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:39.174823999 CET377838490193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:39.595761061 CET377838488193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:39.596187115 CET384883778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:39.716759920 CET377838488193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:40.598859072 CET384923778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:40.723407984 CET377838492193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:40.723571062 CET384923778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:40.724854946 CET384923778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:40.844394922 CET377838492193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:40.844543934 CET384923778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:40.964895010 CET377838492193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:41.323851109 CET377838490193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:41.324151039 CET384903778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:41.446568012 CET377838490193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:42.326575994 CET384943778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:42.446177959 CET377838494193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:42.446285963 CET384943778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:42.447556019 CET384943778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:42.567045927 CET377838494193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:42.567265034 CET384943778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:42.687329054 CET377838494193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:43.017774105 CET377838492193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:43.018323898 CET384923778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:43.138024092 CET377838492193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:44.020718098 CET384963778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:44.140553951 CET377838496193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:44.140733957 CET384963778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:44.142029047 CET384963778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:44.261575937 CET377838496193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:44.261867046 CET384963778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:44.381433964 CET377838496193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:44.839481115 CET377838494193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:44.839776993 CET384943778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:44.964411020 CET377838494193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:45.842396021 CET384983778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:45.963669062 CET377838498193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:45.963907003 CET384983778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:45.964978933 CET384983778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:46.088172913 CET377838498193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:46.088428974 CET384983778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:46.213884115 CET377838498193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:46.538424969 CET377838496193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:46.538899899 CET384963778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:46.658688068 CET377838496193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:47.541109085 CET385003778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:47.665096045 CET377838500193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:47.665468931 CET385003778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:47.666834116 CET385003778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:47.788729906 CET377838500193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:47.789136887 CET385003778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:47.911966085 CET377838500193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:48.370872974 CET377838498193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:48.371351957 CET384983778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:48.491204023 CET377838498193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:49.373912096 CET385023778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:49.495309114 CET377838502193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:49.495502949 CET385023778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:49.497028112 CET385023778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:49.617153883 CET377838502193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:49.617288113 CET385023778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:49.737409115 CET377838502193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:50.027103901 CET377838500193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:50.027549028 CET385003778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:50.152957916 CET377838500193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:51.030292034 CET385043778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:51.150002956 CET377838504193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:51.150321960 CET385043778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:51.152179956 CET385043778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:51.272449017 CET377838504193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:51.272670984 CET385043778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:51.396075964 CET377838504193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:51.783673048 CET377838502193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:51.784262896 CET385023778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:51.904124975 CET377838502193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:52.786801100 CET385063778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:52.909919977 CET377838506193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:52.910093069 CET385063778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:52.910866976 CET385063778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:53.037246943 CET377838506193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:53.037389040 CET385063778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:53.163845062 CET377838506193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:53.486848116 CET377838504193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:53.487345934 CET385043778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:53.606939077 CET377838504193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:54.490267038 CET385083778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:54.613734007 CET377838508193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:54.614216089 CET385083778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:54.616245031 CET385083778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:54.742548943 CET377838508193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:54.742939949 CET385083778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:54.869587898 CET377838508193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:55.295751095 CET377838506193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:55.296298981 CET385063778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:55.418045044 CET377838506193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:56.298351049 CET385103778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:56.422749043 CET377838510193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:56.423054934 CET385103778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:56.424474955 CET385103778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:56.546385050 CET377838510193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:56.546632051 CET385103778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:56.666264057 CET377838510193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:57.074206114 CET377838508193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:57.074650049 CET385083778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:57.198148966 CET377838508193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:58.077306032 CET385123778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:58.199604988 CET377838512193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:58.200037003 CET385123778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:58.201637983 CET385123778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:58.328026056 CET377838512193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:58.328244925 CET385123778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:58.450810909 CET377838512193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:58.763056993 CET377838510193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:58.763540983 CET385103778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:58.883945942 CET377838510193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:59.765079021 CET385143778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:59.890505075 CET377838514193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:54:59.890722036 CET385143778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:54:59.891992092 CET385143778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:55:00.011627913 CET377838514193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:55:00.011853933 CET385143778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:55:00.134406090 CET377838514193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:55:00.580848932 CET377838512193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:55:00.581454039 CET385123778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:55:00.703038931 CET377838512193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:55:01.583277941 CET385163778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:55:01.703203917 CET377838516193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:55:01.703362942 CET385163778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:55:01.704457998 CET385163778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:55:01.824052095 CET377838516193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:55:01.824220896 CET385163778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:55:01.943967104 CET377838516193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:55:02.174824953 CET377838514193.84.71.119192.168.2.23
                                                              Nov 23, 2024 19:55:02.175127983 CET385143778192.168.2.23193.84.71.119
                                                              Nov 23, 2024 19:55:02.301594019 CET377838514193.84.71.119192.168.2.23

                                                              System Behavior

                                                              Start time (UTC):18:52:50
                                                              Start date (UTC):23/11/2024
                                                              Path:/tmp/Satan.sh4.elf
                                                              Arguments:/tmp/Satan.sh4.elf
                                                              File size:4139976 bytes
                                                              MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                                              Start time (UTC):18:52:50
                                                              Start date (UTC):23/11/2024
                                                              Path:/tmp/Satan.sh4.elf
                                                              Arguments:-
                                                              File size:4139976 bytes
                                                              MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                                              Start time (UTC):18:52:50
                                                              Start date (UTC):23/11/2024
                                                              Path:/tmp/Satan.sh4.elf
                                                              Arguments:-
                                                              File size:4139976 bytes
                                                              MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                                              Start time (UTC):18:52:50
                                                              Start date (UTC):23/11/2024
                                                              Path:/tmp/Satan.sh4.elf
                                                              Arguments:-
                                                              File size:4139976 bytes
                                                              MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                                              Start time (UTC):18:52:56
                                                              Start date (UTC):23/11/2024
                                                              Path:/tmp/Satan.sh4.elf
                                                              Arguments:-
                                                              File size:4139976 bytes
                                                              MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                                              Start time (UTC):18:52:56
                                                              Start date (UTC):23/11/2024
                                                              Path:/tmp/Satan.sh4.elf
                                                              Arguments:-
                                                              File size:4139976 bytes
                                                              MD5 hash:8943e5f8f8c280467b4472c15ae93ba9