Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
zersh4.elf

Overview

General Information

Sample name:zersh4.elf
Analysis ID:1604431
MD5:9b9094f3ae2242597704fc6599329737
SHA1:af6b42528082d32ad418077b8697073bbf0ec937
SHA256:ea8b27801b58bb631eb540cf59c7f0bd324c92994967bc0e45496f1ea6f95b68
Tags:elfuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Sample deletes itself
Sends malformed DNS queries
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1604431
Start date and time:2025-02-01 14:45:21 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 41s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:zersh4.elf
Detection:MAL
Classification:mal56.troj.evad.linELF@0/0@27/0
Command:/tmp/zersh4.elf
PID:5443
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
gosh that chinese family at the other table sure ate a lot
Standard Error:
  • system is lnxubuntu20
  • zersh4.elf (PID: 5443, Parent: 5364, MD5: 8943e5f8f8c280467b4472c15ae93ba9) Arguments: /tmp/zersh4.elf
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: zersh4.elfVirustotal: Detection: 25%Perma Link
Source: zersh4.elfReversingLabs: Detection: 21%

Networking

barindex
Source: global trafficDNS traffic detected: malformed DNS query: serisbot.geek. [malformed]
Source: global trafficTCP traffic: 192.168.2.13:34002 -> 209.38.56.135:1440
Source: global trafficTCP traffic: 192.168.2.13:33192 -> 146.190.204.203:1440
Source: global trafficTCP traffic: 192.168.2.13:43994 -> 68.183.244.135:1440
Source: global trafficTCP traffic: 192.168.2.13:39168 -> 64.225.86.206:1440
Source: global trafficTCP traffic: 192.168.2.13:51684 -> 209.38.188.134:1440
Source: /tmp/zersh4.elf (PID: 5443)Socket: 127.0.0.1:39148Jump to behavior
Source: global trafficTCP traffic: 192.168.2.13:48202 -> 185.125.190.26:443
Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
Source: unknownUDP traffic detected without corresponding DNS query: 152.53.15.127
Source: unknownUDP traffic detected without corresponding DNS query: 152.53.15.127
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 202.61.197.122
Source: unknownUDP traffic detected without corresponding DNS query: 168.235.111.72
Source: unknownUDP traffic detected without corresponding DNS query: 168.235.111.72
Source: unknownUDP traffic detected without corresponding DNS query: 168.235.111.72
Source: unknownUDP traffic detected without corresponding DNS query: 168.235.111.72
Source: unknownUDP traffic detected without corresponding DNS query: 168.235.111.72
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 152.53.15.127
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: global trafficDNS traffic detected: DNS query: serisontop.dyn
Source: global trafficDNS traffic detected: DNS query: serisbot.geek. [malformed]
Source: unknownNetwork traffic detected: HTTP traffic on port 48202 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal56.troj.evad.linELF@0/0@27/0

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/zersh4.elf (PID: 5443)File: /tmp/zersh4.elfJump to behavior
Source: /tmp/zersh4.elf (PID: 5443)Queries kernel information via 'uname': Jump to behavior
Source: zersh4.elf, 5443.1.0000555745271000.00005557452d4000.rw-.sdmpBinary or memory string: 5'EWU5!/etc/qemu-binfmt/sh4
Source: zersh4.elf, 5443.1.00007ffc9597b000.00007ffc9599c000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sh4
Source: zersh4.elf, 5443.1.0000555745271000.00005557452d4000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sh4
Source: zersh4.elf, 5443.1.00007ffc9597b000.00007ffc9599c000.rw-.sdmpBinary or memory string: )x86_64/usr/bin/qemu-sh4/tmp/zersh4.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/zersh4.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1604431 Sample: zersh4.elf Startdate: 01/02/2025 Architecture: LINUX Score: 56 15 serisbot.geek. [malformed] 2->15 17 serisontop.dyn 146.190.204.203, 1440, 33192, 33194 UUNETUS United States 2->17 19 5 other IPs or domains 2->19 21 Multi AV Scanner detection for submitted file 2->21 8 zersh4.elf 2->8         started        signatures3 23 Sends malformed DNS queries 15->23 process4 signatures5 25 Sample deletes itself 8->25 11 zersh4.elf 8->11         started        process6 process7 13 zersh4.elf 11->13         started       
SourceDetectionScannerLabelLink
zersh4.elf25%VirustotalBrowse
zersh4.elf21%ReversingLabsLinux.Backdoor.Gafgyt
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
serisontop.dyn
146.190.204.203
truefalse
    high
    serisbot.geek. [malformed]
    unknown
    unknownfalse
      high
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      64.225.86.206
      unknownUnited States
      14061DIGITALOCEAN-ASNUSfalse
      146.190.204.203
      serisontop.dynUnited States
      702UUNETUSfalse
      185.125.190.26
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      209.38.56.135
      unknownUnited States
      7018ATT-INTERNET4USfalse
      68.183.244.135
      unknownUnited States
      14061DIGITALOCEAN-ASNUSfalse
      209.38.188.134
      unknownUnited States
      7018ATT-INTERNET4USfalse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      185.125.190.26arm5.elfGet hashmaliciousMiraiBrowse
        spc.elfGet hashmaliciousMiraiBrowse
          yakuza.x86.elfGet hashmaliciousGafgyt, MiraiBrowse
            176.65.134.111-boatnet.arm6-2025-02-01T00_59_15.elfGet hashmaliciousMiraiBrowse
              na.elfGet hashmaliciousPrometeiBrowse
                i686.elfGet hashmaliciousMiraiBrowse
                  x86_64.elfGet hashmaliciousMirai, OkiruBrowse
                    na.elfGet hashmaliciousPrometeiBrowse
                      hold.x86_64.elfGet hashmaliciousOkiruBrowse
                        hold.m68k.elfGet hashmaliciousMirai, OkiruBrowse
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          serisontop.dynsplppc.elfGet hashmaliciousUnknownBrowse
                          • 209.38.188.134
                          nabppc.elfGet hashmaliciousUnknownBrowse
                          • 68.183.244.135
                          splarm.elfGet hashmaliciousUnknownBrowse
                          • 64.225.86.206
                          nklx86.elfGet hashmaliciousUnknownBrowse
                          • 146.190.204.203
                          193.143.1.32-mips-2025-02-01T10_01_48.elfGet hashmaliciousUnknownBrowse
                          • 64.225.86.206
                          193.143.1.32-arm-2025-02-01T10_01_48.elfGet hashmaliciousUnknownBrowse
                          • 146.190.204.203
                          193.143.1.32-x86-2025-02-01T10_16_50.elfGet hashmaliciousUnknownBrowse
                          • 64.225.86.206
                          splm68k.elfGet hashmaliciousUnknownBrowse
                          • 154.216.16.250
                          nklarm7.elfGet hashmaliciousUnknownBrowse
                          • 154.216.16.244
                          splarm7.elfGet hashmaliciousUnknownBrowse
                          • 209.38.192.73
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          UUNETUSnabppc.elfGet hashmaliciousUnknownBrowse
                          • 194.174.26.76
                          nklx86.elfGet hashmaliciousUnknownBrowse
                          • 108.31.206.214
                          193.143.1.32-mips-2025-02-01T10_01_48.elfGet hashmaliciousUnknownBrowse
                          • 140.223.201.46
                          193.143.1.32-arm-2025-02-01T10_01_48.elfGet hashmaliciousUnknownBrowse
                          • 108.11.217.98
                          193.143.1.32-x86-2025-02-01T10_16_50.elfGet hashmaliciousUnknownBrowse
                          • 195.127.234.125
                          Fantazy.mpsl.elfGet hashmaliciousUnknownBrowse
                          • 195.129.27.157
                          Fantazy.x86_64.elfGet hashmaliciousUnknownBrowse
                          • 208.217.86.46
                          RPV.exeGet hashmaliciousI2PRATBrowse
                          • 71.164.108.12
                          boatnet.arm.elfGet hashmaliciousMirai, GafgytBrowse
                          • 193.129.42.245
                          boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                          • 173.57.146.156
                          CANONICAL-ASGBFantazy.arc.elfGet hashmaliciousUnknownBrowse
                          • 91.189.91.42
                          na.elfGet hashmaliciousPrometeiBrowse
                          • 91.189.91.42
                          na.elfGet hashmaliciousPrometeiBrowse
                          • 91.189.91.42
                          na.elfGet hashmaliciousPrometeiBrowse
                          • 91.189.91.42
                          Fantazy.arm6.elfGet hashmaliciousUnknownBrowse
                          • 91.189.91.42
                          na.elfGet hashmaliciousPrometeiBrowse
                          • 91.189.91.42
                          na.elfGet hashmaliciousPrometeiBrowse
                          • 91.189.91.42
                          i686.elfGet hashmaliciousMiraiBrowse
                          • 91.189.91.42
                          aarch64.elfGet hashmaliciousMiraiBrowse
                          • 91.189.91.42
                          na.elfGet hashmaliciousPrometeiBrowse
                          • 91.189.91.42
                          DIGITALOCEAN-ASNUS193.143.1.32-mips-2025-02-01T10_01_48.elfGet hashmaliciousUnknownBrowse
                          • 138.68.122.136
                          https://cn.42mbetx.com/index.php/Get hashmaliciousUnknownBrowse
                          • 139.59.107.226
                          https://cn.310manx.com/home/Get hashmaliciousUnknownBrowse
                          • 139.59.107.226
                          http://customervoice.microsoft.com/Pages/ResponsePage.aspx?id=s1DYVAfXq0GW6Lk4FvadfsA_WbUNnbROrKLIbauDU1xUNzBDNkg0RFRSSFMwVldFOE42WVc1Wkg3Ty4uGet hashmaliciousHTMLPhisherBrowse
                          • 167.99.8.102
                          AWB#_4365052.exeGet hashmaliciousFormBookBrowse
                          • 178.128.48.21
                          https://php-omanzinge-adac-allservning20251.codeanyapp.com/cada/web/login.phpGet hashmaliciousUnknownBrowse
                          • 198.199.109.95
                          https://cn.manbetx22.pro/home/register/Get hashmaliciousUnknownBrowse
                          • 139.59.107.226
                          https://seamars.com/home/register/Get hashmaliciousUnknownBrowse
                          • 139.59.107.226
                          https://templates.rjuuc.edu.npGet hashmaliciousUnknownBrowse
                          • 167.172.148.114
                          http://www.investecprivatebank.co.zaGet hashmaliciousUnknownBrowse
                          • 157.245.20.41
                          No context
                          No context
                          No created / dropped files found
                          File type:ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
                          Entropy (8bit):6.726121944941634
                          TrID:
                          • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                          File name:zersh4.elf
                          File size:46'008 bytes
                          MD5:9b9094f3ae2242597704fc6599329737
                          SHA1:af6b42528082d32ad418077b8697073bbf0ec937
                          SHA256:ea8b27801b58bb631eb540cf59c7f0bd324c92994967bc0e45496f1ea6f95b68
                          SHA512:9c03ee34d2aa53b03a3adefd6d771e9f86f74c44119195a832ada6452a7174fbfabec78f153af754038f554fa719f791b6cd7cba767458c77d534fb2899d3aed
                          SSDEEP:768:7aVwt6Soxe5qyUTxJU7O4PaXtLkCIoqLX8nC+:7aVwt6Sns4Bok4gX8nC+
                          TLSH:41237E63C42AADD0C50946B4A6299F742B13E404C7A62FFB674E86728007EBCF61D3F5
                          File Content Preview:.ELF..............*.......@.4...........4. ...(...............@...@...........................A...A.....$...........Q.td............................././"O.n........#.*@........#.*@l....o&O.n...l..............................././.../.a"O.!...n...a.b("...q.

                          ELF header

                          Class:ELF32
                          Data:2's complement, little endian
                          Version:1 (current)
                          Machine:<unknown>
                          Version Number:0x1
                          Type:EXEC (Executable file)
                          OS/ABI:UNIX - System V
                          ABI Version:0
                          Entry Point Address:0x4001a0
                          Flags:0x9
                          ELF Header Size:52
                          Program Header Offset:52
                          Program Header Size:32
                          Number of Program Headers:3
                          Section Header Offset:45568
                          Section Header Size:40
                          Number of Section Headers:11
                          Header String Table Index:10
                          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                          NULL0x00x00x00x00x0000
                          .initPROGBITS0x4000940x940x300x00x6AX004
                          .textPROGBITS0x4000e00xe00xa4800x00x6AX0032
                          .finiPROGBITS0x40a5600xa5600x240x00x6AX004
                          .rodataPROGBITS0x40a5840xa5840x76c0x00x2A004
                          .ctorsPROGBITS0x41b0000xb0000x80x00x3WA004
                          .dtorsPROGBITS0x41b0080xb0080x80x00x3WA004
                          .jcrPROGBITS0x41b0100xb0100x40x00x3WA004
                          .dataPROGBITS0x41b0140xb0140x1a80x00x3WA004
                          .bssNOBITS0x41b1bc0xb1bc0x2680x00x3WA004
                          .shstrtabSTRTAB0x00xb1bc0x430x00x0001
                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                          LOAD0x00x4000000x4000000xacf00xacf06.84530x5R E0x10000.init .text .fini .rodata
                          LOAD0xb0000x41b0000x41b0000x1bc0x4242.34070x6RW 0x10000.ctors .dtors .jcr .data .bss
                          GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                          TimestampSource PortDest PortSource IPDest IP
                          Feb 1, 2025 14:46:15.843554020 CET340021440192.168.2.13209.38.56.135
                          Feb 1, 2025 14:46:15.848423004 CET144034002209.38.56.135192.168.2.13
                          Feb 1, 2025 14:46:15.848500013 CET340021440192.168.2.13209.38.56.135
                          Feb 1, 2025 14:46:15.860229015 CET340021440192.168.2.13209.38.56.135
                          Feb 1, 2025 14:46:15.865147114 CET144034002209.38.56.135192.168.2.13
                          Feb 1, 2025 14:46:15.865211010 CET340021440192.168.2.13209.38.56.135
                          Feb 1, 2025 14:46:15.869976997 CET144034002209.38.56.135192.168.2.13
                          Feb 1, 2025 14:46:25.870538950 CET340021440192.168.2.13209.38.56.135
                          Feb 1, 2025 14:46:25.875427008 CET144034002209.38.56.135192.168.2.13
                          Feb 1, 2025 14:46:26.484986067 CET144034002209.38.56.135192.168.2.13
                          Feb 1, 2025 14:46:26.485675097 CET340021440192.168.2.13209.38.56.135
                          Feb 1, 2025 14:46:26.490477085 CET144034002209.38.56.135192.168.2.13
                          Feb 1, 2025 14:46:27.087383986 CET48202443192.168.2.13185.125.190.26
                          Feb 1, 2025 14:46:27.507143974 CET331921440192.168.2.13146.190.204.203
                          Feb 1, 2025 14:46:27.511970043 CET144033192146.190.204.203192.168.2.13
                          Feb 1, 2025 14:46:27.512049913 CET331921440192.168.2.13146.190.204.203
                          Feb 1, 2025 14:46:27.513123989 CET331921440192.168.2.13146.190.204.203
                          Feb 1, 2025 14:46:27.517915964 CET144033192146.190.204.203192.168.2.13
                          Feb 1, 2025 14:46:27.517980099 CET331921440192.168.2.13146.190.204.203
                          Feb 1, 2025 14:46:27.522711039 CET144033192146.190.204.203192.168.2.13
                          Feb 1, 2025 14:46:38.152137041 CET144033192146.190.204.203192.168.2.13
                          Feb 1, 2025 14:46:38.152499914 CET331921440192.168.2.13146.190.204.203
                          Feb 1, 2025 14:46:38.157286882 CET144033192146.190.204.203192.168.2.13
                          Feb 1, 2025 14:46:39.334352016 CET331941440192.168.2.13146.190.204.203
                          Feb 1, 2025 14:46:39.339235067 CET144033194146.190.204.203192.168.2.13
                          Feb 1, 2025 14:46:39.339404106 CET331941440192.168.2.13146.190.204.203
                          Feb 1, 2025 14:46:39.340616941 CET331941440192.168.2.13146.190.204.203
                          Feb 1, 2025 14:46:39.345424891 CET144033194146.190.204.203192.168.2.13
                          Feb 1, 2025 14:46:39.345496893 CET331941440192.168.2.13146.190.204.203
                          Feb 1, 2025 14:46:39.350332022 CET144033194146.190.204.203192.168.2.13
                          Feb 1, 2025 14:46:50.026154041 CET144033194146.190.204.203192.168.2.13
                          Feb 1, 2025 14:46:50.026555061 CET331941440192.168.2.13146.190.204.203
                          Feb 1, 2025 14:46:50.031384945 CET144033194146.190.204.203192.168.2.13
                          Feb 1, 2025 14:46:51.114794016 CET331961440192.168.2.13146.190.204.203
                          Feb 1, 2025 14:46:51.119729996 CET144033196146.190.204.203192.168.2.13
                          Feb 1, 2025 14:46:51.119844913 CET331961440192.168.2.13146.190.204.203
                          Feb 1, 2025 14:46:51.120956898 CET331961440192.168.2.13146.190.204.203
                          Feb 1, 2025 14:46:51.128767967 CET144033196146.190.204.203192.168.2.13
                          Feb 1, 2025 14:46:51.128844976 CET331961440192.168.2.13146.190.204.203
                          Feb 1, 2025 14:46:51.133708000 CET144033196146.190.204.203192.168.2.13
                          Feb 1, 2025 14:46:59.343508959 CET48202443192.168.2.13185.125.190.26
                          Feb 1, 2025 14:47:01.935077906 CET144033196146.190.204.203192.168.2.13
                          Feb 1, 2025 14:47:01.935369015 CET331961440192.168.2.13146.190.204.203
                          Feb 1, 2025 14:47:01.935416937 CET331961440192.168.2.13146.190.204.203
                          Feb 1, 2025 14:47:01.940298080 CET144033196146.190.204.203192.168.2.13
                          Feb 1, 2025 14:47:02.966658115 CET439941440192.168.2.1368.183.244.135
                          Feb 1, 2025 14:47:02.971594095 CET14404399468.183.244.135192.168.2.13
                          Feb 1, 2025 14:47:02.971700907 CET439941440192.168.2.1368.183.244.135
                          Feb 1, 2025 14:47:02.973395109 CET439941440192.168.2.1368.183.244.135
                          Feb 1, 2025 14:47:02.978252888 CET14404399468.183.244.135192.168.2.13
                          Feb 1, 2025 14:47:02.978336096 CET439941440192.168.2.1368.183.244.135
                          Feb 1, 2025 14:47:02.983127117 CET14404399468.183.244.135192.168.2.13
                          Feb 1, 2025 14:47:14.236999989 CET14404399468.183.244.135192.168.2.13
                          Feb 1, 2025 14:47:14.237303019 CET439941440192.168.2.1368.183.244.135
                          Feb 1, 2025 14:47:14.242109060 CET14404399468.183.244.135192.168.2.13
                          Feb 1, 2025 14:47:15.258985996 CET391681440192.168.2.1364.225.86.206
                          Feb 1, 2025 14:47:15.263772964 CET14403916864.225.86.206192.168.2.13
                          Feb 1, 2025 14:47:15.263875961 CET391681440192.168.2.1364.225.86.206
                          Feb 1, 2025 14:47:15.265115976 CET391681440192.168.2.1364.225.86.206
                          Feb 1, 2025 14:47:15.269871950 CET14403916864.225.86.206192.168.2.13
                          Feb 1, 2025 14:47:15.269944906 CET391681440192.168.2.1364.225.86.206
                          Feb 1, 2025 14:47:15.274775028 CET14403916864.225.86.206192.168.2.13
                          Feb 1, 2025 14:47:26.536187887 CET14403916864.225.86.206192.168.2.13
                          Feb 1, 2025 14:47:26.536760092 CET391681440192.168.2.1364.225.86.206
                          Feb 1, 2025 14:47:26.541577101 CET14403916864.225.86.206192.168.2.13
                          Feb 1, 2025 14:47:28.584572077 CET391701440192.168.2.1364.225.86.206
                          Feb 1, 2025 14:47:28.589493036 CET14403917064.225.86.206192.168.2.13
                          Feb 1, 2025 14:47:28.589564085 CET391701440192.168.2.1364.225.86.206
                          Feb 1, 2025 14:47:28.590332031 CET391701440192.168.2.1364.225.86.206
                          Feb 1, 2025 14:47:28.595200062 CET14403917064.225.86.206192.168.2.13
                          Feb 1, 2025 14:47:28.595268965 CET391701440192.168.2.1364.225.86.206
                          Feb 1, 2025 14:47:28.600095034 CET14403917064.225.86.206192.168.2.13
                          Feb 1, 2025 14:47:38.600521088 CET391701440192.168.2.1364.225.86.206
                          Feb 1, 2025 14:47:38.605371952 CET14403917064.225.86.206192.168.2.13
                          Feb 1, 2025 14:47:39.172329903 CET14403917064.225.86.206192.168.2.13
                          Feb 1, 2025 14:47:39.172580957 CET391701440192.168.2.1364.225.86.206
                          Feb 1, 2025 14:47:39.177484035 CET14403917064.225.86.206192.168.2.13
                          Feb 1, 2025 14:47:40.205038071 CET340161440192.168.2.13209.38.56.135
                          Feb 1, 2025 14:47:40.211524010 CET144034016209.38.56.135192.168.2.13
                          Feb 1, 2025 14:47:40.211632013 CET340161440192.168.2.13209.38.56.135
                          Feb 1, 2025 14:47:40.212735891 CET340161440192.168.2.13209.38.56.135
                          Feb 1, 2025 14:47:40.219284058 CET144034016209.38.56.135192.168.2.13
                          Feb 1, 2025 14:47:40.219366074 CET340161440192.168.2.13209.38.56.135
                          Feb 1, 2025 14:47:40.228065014 CET144034016209.38.56.135192.168.2.13
                          Feb 1, 2025 14:47:51.647108078 CET144034016209.38.56.135192.168.2.13
                          Feb 1, 2025 14:47:51.647452116 CET340161440192.168.2.13209.38.56.135
                          Feb 1, 2025 14:47:51.652332067 CET144034016209.38.56.135192.168.2.13
                          Feb 1, 2025 14:47:52.673433065 CET516841440192.168.2.13209.38.188.134
                          Feb 1, 2025 14:47:52.678184986 CET144051684209.38.188.134192.168.2.13
                          Feb 1, 2025 14:47:52.678287029 CET516841440192.168.2.13209.38.188.134
                          Feb 1, 2025 14:47:52.679263115 CET516841440192.168.2.13209.38.188.134
                          Feb 1, 2025 14:47:52.684031963 CET144051684209.38.188.134192.168.2.13
                          Feb 1, 2025 14:47:52.684098005 CET516841440192.168.2.13209.38.188.134
                          Feb 1, 2025 14:47:52.688826084 CET144051684209.38.188.134192.168.2.13
                          Feb 1, 2025 14:48:03.346148014 CET144051684209.38.188.134192.168.2.13
                          Feb 1, 2025 14:48:03.346422911 CET516841440192.168.2.13209.38.188.134
                          Feb 1, 2025 14:48:03.351202011 CET144051684209.38.188.134192.168.2.13
                          Feb 1, 2025 14:48:04.520903111 CET516861440192.168.2.13209.38.188.134
                          Feb 1, 2025 14:48:04.527439117 CET144051686209.38.188.134192.168.2.13
                          Feb 1, 2025 14:48:04.527493000 CET516861440192.168.2.13209.38.188.134
                          Feb 1, 2025 14:48:04.528213024 CET516861440192.168.2.13209.38.188.134
                          Feb 1, 2025 14:48:04.533313036 CET144051686209.38.188.134192.168.2.13
                          Feb 1, 2025 14:48:04.533471107 CET516861440192.168.2.13209.38.188.134
                          Feb 1, 2025 14:48:04.538249969 CET144051686209.38.188.134192.168.2.13
                          Feb 1, 2025 14:48:15.141297102 CET144051686209.38.188.134192.168.2.13
                          Feb 1, 2025 14:48:15.141958952 CET516861440192.168.2.13209.38.188.134
                          Feb 1, 2025 14:48:15.146800041 CET144051686209.38.188.134192.168.2.13
                          Feb 1, 2025 14:48:16.173015118 CET391781440192.168.2.1364.225.86.206
                          Feb 1, 2025 14:48:16.177845955 CET14403917864.225.86.206192.168.2.13
                          Feb 1, 2025 14:48:16.177984953 CET391781440192.168.2.1364.225.86.206
                          Feb 1, 2025 14:48:16.179117918 CET391781440192.168.2.1364.225.86.206
                          Feb 1, 2025 14:48:16.183960915 CET14403917864.225.86.206192.168.2.13
                          Feb 1, 2025 14:48:16.184036970 CET391781440192.168.2.1364.225.86.206
                          Feb 1, 2025 14:48:16.188863039 CET14403917864.225.86.206192.168.2.13
                          TimestampSource PortDest PortSource IPDest IP
                          Feb 1, 2025 14:46:15.824985981 CET3478253192.168.2.13152.53.15.127
                          Feb 1, 2025 14:46:15.842504025 CET5334782152.53.15.127192.168.2.13
                          Feb 1, 2025 14:46:27.489396095 CET5954153192.168.2.13152.53.15.127
                          Feb 1, 2025 14:46:27.506470919 CET5359541152.53.15.127192.168.2.13
                          Feb 1, 2025 14:46:39.156619072 CET3448953192.168.2.13185.181.61.24
                          Feb 1, 2025 14:46:39.192287922 CET5334489185.181.61.24192.168.2.13
                          Feb 1, 2025 14:46:39.194102049 CET3306853192.168.2.13185.181.61.24
                          Feb 1, 2025 14:46:39.227159977 CET5333068185.181.61.24192.168.2.13
                          Feb 1, 2025 14:46:39.229038000 CET4119153192.168.2.13185.181.61.24
                          Feb 1, 2025 14:46:39.262092113 CET5341191185.181.61.24192.168.2.13
                          Feb 1, 2025 14:46:39.263670921 CET5433953192.168.2.13185.181.61.24
                          Feb 1, 2025 14:46:39.296788931 CET5354339185.181.61.24192.168.2.13
                          Feb 1, 2025 14:46:39.298355103 CET4971353192.168.2.13185.181.61.24
                          Feb 1, 2025 14:46:39.333163977 CET5349713185.181.61.24192.168.2.13
                          Feb 1, 2025 14:46:51.030591965 CET6008653192.168.2.1351.158.108.203
                          Feb 1, 2025 14:46:51.046251059 CET536008651.158.108.203192.168.2.13
                          Feb 1, 2025 14:46:51.047713041 CET3524853192.168.2.1351.158.108.203
                          Feb 1, 2025 14:46:51.062825918 CET533524851.158.108.203192.168.2.13
                          Feb 1, 2025 14:46:51.064481974 CET4195553192.168.2.1351.158.108.203
                          Feb 1, 2025 14:46:51.079622984 CET534195551.158.108.203192.168.2.13
                          Feb 1, 2025 14:46:51.081165075 CET4236353192.168.2.1351.158.108.203
                          Feb 1, 2025 14:46:51.096352100 CET534236351.158.108.203192.168.2.13
                          Feb 1, 2025 14:46:51.097687006 CET5296653192.168.2.1351.158.108.203
                          Feb 1, 2025 14:46:51.113920927 CET535296651.158.108.203192.168.2.13
                          Feb 1, 2025 14:47:02.939017057 CET3632053192.168.2.1381.169.136.222
                          Feb 1, 2025 14:47:02.965975046 CET533632081.169.136.222192.168.2.13
                          Feb 1, 2025 14:47:15.240367889 CET5529153192.168.2.13202.61.197.122
                          Feb 1, 2025 14:47:15.258027077 CET5355291202.61.197.122192.168.2.13
                          Feb 1, 2025 14:47:27.539566994 CET4874353192.168.2.13168.235.111.72
                          Feb 1, 2025 14:47:28.210582018 CET5348743168.235.111.72192.168.2.13
                          Feb 1, 2025 14:47:28.212260962 CET3500653192.168.2.13168.235.111.72
                          Feb 1, 2025 14:47:28.301014900 CET5335006168.235.111.72192.168.2.13
                          Feb 1, 2025 14:47:28.302416086 CET3359653192.168.2.13168.235.111.72
                          Feb 1, 2025 14:47:28.391989946 CET5333596168.235.111.72192.168.2.13
                          Feb 1, 2025 14:47:28.393060923 CET4890753192.168.2.13168.235.111.72
                          Feb 1, 2025 14:47:28.493273020 CET5348907168.235.111.72192.168.2.13
                          Feb 1, 2025 14:47:28.494344950 CET3590153192.168.2.13168.235.111.72
                          Feb 1, 2025 14:47:28.583995104 CET5335901168.235.111.72192.168.2.13
                          Feb 1, 2025 14:47:40.175584078 CET3831653192.168.2.1381.169.136.222
                          Feb 1, 2025 14:47:40.204039097 CET533831681.169.136.222192.168.2.13
                          Feb 1, 2025 14:47:52.649831057 CET4603753192.168.2.13152.53.15.127
                          Feb 1, 2025 14:47:52.672976971 CET5346037152.53.15.127192.168.2.13
                          Feb 1, 2025 14:48:04.349486113 CET4565453192.168.2.13185.181.61.24
                          Feb 1, 2025 14:48:04.382642031 CET5345654185.181.61.24192.168.2.13
                          Feb 1, 2025 14:48:04.383805990 CET5195553192.168.2.13185.181.61.24
                          Feb 1, 2025 14:48:04.417031050 CET5351955185.181.61.24192.168.2.13
                          Feb 1, 2025 14:48:04.418086052 CET5076153192.168.2.13185.181.61.24
                          Feb 1, 2025 14:48:04.452168941 CET5350761185.181.61.24192.168.2.13
                          Feb 1, 2025 14:48:04.453175068 CET6082853192.168.2.13185.181.61.24
                          Feb 1, 2025 14:48:04.486351013 CET5360828185.181.61.24192.168.2.13
                          Feb 1, 2025 14:48:04.487339020 CET5619053192.168.2.13185.181.61.24
                          Feb 1, 2025 14:48:04.520458937 CET5356190185.181.61.24192.168.2.13
                          Feb 1, 2025 14:48:16.145061016 CET4838753192.168.2.1381.169.136.222
                          Feb 1, 2025 14:48:16.172167063 CET534838781.169.136.222192.168.2.13
                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                          Feb 1, 2025 14:46:15.824985981 CET192.168.2.13152.53.15.1270xfdeStandard query (0)serisontop.dynA (IP address)IN (0x0001)false
                          Feb 1, 2025 14:46:27.489396095 CET192.168.2.13152.53.15.1270x1d25Standard query (0)serisontop.dynA (IP address)IN (0x0001)false
                          Feb 1, 2025 14:46:39.156619072 CET192.168.2.13185.181.61.240x13b3Standard query (0)serisbot.geek. [malformed]256447false
                          Feb 1, 2025 14:46:39.194102049 CET192.168.2.13185.181.61.240x13b3Standard query (0)serisbot.geek. [malformed]256447false
                          Feb 1, 2025 14:46:39.229038000 CET192.168.2.13185.181.61.240x13b3Standard query (0)serisbot.geek. [malformed]256447false
                          Feb 1, 2025 14:46:39.263670921 CET192.168.2.13185.181.61.240x13b3Standard query (0)serisbot.geek. [malformed]256447false
                          Feb 1, 2025 14:46:39.298355103 CET192.168.2.13185.181.61.240x13b3Standard query (0)serisbot.geek. [malformed]256447false
                          Feb 1, 2025 14:46:51.030591965 CET192.168.2.1351.158.108.2030x7ae7Standard query (0)serisbot.geek. [malformed]256459false
                          Feb 1, 2025 14:46:51.047713041 CET192.168.2.1351.158.108.2030x7ae7Standard query (0)serisbot.geek. [malformed]256459false
                          Feb 1, 2025 14:46:51.064481974 CET192.168.2.1351.158.108.2030x7ae7Standard query (0)serisbot.geek. [malformed]256459false
                          Feb 1, 2025 14:46:51.081165075 CET192.168.2.1351.158.108.2030x7ae7Standard query (0)serisbot.geek. [malformed]256459false
                          Feb 1, 2025 14:46:51.097687006 CET192.168.2.1351.158.108.2030x7ae7Standard query (0)serisbot.geek. [malformed]256459false
                          Feb 1, 2025 14:47:02.939017057 CET192.168.2.1381.169.136.2220x1049Standard query (0)serisontop.dynA (IP address)IN (0x0001)false
                          Feb 1, 2025 14:47:15.240367889 CET192.168.2.13202.61.197.1220x8909Standard query (0)serisontop.dynA (IP address)IN (0x0001)false
                          Feb 1, 2025 14:47:27.539566994 CET192.168.2.13168.235.111.720xaaffStandard query (0)serisbot.geek. [malformed]256496false
                          Feb 1, 2025 14:47:28.212260962 CET192.168.2.13168.235.111.720xaaffStandard query (0)serisbot.geek. [malformed]256496false
                          Feb 1, 2025 14:47:28.302416086 CET192.168.2.13168.235.111.720xaaffStandard query (0)serisbot.geek. [malformed]256496false
                          Feb 1, 2025 14:47:28.393060923 CET192.168.2.13168.235.111.720xaaffStandard query (0)serisbot.geek. [malformed]256496false
                          Feb 1, 2025 14:47:28.494344950 CET192.168.2.13168.235.111.720xaaffStandard query (0)serisbot.geek. [malformed]256496false
                          Feb 1, 2025 14:47:40.175584078 CET192.168.2.1381.169.136.2220x5e3dStandard query (0)serisontop.dynA (IP address)IN (0x0001)false
                          Feb 1, 2025 14:47:52.649831057 CET192.168.2.13152.53.15.1270xa6daStandard query (0)serisontop.dynA (IP address)IN (0x0001)false
                          Feb 1, 2025 14:48:04.349486113 CET192.168.2.13185.181.61.240x82ccStandard query (0)serisbot.geek. [malformed]256276false
                          Feb 1, 2025 14:48:04.383805990 CET192.168.2.13185.181.61.240x82ccStandard query (0)serisbot.geek. [malformed]256276false
                          Feb 1, 2025 14:48:04.418086052 CET192.168.2.13185.181.61.240x82ccStandard query (0)serisbot.geek. [malformed]256276false
                          Feb 1, 2025 14:48:04.453175068 CET192.168.2.13185.181.61.240x82ccStandard query (0)serisbot.geek. [malformed]256276false
                          Feb 1, 2025 14:48:04.487339020 CET192.168.2.13185.181.61.240x82ccStandard query (0)serisbot.geek. [malformed]256276false
                          Feb 1, 2025 14:48:16.145061016 CET192.168.2.1381.169.136.2220xa5a4Standard query (0)serisontop.dynA (IP address)IN (0x0001)false
                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                          Feb 1, 2025 14:46:15.842504025 CET152.53.15.127192.168.2.130xfdeNo error (0)serisontop.dyn146.190.204.203A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:46:15.842504025 CET152.53.15.127192.168.2.130xfdeNo error (0)serisontop.dyn68.183.244.135A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:46:15.842504025 CET152.53.15.127192.168.2.130xfdeNo error (0)serisontop.dyn209.38.188.134A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:46:15.842504025 CET152.53.15.127192.168.2.130xfdeNo error (0)serisontop.dyn209.38.56.135A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:46:15.842504025 CET152.53.15.127192.168.2.130xfdeNo error (0)serisontop.dyn209.38.56.129A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:46:15.842504025 CET152.53.15.127192.168.2.130xfdeNo error (0)serisontop.dyn64.225.86.206A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:46:27.506470919 CET152.53.15.127192.168.2.130x1d25No error (0)serisontop.dyn209.38.56.135A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:46:27.506470919 CET152.53.15.127192.168.2.130x1d25No error (0)serisontop.dyn209.38.56.129A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:46:27.506470919 CET152.53.15.127192.168.2.130x1d25No error (0)serisontop.dyn64.225.86.206A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:46:27.506470919 CET152.53.15.127192.168.2.130x1d25No error (0)serisontop.dyn146.190.204.203A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:46:27.506470919 CET152.53.15.127192.168.2.130x1d25No error (0)serisontop.dyn68.183.244.135A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:46:27.506470919 CET152.53.15.127192.168.2.130x1d25No error (0)serisontop.dyn209.38.188.134A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:46:51.046251059 CET51.158.108.203192.168.2.130x7ae7Format error (1)serisbot.geek. [malformed]nonenone256459false
                          Feb 1, 2025 14:46:51.062825918 CET51.158.108.203192.168.2.130x7ae7Format error (1)serisbot.geek. [malformed]nonenone256459false
                          Feb 1, 2025 14:46:51.079622984 CET51.158.108.203192.168.2.130x7ae7Format error (1)serisbot.geek. [malformed]nonenone256459false
                          Feb 1, 2025 14:46:51.096352100 CET51.158.108.203192.168.2.130x7ae7Format error (1)serisbot.geek. [malformed]nonenone256459false
                          Feb 1, 2025 14:46:51.113920927 CET51.158.108.203192.168.2.130x7ae7Format error (1)serisbot.geek. [malformed]nonenone256459false
                          Feb 1, 2025 14:47:02.965975046 CET81.169.136.222192.168.2.130x1049No error (0)serisontop.dyn68.183.244.135A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:47:02.965975046 CET81.169.136.222192.168.2.130x1049No error (0)serisontop.dyn209.38.188.134A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:47:02.965975046 CET81.169.136.222192.168.2.130x1049No error (0)serisontop.dyn64.225.86.206A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:47:02.965975046 CET81.169.136.222192.168.2.130x1049No error (0)serisontop.dyn209.38.56.135A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:47:02.965975046 CET81.169.136.222192.168.2.130x1049No error (0)serisontop.dyn146.190.204.203A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:47:02.965975046 CET81.169.136.222192.168.2.130x1049No error (0)serisontop.dyn209.38.56.129A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:47:15.258027077 CET202.61.197.122192.168.2.130x8909No error (0)serisontop.dyn209.38.56.135A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:47:15.258027077 CET202.61.197.122192.168.2.130x8909No error (0)serisontop.dyn64.225.86.206A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:47:15.258027077 CET202.61.197.122192.168.2.130x8909No error (0)serisontop.dyn68.183.244.135A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:47:15.258027077 CET202.61.197.122192.168.2.130x8909No error (0)serisontop.dyn146.190.204.203A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:47:15.258027077 CET202.61.197.122192.168.2.130x8909No error (0)serisontop.dyn209.38.56.129A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:47:15.258027077 CET202.61.197.122192.168.2.130x8909No error (0)serisontop.dyn209.38.188.134A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:47:40.204039097 CET81.169.136.222192.168.2.130x5e3dNo error (0)serisontop.dyn209.38.188.134A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:47:40.204039097 CET81.169.136.222192.168.2.130x5e3dNo error (0)serisontop.dyn64.225.86.206A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:47:40.204039097 CET81.169.136.222192.168.2.130x5e3dNo error (0)serisontop.dyn68.183.244.135A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:47:40.204039097 CET81.169.136.222192.168.2.130x5e3dNo error (0)serisontop.dyn146.190.204.203A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:47:40.204039097 CET81.169.136.222192.168.2.130x5e3dNo error (0)serisontop.dyn209.38.56.129A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:47:40.204039097 CET81.169.136.222192.168.2.130x5e3dNo error (0)serisontop.dyn209.38.56.135A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:47:52.672976971 CET152.53.15.127192.168.2.130xa6daNo error (0)serisontop.dyn68.183.244.135A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:47:52.672976971 CET152.53.15.127192.168.2.130xa6daNo error (0)serisontop.dyn209.38.188.134A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:47:52.672976971 CET152.53.15.127192.168.2.130xa6daNo error (0)serisontop.dyn209.38.56.135A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:47:52.672976971 CET152.53.15.127192.168.2.130xa6daNo error (0)serisontop.dyn209.38.56.129A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:47:52.672976971 CET152.53.15.127192.168.2.130xa6daNo error (0)serisontop.dyn64.225.86.206A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:47:52.672976971 CET152.53.15.127192.168.2.130xa6daNo error (0)serisontop.dyn146.190.204.203A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:48:16.172167063 CET81.169.136.222192.168.2.130xa5a4No error (0)serisontop.dyn209.38.188.134A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:48:16.172167063 CET81.169.136.222192.168.2.130xa5a4No error (0)serisontop.dyn64.225.86.206A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:48:16.172167063 CET81.169.136.222192.168.2.130xa5a4No error (0)serisontop.dyn209.38.56.129A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:48:16.172167063 CET81.169.136.222192.168.2.130xa5a4No error (0)serisontop.dyn68.183.244.135A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:48:16.172167063 CET81.169.136.222192.168.2.130xa5a4No error (0)serisontop.dyn146.190.204.203A (IP address)IN (0x0001)false
                          Feb 1, 2025 14:48:16.172167063 CET81.169.136.222192.168.2.130xa5a4No error (0)serisontop.dyn209.38.56.135A (IP address)IN (0x0001)false

                          System Behavior

                          Start time (UTC):13:46:15
                          Start date (UTC):01/02/2025
                          Path:/tmp/zersh4.elf
                          Arguments:/tmp/zersh4.elf
                          File size:4139976 bytes
                          MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                          Start time (UTC):13:46:15
                          Start date (UTC):01/02/2025
                          Path:/tmp/zersh4.elf
                          Arguments:-
                          File size:4139976 bytes
                          MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                          Start time (UTC):13:46:15
                          Start date (UTC):01/02/2025
                          Path:/tmp/zersh4.elf
                          Arguments:-
                          File size:4139976 bytes
                          MD5 hash:8943e5f8f8c280467b4472c15ae93ba9