Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
zerarm.elf

Overview

General Information

Sample name:zerarm.elf
Analysis ID:1604432
MD5:ac8f3b8f700e1693dba319978fa99989
SHA1:29e0936130539188a8f8053138dce79eb52e3ffd
SHA256:49bd7ec5866221a5ca5002470b4582df540c442d90d4654315df58ff16c7888f
Tags:elfuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Sample deletes itself
Sends malformed DNS queries
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1604432
Start date and time:2025-02-01 14:45:25 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 44s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:zerarm.elf
Detection:MAL
Classification:mal56.troj.evad.linELF@0/0@15/0
Command:/tmp/zerarm.elf
PID:5515
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
gosh that chinese family at the other table sure ate a lot
Standard Error:
  • system is lnxubuntu20
  • zerarm.elf (PID: 5515, Parent: 5434, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/zerarm.elf
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: zerarm.elfVirustotal: Detection: 41%Perma Link
Source: zerarm.elfReversingLabs: Detection: 42%

Networking

barindex
Source: global trafficDNS traffic detected: malformed DNS query: serisbot.geek. [malformed]
Source: global trafficTCP traffic: 192.168.2.14:54694 -> 64.225.86.206:1440
Source: global trafficTCP traffic: 192.168.2.14:43740 -> 209.38.56.135:1440
Source: global trafficTCP traffic: 192.168.2.14:37620 -> 209.38.188.134:1440
Source: global trafficTCP traffic: 192.168.2.14:57054 -> 68.183.244.135:1440
Source: global trafficTCP traffic: 192.168.2.14:44284 -> 209.38.56.129:1440
Source: /tmp/zerarm.elf (PID: 5515)Socket: 127.0.0.1:39148Jump to behavior
Source: global trafficTCP traffic: 192.168.2.14:46540 -> 185.125.190.26:443
Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 152.53.15.127
Source: unknownUDP traffic detected without corresponding DNS query: 152.53.15.127
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 202.61.197.122
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: global trafficDNS traffic detected: DNS query: serisbot.geek
Source: global trafficDNS traffic detected: DNS query: serisontop.dyn
Source: global trafficDNS traffic detected: DNS query: serisbot.geek. [malformed]
Source: unknownNetwork traffic detected: HTTP traffic on port 46540 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal56.troj.evad.linELF@0/0@15/0

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/zerarm.elf (PID: 5515)File: /tmp/zerarm.elfJump to behavior
Source: /tmp/zerarm.elf (PID: 5515)Queries kernel information via 'uname': Jump to behavior
Source: zerarm.elf, 5515.1.0000563ae4ed0000.0000563ae4ffe000.rw-.sdmpBinary or memory string: :V!/etc/qemu-binfmt/arm
Source: zerarm.elf, 5515.1.0000563ae4ed0000.0000563ae4ffe000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: zerarm.elf, 5515.1.00007ffe9ceef000.00007ffe9cf10000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: zerarm.elf, 5515.1.00007ffe9ceef000.00007ffe9cf10000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/zerarm.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/zerarm.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1604432 Sample: zerarm.elf Startdate: 01/02/2025 Architecture: LINUX Score: 56 15 serisbot.geek. [malformed] 2->15 17 serisbot.geek 64.225.86.206, 1440, 54694, 54708 DIGITALOCEAN-ASNUS United States 2->17 19 6 other IPs or domains 2->19 21 Multi AV Scanner detection for submitted file 2->21 8 zerarm.elf 2->8         started        signatures3 23 Sends malformed DNS queries 15->23 process4 signatures5 25 Sample deletes itself 8->25 11 zerarm.elf 8->11         started        process6 process7 13 zerarm.elf 11->13         started       
SourceDetectionScannerLabelLink
zerarm.elf41%VirustotalBrowse
zerarm.elf42%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
serisontop.dyn
64.225.86.206
truefalse
    high
    serisbot.geek
    64.225.86.206
    truefalse
      high
      serisbot.geek. [malformed]
      unknown
      unknownfalse
        high
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        64.225.86.206
        serisontop.dynUnited States
        14061DIGITALOCEAN-ASNUSfalse
        209.38.56.129
        unknownUnited States
        7018ATT-INTERNET4USfalse
        185.125.190.26
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        209.38.56.135
        unknownUnited States
        7018ATT-INTERNET4USfalse
        68.183.244.135
        unknownUnited States
        14061DIGITALOCEAN-ASNUSfalse
        209.38.188.134
        unknownUnited States
        7018ATT-INTERNET4USfalse
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        185.125.190.26arm5.elfGet hashmaliciousMiraiBrowse
          spc.elfGet hashmaliciousMiraiBrowse
            yakuza.x86.elfGet hashmaliciousGafgyt, MiraiBrowse
              176.65.134.111-boatnet.arm6-2025-02-01T00_59_15.elfGet hashmaliciousMiraiBrowse
                na.elfGet hashmaliciousPrometeiBrowse
                  i686.elfGet hashmaliciousMiraiBrowse
                    x86_64.elfGet hashmaliciousMirai, OkiruBrowse
                      na.elfGet hashmaliciousPrometeiBrowse
                        hold.x86_64.elfGet hashmaliciousOkiruBrowse
                          hold.m68k.elfGet hashmaliciousMirai, OkiruBrowse
                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                            serisontop.dynsplppc.elfGet hashmaliciousUnknownBrowse
                            • 209.38.188.134
                            nabppc.elfGet hashmaliciousUnknownBrowse
                            • 68.183.244.135
                            splarm.elfGet hashmaliciousUnknownBrowse
                            • 64.225.86.206
                            nklx86.elfGet hashmaliciousUnknownBrowse
                            • 146.190.204.203
                            193.143.1.32-mips-2025-02-01T10_01_48.elfGet hashmaliciousUnknownBrowse
                            • 64.225.86.206
                            193.143.1.32-arm-2025-02-01T10_01_48.elfGet hashmaliciousUnknownBrowse
                            • 146.190.204.203
                            193.143.1.32-x86-2025-02-01T10_16_50.elfGet hashmaliciousUnknownBrowse
                            • 64.225.86.206
                            splm68k.elfGet hashmaliciousUnknownBrowse
                            • 154.216.16.250
                            nklarm7.elfGet hashmaliciousUnknownBrowse
                            • 154.216.16.244
                            splarm7.elfGet hashmaliciousUnknownBrowse
                            • 209.38.192.73
                            serisbot.geeknabppc.elfGet hashmaliciousUnknownBrowse
                            • 209.38.188.134
                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                            ATT-INTERNET4USsplppc.elfGet hashmaliciousUnknownBrowse
                            • 196.53.198.189
                            splarm.elfGet hashmaliciousUnknownBrowse
                            • 99.110.125.170
                            nklx86.elfGet hashmaliciousUnknownBrowse
                            • 12.170.82.39
                            193.143.1.32-mips-2025-02-01T10_01_48.elfGet hashmaliciousUnknownBrowse
                            • 12.171.150.17
                            193.143.1.32-arm-2025-02-01T10_01_48.elfGet hashmaliciousUnknownBrowse
                            • 69.234.8.197
                            Fantazy.arm7.elfGet hashmaliciousMiraiBrowse
                            • 99.146.205.16
                            Fantazy.mpsl.elfGet hashmaliciousUnknownBrowse
                            • 76.228.30.231
                            Fantazy.x86_64.elfGet hashmaliciousUnknownBrowse
                            • 71.136.166.233
                            i686.elfGet hashmaliciousMiraiBrowse
                            • 69.150.225.5
                            https://princetonmercerregionalchamberofcommerce.growthzoneapp.com/ap/r/ab6a4316cf944142a2bf4308dc59665dGet hashmaliciousUnknownBrowse
                            • 172.170.249.2
                            CANONICAL-ASGBFantazy.arc.elfGet hashmaliciousUnknownBrowse
                            • 91.189.91.42
                            na.elfGet hashmaliciousPrometeiBrowse
                            • 91.189.91.42
                            na.elfGet hashmaliciousPrometeiBrowse
                            • 91.189.91.42
                            na.elfGet hashmaliciousPrometeiBrowse
                            • 91.189.91.42
                            Fantazy.arm6.elfGet hashmaliciousUnknownBrowse
                            • 91.189.91.42
                            na.elfGet hashmaliciousPrometeiBrowse
                            • 91.189.91.42
                            na.elfGet hashmaliciousPrometeiBrowse
                            • 91.189.91.42
                            i686.elfGet hashmaliciousMiraiBrowse
                            • 91.189.91.42
                            aarch64.elfGet hashmaliciousMiraiBrowse
                            • 91.189.91.42
                            na.elfGet hashmaliciousPrometeiBrowse
                            • 91.189.91.42
                            DIGITALOCEAN-ASNUS193.143.1.32-mips-2025-02-01T10_01_48.elfGet hashmaliciousUnknownBrowse
                            • 138.68.122.136
                            https://cn.42mbetx.com/index.php/Get hashmaliciousUnknownBrowse
                            • 139.59.107.226
                            https://cn.310manx.com/home/Get hashmaliciousUnknownBrowse
                            • 139.59.107.226
                            http://customervoice.microsoft.com/Pages/ResponsePage.aspx?id=s1DYVAfXq0GW6Lk4FvadfsA_WbUNnbROrKLIbauDU1xUNzBDNkg0RFRSSFMwVldFOE42WVc1Wkg3Ty4uGet hashmaliciousHTMLPhisherBrowse
                            • 167.99.8.102
                            AWB#_4365052.exeGet hashmaliciousFormBookBrowse
                            • 178.128.48.21
                            https://php-omanzinge-adac-allservning20251.codeanyapp.com/cada/web/login.phpGet hashmaliciousUnknownBrowse
                            • 198.199.109.95
                            https://cn.manbetx22.pro/home/register/Get hashmaliciousUnknownBrowse
                            • 139.59.107.226
                            https://seamars.com/home/register/Get hashmaliciousUnknownBrowse
                            • 139.59.107.226
                            https://templates.rjuuc.edu.npGet hashmaliciousUnknownBrowse
                            • 167.172.148.114
                            http://www.investecprivatebank.co.zaGet hashmaliciousUnknownBrowse
                            • 157.245.20.41
                            No context
                            No context
                            No created / dropped files found
                            File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
                            Entropy (8bit):5.992824015040782
                            TrID:
                            • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                            File name:zerarm.elf
                            File size:50'408 bytes
                            MD5:ac8f3b8f700e1693dba319978fa99989
                            SHA1:29e0936130539188a8f8053138dce79eb52e3ffd
                            SHA256:49bd7ec5866221a5ca5002470b4582df540c442d90d4654315df58ff16c7888f
                            SHA512:5e7786ecc9bce6c1d551ef65b1faf9cfb4365a1e2be160a0e1d43f4eab0b1c3cc469d29d7c713fd2a54641ad3edc5fe7d4b4284a1ec1b129c07272b7b582dba0
                            SSDEEP:768:smI7eBNc6DnhnVG9pZESJGYWzdo6wH8rA2/hnm8QbaCN7zle4C1:a7INYpZ9gYEMH8U25m8xF
                            TLSH:70330855B8C19A17C5E023BBFA2E419C372523B8E2DF7217CD122F513B8A82F0DA7655
                            File Content Preview:.ELF...a..........(.........4...0.......4. ...(.....................(...(...............,...,...,.......(...........Q.td..................................-...L."...............0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

                            ELF header

                            Class:ELF32
                            Data:2's complement, little endian
                            Version:1 (current)
                            Machine:ARM
                            Version Number:0x1
                            Type:EXEC (Executable file)
                            OS/ABI:ARM - ABI
                            ABI Version:0
                            Entry Point Address:0x8190
                            Flags:0x202
                            ELF Header Size:52
                            Program Header Offset:52
                            Program Header Size:32
                            Number of Program Headers:3
                            Section Header Offset:49968
                            Section Header Size:40
                            Number of Section Headers:11
                            Header String Table Index:10
                            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                            NULL0x00x00x00x00x0000
                            .initPROGBITS0x80940x940x180x00x6AX004
                            .textPROGBITS0x80b00xb00xb8b00x00x6AX0016
                            .finiPROGBITS0x139600xb9600x140x00x6AX004
                            .rodataPROGBITS0x139740xb9740x7b40x00x2A004
                            .ctorsPROGBITS0x1c12c0xc12c0x80x00x3WA004
                            .dtorsPROGBITS0x1c1340xc1340x80x00x3WA004
                            .jcrPROGBITS0x1c13c0xc13c0x40x00x3WA004
                            .dataPROGBITS0x1c1400xc1400x1ac0x00x3WA004
                            .bssNOBITS0x1c2ec0xc2ec0x2680x00x3WA004
                            .shstrtabSTRTAB0x00xc2ec0x430x00x0001
                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                            LOAD0x00x80000x80000xc1280xc1286.02340x5R E0x8000.init .text .fini .rodata
                            LOAD0xc12c0x1c12c0x1c12c0x1c00x4282.30540x6RW 0x8000.ctors .dtors .jcr .data .bss
                            GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                            TimestampSource PortDest PortSource IPDest IP
                            Feb 1, 2025 14:46:18.065093040 CET546941440192.168.2.1464.225.86.206
                            Feb 1, 2025 14:46:18.069930077 CET14405469464.225.86.206192.168.2.14
                            Feb 1, 2025 14:46:18.069988012 CET546941440192.168.2.1464.225.86.206
                            Feb 1, 2025 14:46:18.071444035 CET546941440192.168.2.1464.225.86.206
                            Feb 1, 2025 14:46:18.076190948 CET14405469464.225.86.206192.168.2.14
                            Feb 1, 2025 14:46:18.076234102 CET546941440192.168.2.1464.225.86.206
                            Feb 1, 2025 14:46:18.081037045 CET14405469464.225.86.206192.168.2.14
                            Feb 1, 2025 14:46:28.081357956 CET546941440192.168.2.1464.225.86.206
                            Feb 1, 2025 14:46:28.086239100 CET14405469464.225.86.206192.168.2.14
                            Feb 1, 2025 14:46:28.641881943 CET14405469464.225.86.206192.168.2.14
                            Feb 1, 2025 14:46:28.642445087 CET546941440192.168.2.1464.225.86.206
                            Feb 1, 2025 14:46:28.647362947 CET14405469464.225.86.206192.168.2.14
                            Feb 1, 2025 14:46:29.679682016 CET437401440192.168.2.14209.38.56.135
                            Feb 1, 2025 14:46:29.684505939 CET144043740209.38.56.135192.168.2.14
                            Feb 1, 2025 14:46:29.684588909 CET437401440192.168.2.14209.38.56.135
                            Feb 1, 2025 14:46:29.685390949 CET437401440192.168.2.14209.38.56.135
                            Feb 1, 2025 14:46:29.690175056 CET144043740209.38.56.135192.168.2.14
                            Feb 1, 2025 14:46:29.690238953 CET437401440192.168.2.14209.38.56.135
                            Feb 1, 2025 14:46:29.694969893 CET144043740209.38.56.135192.168.2.14
                            Feb 1, 2025 14:46:29.729242086 CET46540443192.168.2.14185.125.190.26
                            Feb 1, 2025 14:46:41.120348930 CET144043740209.38.56.135192.168.2.14
                            Feb 1, 2025 14:46:41.120650053 CET437401440192.168.2.14209.38.56.135
                            Feb 1, 2025 14:46:41.125437975 CET144043740209.38.56.135192.168.2.14
                            Feb 1, 2025 14:46:42.141747952 CET376201440192.168.2.14209.38.188.134
                            Feb 1, 2025 14:46:42.146541119 CET144037620209.38.188.134192.168.2.14
                            Feb 1, 2025 14:46:42.146657944 CET376201440192.168.2.14209.38.188.134
                            Feb 1, 2025 14:46:42.147908926 CET376201440192.168.2.14209.38.188.134
                            Feb 1, 2025 14:46:42.152663946 CET144037620209.38.188.134192.168.2.14
                            Feb 1, 2025 14:46:42.152754068 CET376201440192.168.2.14209.38.188.134
                            Feb 1, 2025 14:46:42.157557011 CET144037620209.38.188.134192.168.2.14
                            Feb 1, 2025 14:46:52.774765968 CET144037620209.38.188.134192.168.2.14
                            Feb 1, 2025 14:46:52.774983883 CET376201440192.168.2.14209.38.188.134
                            Feb 1, 2025 14:46:52.779867887 CET144037620209.38.188.134192.168.2.14
                            Feb 1, 2025 14:46:53.797326088 CET570541440192.168.2.1468.183.244.135
                            Feb 1, 2025 14:46:53.802134037 CET14405705468.183.244.135192.168.2.14
                            Feb 1, 2025 14:46:53.802208900 CET570541440192.168.2.1468.183.244.135
                            Feb 1, 2025 14:46:53.803714037 CET570541440192.168.2.1468.183.244.135
                            Feb 1, 2025 14:46:53.808465958 CET14405705468.183.244.135192.168.2.14
                            Feb 1, 2025 14:46:53.808527946 CET570541440192.168.2.1468.183.244.135
                            Feb 1, 2025 14:46:53.813323975 CET14405705468.183.244.135192.168.2.14
                            Feb 1, 2025 14:47:00.192250967 CET46540443192.168.2.14185.125.190.26
                            Feb 1, 2025 14:47:05.158977032 CET14405705468.183.244.135192.168.2.14
                            Feb 1, 2025 14:47:05.159282923 CET570541440192.168.2.1468.183.244.135
                            Feb 1, 2025 14:47:05.164097071 CET14405705468.183.244.135192.168.2.14
                            Feb 1, 2025 14:47:06.249392986 CET570561440192.168.2.1468.183.244.135
                            Feb 1, 2025 14:47:06.254271030 CET14405705668.183.244.135192.168.2.14
                            Feb 1, 2025 14:47:06.254352093 CET570561440192.168.2.1468.183.244.135
                            Feb 1, 2025 14:47:06.255906105 CET570561440192.168.2.1468.183.244.135
                            Feb 1, 2025 14:47:06.260668039 CET14405705668.183.244.135192.168.2.14
                            Feb 1, 2025 14:47:06.260720015 CET570561440192.168.2.1468.183.244.135
                            Feb 1, 2025 14:47:06.265552998 CET14405705668.183.244.135192.168.2.14
                            Feb 1, 2025 14:47:17.580879927 CET14405705668.183.244.135192.168.2.14
                            Feb 1, 2025 14:47:17.581149101 CET570561440192.168.2.1468.183.244.135
                            Feb 1, 2025 14:47:17.585954905 CET14405705668.183.244.135192.168.2.14
                            Feb 1, 2025 14:47:18.607728958 CET437481440192.168.2.14209.38.56.135
                            Feb 1, 2025 14:47:18.612601042 CET144043748209.38.56.135192.168.2.14
                            Feb 1, 2025 14:47:18.612667084 CET437481440192.168.2.14209.38.56.135
                            Feb 1, 2025 14:47:18.613616943 CET437481440192.168.2.14209.38.56.135
                            Feb 1, 2025 14:47:18.618424892 CET144043748209.38.56.135192.168.2.14
                            Feb 1, 2025 14:47:18.618469954 CET437481440192.168.2.14209.38.56.135
                            Feb 1, 2025 14:47:18.623250961 CET144043748209.38.56.135192.168.2.14
                            Feb 1, 2025 14:47:30.059027910 CET144043748209.38.56.135192.168.2.14
                            Feb 1, 2025 14:47:30.059331894 CET437481440192.168.2.14209.38.56.135
                            Feb 1, 2025 14:47:30.066745996 CET144043748209.38.56.135192.168.2.14
                            Feb 1, 2025 14:47:31.079977989 CET437501440192.168.2.14209.38.56.135
                            Feb 1, 2025 14:47:31.085102081 CET144043750209.38.56.135192.168.2.14
                            Feb 1, 2025 14:47:31.085155010 CET437501440192.168.2.14209.38.56.135
                            Feb 1, 2025 14:47:31.086370945 CET437501440192.168.2.14209.38.56.135
                            Feb 1, 2025 14:47:31.091155052 CET144043750209.38.56.135192.168.2.14
                            Feb 1, 2025 14:47:31.091200113 CET437501440192.168.2.14209.38.56.135
                            Feb 1, 2025 14:47:31.095983982 CET144043750209.38.56.135192.168.2.14
                            Feb 1, 2025 14:47:41.096239090 CET437501440192.168.2.14209.38.56.135
                            Feb 1, 2025 14:47:41.101933002 CET144043750209.38.56.135192.168.2.14
                            Feb 1, 2025 14:47:41.695564032 CET144043750209.38.56.135192.168.2.14
                            Feb 1, 2025 14:47:41.696187973 CET437501440192.168.2.14209.38.56.135
                            Feb 1, 2025 14:47:41.701008081 CET144043750209.38.56.135192.168.2.14
                            Feb 1, 2025 14:47:42.730040073 CET547081440192.168.2.1464.225.86.206
                            Feb 1, 2025 14:47:42.734914064 CET14405470864.225.86.206192.168.2.14
                            Feb 1, 2025 14:47:42.735007048 CET547081440192.168.2.1464.225.86.206
                            Feb 1, 2025 14:47:42.736100912 CET547081440192.168.2.1464.225.86.206
                            Feb 1, 2025 14:47:42.740963936 CET14405470864.225.86.206192.168.2.14
                            Feb 1, 2025 14:47:42.741022110 CET547081440192.168.2.1464.225.86.206
                            Feb 1, 2025 14:47:42.745793104 CET14405470864.225.86.206192.168.2.14
                            Feb 1, 2025 14:47:54.040636063 CET14405470864.225.86.206192.168.2.14
                            Feb 1, 2025 14:47:54.040828943 CET547081440192.168.2.1464.225.86.206
                            Feb 1, 2025 14:47:54.045577049 CET14405470864.225.86.206192.168.2.14
                            Feb 1, 2025 14:47:55.077584028 CET442841440192.168.2.14209.38.56.129
                            Feb 1, 2025 14:47:55.082340002 CET144044284209.38.56.129192.168.2.14
                            Feb 1, 2025 14:47:55.082432032 CET442841440192.168.2.14209.38.56.129
                            Feb 1, 2025 14:47:55.083507061 CET442841440192.168.2.14209.38.56.129
                            Feb 1, 2025 14:47:55.088291883 CET144044284209.38.56.129192.168.2.14
                            Feb 1, 2025 14:47:55.088350058 CET442841440192.168.2.14209.38.56.129
                            Feb 1, 2025 14:47:55.093064070 CET144044284209.38.56.129192.168.2.14
                            Feb 1, 2025 14:48:06.445494890 CET144044284209.38.56.129192.168.2.14
                            Feb 1, 2025 14:48:06.445708990 CET442841440192.168.2.14209.38.56.129
                            Feb 1, 2025 14:48:06.450930119 CET144044284209.38.56.129192.168.2.14
                            Feb 1, 2025 14:48:07.467370987 CET570661440192.168.2.1468.183.244.135
                            Feb 1, 2025 14:48:07.472243071 CET14405706668.183.244.135192.168.2.14
                            Feb 1, 2025 14:48:07.472342014 CET570661440192.168.2.1468.183.244.135
                            Feb 1, 2025 14:48:07.473321915 CET570661440192.168.2.1468.183.244.135
                            Feb 1, 2025 14:48:07.478075027 CET14405706668.183.244.135192.168.2.14
                            Feb 1, 2025 14:48:07.478138924 CET570661440192.168.2.1468.183.244.135
                            Feb 1, 2025 14:48:07.482907057 CET14405706668.183.244.135192.168.2.14
                            Feb 1, 2025 14:48:18.790261030 CET14405706668.183.244.135192.168.2.14
                            Feb 1, 2025 14:48:18.790441990 CET570661440192.168.2.1468.183.244.135
                            Feb 1, 2025 14:48:18.795401096 CET14405706668.183.244.135192.168.2.14
                            Feb 1, 2025 14:48:19.810524940 CET570681440192.168.2.1468.183.244.135
                            Feb 1, 2025 14:48:19.816334963 CET14405706868.183.244.135192.168.2.14
                            Feb 1, 2025 14:48:19.816427946 CET570681440192.168.2.1468.183.244.135
                            Feb 1, 2025 14:48:19.817709923 CET570681440192.168.2.1468.183.244.135
                            Feb 1, 2025 14:48:19.822650909 CET14405706868.183.244.135192.168.2.14
                            Feb 1, 2025 14:48:19.822743893 CET570681440192.168.2.1468.183.244.135
                            Feb 1, 2025 14:48:19.827567101 CET14405706868.183.244.135192.168.2.14
                            TimestampSource PortDest PortSource IPDest IP
                            Feb 1, 2025 14:46:18.030462027 CET5340653192.168.2.14185.181.61.24
                            Feb 1, 2025 14:46:18.063790083 CET5353406185.181.61.24192.168.2.14
                            Feb 1, 2025 14:46:29.645742893 CET3451553192.168.2.14185.181.61.24
                            Feb 1, 2025 14:46:29.678843975 CET5334515185.181.61.24192.168.2.14
                            Feb 1, 2025 14:46:42.123651028 CET6090053192.168.2.14152.53.15.127
                            Feb 1, 2025 14:46:42.140882015 CET5360900152.53.15.127192.168.2.14
                            Feb 1, 2025 14:46:53.779098034 CET3398453192.168.2.14152.53.15.127
                            Feb 1, 2025 14:46:53.796448946 CET5333984152.53.15.127192.168.2.14
                            Feb 1, 2025 14:47:06.163115025 CET4608053192.168.2.1451.158.108.203
                            Feb 1, 2025 14:47:06.179338932 CET534608051.158.108.203192.168.2.14
                            Feb 1, 2025 14:47:06.181040049 CET5568353192.168.2.1451.158.108.203
                            Feb 1, 2025 14:47:06.196772099 CET535568351.158.108.203192.168.2.14
                            Feb 1, 2025 14:47:06.198246002 CET4775653192.168.2.1451.158.108.203
                            Feb 1, 2025 14:47:06.213969946 CET534775651.158.108.203192.168.2.14
                            Feb 1, 2025 14:47:06.215774059 CET5751853192.168.2.1451.158.108.203
                            Feb 1, 2025 14:47:06.231679916 CET535751851.158.108.203192.168.2.14
                            Feb 1, 2025 14:47:06.233191013 CET3829653192.168.2.1451.158.108.203
                            Feb 1, 2025 14:47:06.248483896 CET533829651.158.108.203192.168.2.14
                            Feb 1, 2025 14:47:18.584275007 CET4312853192.168.2.14194.36.144.87
                            Feb 1, 2025 14:47:18.607060909 CET5343128194.36.144.87192.168.2.14
                            Feb 1, 2025 14:47:31.063297987 CET4965353192.168.2.1451.158.108.203
                            Feb 1, 2025 14:47:31.078865051 CET534965351.158.108.203192.168.2.14
                            Feb 1, 2025 14:47:42.700836897 CET3567353192.168.2.1481.169.136.222
                            Feb 1, 2025 14:47:42.728163958 CET533567381.169.136.222192.168.2.14
                            Feb 1, 2025 14:47:55.043235064 CET4527453192.168.2.14185.181.61.24
                            Feb 1, 2025 14:47:55.077068090 CET5345274185.181.61.24192.168.2.14
                            Feb 1, 2025 14:48:07.448549032 CET4763153192.168.2.14202.61.197.122
                            Feb 1, 2025 14:48:07.466658115 CET5347631202.61.197.122192.168.2.14
                            Feb 1, 2025 14:48:19.794176102 CET3450153192.168.2.1451.158.108.203
                            Feb 1, 2025 14:48:19.809778929 CET533450151.158.108.203192.168.2.14
                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                            Feb 1, 2025 14:46:18.030462027 CET192.168.2.14185.181.61.240xe26bStandard query (0)serisbot.geekA (IP address)IN (0x0001)false
                            Feb 1, 2025 14:46:29.645742893 CET192.168.2.14185.181.61.240x6b7dStandard query (0)serisbot.geekA (IP address)IN (0x0001)false
                            Feb 1, 2025 14:46:42.123651028 CET192.168.2.14152.53.15.1270xb18fStandard query (0)serisbot.geekA (IP address)IN (0x0001)false
                            Feb 1, 2025 14:46:53.779098034 CET192.168.2.14152.53.15.1270xb8efStandard query (0)serisontop.dynA (IP address)IN (0x0001)false
                            Feb 1, 2025 14:47:06.163115025 CET192.168.2.1451.158.108.2030x596fStandard query (0)serisbot.geek. [malformed]256474false
                            Feb 1, 2025 14:47:06.181040049 CET192.168.2.1451.158.108.2030x596fStandard query (0)serisbot.geek. [malformed]256474false
                            Feb 1, 2025 14:47:06.198246002 CET192.168.2.1451.158.108.2030x596fStandard query (0)serisbot.geek. [malformed]256474false
                            Feb 1, 2025 14:47:06.215774059 CET192.168.2.1451.158.108.2030x596fStandard query (0)serisbot.geek. [malformed]256474false
                            Feb 1, 2025 14:47:06.233191013 CET192.168.2.1451.158.108.2030x596fStandard query (0)serisbot.geek. [malformed]256474false
                            Feb 1, 2025 14:47:18.584275007 CET192.168.2.14194.36.144.870x69cbStandard query (0)serisontop.dynA (IP address)IN (0x0001)false
                            Feb 1, 2025 14:47:31.063297987 CET192.168.2.1451.158.108.2030x531cStandard query (0)serisontop.dynA (IP address)IN (0x0001)false
                            Feb 1, 2025 14:47:42.700836897 CET192.168.2.1481.169.136.2220x956bStandard query (0)serisontop.dynA (IP address)IN (0x0001)false
                            Feb 1, 2025 14:47:55.043235064 CET192.168.2.14185.181.61.240x870cStandard query (0)serisontop.dynA (IP address)IN (0x0001)false
                            Feb 1, 2025 14:48:07.448549032 CET192.168.2.14202.61.197.1220x227aStandard query (0)serisontop.dynA (IP address)IN (0x0001)false
                            Feb 1, 2025 14:48:19.794176102 CET192.168.2.1451.158.108.2030x177aStandard query (0)serisontop.dynA (IP address)IN (0x0001)false
                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                            Feb 1, 2025 14:46:18.063790083 CET185.181.61.24192.168.2.140xe26bNo error (0)serisbot.geek64.225.86.206A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:46:18.063790083 CET185.181.61.24192.168.2.140xe26bNo error (0)serisbot.geek146.190.204.203A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:46:18.063790083 CET185.181.61.24192.168.2.140xe26bNo error (0)serisbot.geek209.38.56.135A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:46:18.063790083 CET185.181.61.24192.168.2.140xe26bNo error (0)serisbot.geek209.38.56.129A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:46:18.063790083 CET185.181.61.24192.168.2.140xe26bNo error (0)serisbot.geek68.183.244.135A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:46:18.063790083 CET185.181.61.24192.168.2.140xe26bNo error (0)serisbot.geek209.38.188.134A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:46:29.678843975 CET185.181.61.24192.168.2.140x6b7dNo error (0)serisbot.geek209.38.56.135A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:46:29.678843975 CET185.181.61.24192.168.2.140x6b7dNo error (0)serisbot.geek209.38.56.129A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:46:29.678843975 CET185.181.61.24192.168.2.140x6b7dNo error (0)serisbot.geek64.225.86.206A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:46:29.678843975 CET185.181.61.24192.168.2.140x6b7dNo error (0)serisbot.geek146.190.204.203A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:46:29.678843975 CET185.181.61.24192.168.2.140x6b7dNo error (0)serisbot.geek68.183.244.135A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:46:29.678843975 CET185.181.61.24192.168.2.140x6b7dNo error (0)serisbot.geek209.38.188.134A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:46:42.140882015 CET152.53.15.127192.168.2.140xb18fNo error (0)serisbot.geek209.38.56.129A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:46:42.140882015 CET152.53.15.127192.168.2.140xb18fNo error (0)serisbot.geek68.183.244.135A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:46:42.140882015 CET152.53.15.127192.168.2.140xb18fNo error (0)serisbot.geek209.38.188.134A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:46:42.140882015 CET152.53.15.127192.168.2.140xb18fNo error (0)serisbot.geek64.225.86.206A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:46:42.140882015 CET152.53.15.127192.168.2.140xb18fNo error (0)serisbot.geek209.38.56.135A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:46:42.140882015 CET152.53.15.127192.168.2.140xb18fNo error (0)serisbot.geek146.190.204.203A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:46:53.796448946 CET152.53.15.127192.168.2.140xb8efNo error (0)serisontop.dyn64.225.86.206A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:46:53.796448946 CET152.53.15.127192.168.2.140xb8efNo error (0)serisontop.dyn146.190.204.203A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:46:53.796448946 CET152.53.15.127192.168.2.140xb8efNo error (0)serisontop.dyn68.183.244.135A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:46:53.796448946 CET152.53.15.127192.168.2.140xb8efNo error (0)serisontop.dyn209.38.188.134A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:46:53.796448946 CET152.53.15.127192.168.2.140xb8efNo error (0)serisontop.dyn209.38.56.135A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:46:53.796448946 CET152.53.15.127192.168.2.140xb8efNo error (0)serisontop.dyn209.38.56.129A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:47:06.179338932 CET51.158.108.203192.168.2.140x596fFormat error (1)serisbot.geek. [malformed]nonenone256474false
                            Feb 1, 2025 14:47:06.196772099 CET51.158.108.203192.168.2.140x596fFormat error (1)serisbot.geek. [malformed]nonenone256474false
                            Feb 1, 2025 14:47:06.213969946 CET51.158.108.203192.168.2.140x596fFormat error (1)serisbot.geek. [malformed]nonenone256474false
                            Feb 1, 2025 14:47:06.231679916 CET51.158.108.203192.168.2.140x596fFormat error (1)serisbot.geek. [malformed]nonenone256474false
                            Feb 1, 2025 14:47:06.248483896 CET51.158.108.203192.168.2.140x596fFormat error (1)serisbot.geek. [malformed]nonenone256474false
                            Feb 1, 2025 14:47:18.607060909 CET194.36.144.87192.168.2.140x69cbNo error (0)serisontop.dyn209.38.188.134A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:47:18.607060909 CET194.36.144.87192.168.2.140x69cbNo error (0)serisontop.dyn64.225.86.206A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:47:18.607060909 CET194.36.144.87192.168.2.140x69cbNo error (0)serisontop.dyn68.183.244.135A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:47:18.607060909 CET194.36.144.87192.168.2.140x69cbNo error (0)serisontop.dyn209.38.56.135A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:47:18.607060909 CET194.36.144.87192.168.2.140x69cbNo error (0)serisontop.dyn209.38.56.129A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:47:18.607060909 CET194.36.144.87192.168.2.140x69cbNo error (0)serisontop.dyn146.190.204.203A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:47:31.078865051 CET51.158.108.203192.168.2.140x531cNo error (0)serisontop.dyn146.190.204.203A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:47:31.078865051 CET51.158.108.203192.168.2.140x531cNo error (0)serisontop.dyn209.38.56.129A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:47:31.078865051 CET51.158.108.203192.168.2.140x531cNo error (0)serisontop.dyn64.225.86.206A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:47:31.078865051 CET51.158.108.203192.168.2.140x531cNo error (0)serisontop.dyn68.183.244.135A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:47:31.078865051 CET51.158.108.203192.168.2.140x531cNo error (0)serisontop.dyn209.38.56.135A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:47:31.078865051 CET51.158.108.203192.168.2.140x531cNo error (0)serisontop.dyn209.38.188.134A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:47:42.728163958 CET81.169.136.222192.168.2.140x956bNo error (0)serisontop.dyn146.190.204.203A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:47:42.728163958 CET81.169.136.222192.168.2.140x956bNo error (0)serisontop.dyn68.183.244.135A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:47:42.728163958 CET81.169.136.222192.168.2.140x956bNo error (0)serisontop.dyn64.225.86.206A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:47:42.728163958 CET81.169.136.222192.168.2.140x956bNo error (0)serisontop.dyn209.38.188.134A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:47:42.728163958 CET81.169.136.222192.168.2.140x956bNo error (0)serisontop.dyn209.38.56.135A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:47:42.728163958 CET81.169.136.222192.168.2.140x956bNo error (0)serisontop.dyn209.38.56.129A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:47:55.077068090 CET185.181.61.24192.168.2.140x870cNo error (0)serisontop.dyn209.38.188.134A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:47:55.077068090 CET185.181.61.24192.168.2.140x870cNo error (0)serisontop.dyn209.38.56.129A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:47:55.077068090 CET185.181.61.24192.168.2.140x870cNo error (0)serisontop.dyn68.183.244.135A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:47:55.077068090 CET185.181.61.24192.168.2.140x870cNo error (0)serisontop.dyn64.225.86.206A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:47:55.077068090 CET185.181.61.24192.168.2.140x870cNo error (0)serisontop.dyn146.190.204.203A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:47:55.077068090 CET185.181.61.24192.168.2.140x870cNo error (0)serisontop.dyn209.38.56.135A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:48:07.466658115 CET202.61.197.122192.168.2.140x227aNo error (0)serisontop.dyn146.190.204.203A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:48:07.466658115 CET202.61.197.122192.168.2.140x227aNo error (0)serisontop.dyn209.38.56.135A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:48:07.466658115 CET202.61.197.122192.168.2.140x227aNo error (0)serisontop.dyn64.225.86.206A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:48:07.466658115 CET202.61.197.122192.168.2.140x227aNo error (0)serisontop.dyn209.38.188.134A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:48:07.466658115 CET202.61.197.122192.168.2.140x227aNo error (0)serisontop.dyn68.183.244.135A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:48:07.466658115 CET202.61.197.122192.168.2.140x227aNo error (0)serisontop.dyn209.38.56.129A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:48:19.809778929 CET51.158.108.203192.168.2.140x177aNo error (0)serisontop.dyn209.38.56.135A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:48:19.809778929 CET51.158.108.203192.168.2.140x177aNo error (0)serisontop.dyn209.38.188.134A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:48:19.809778929 CET51.158.108.203192.168.2.140x177aNo error (0)serisontop.dyn146.190.204.203A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:48:19.809778929 CET51.158.108.203192.168.2.140x177aNo error (0)serisontop.dyn209.38.56.129A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:48:19.809778929 CET51.158.108.203192.168.2.140x177aNo error (0)serisontop.dyn64.225.86.206A (IP address)IN (0x0001)false
                            Feb 1, 2025 14:48:19.809778929 CET51.158.108.203192.168.2.140x177aNo error (0)serisontop.dyn68.183.244.135A (IP address)IN (0x0001)false

                            System Behavior

                            Start time (UTC):13:46:16
                            Start date (UTC):01/02/2025
                            Path:/tmp/zerarm.elf
                            Arguments:/tmp/zerarm.elf
                            File size:4956856 bytes
                            MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                            Start time (UTC):13:46:16
                            Start date (UTC):01/02/2025
                            Path:/tmp/zerarm.elf
                            Arguments:-
                            File size:4956856 bytes
                            MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                            Start time (UTC):13:46:16
                            Start date (UTC):01/02/2025
                            Path:/tmp/zerarm.elf
                            Arguments:-
                            File size:4956856 bytes
                            MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1