Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
morte.sh4.elf

Overview

General Information

Sample name:morte.sh4.elf
Analysis ID:1635833
MD5:3986d65e580873829f87ec7e1d161733
SHA1:e8402bd5f0e9e0874794e9491692e9f1eb8c1216
SHA256:6c3a059b488d6dff0097a9e41acc5a6e0560d8f76f0516c4a372a3fbad7022fe
Tags:elfuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1635833
Start date and time:2025-03-12 02:37:24 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 44s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:morte.sh4.elf
Detection:MAL
Classification:mal56.linELF@0/0@0/0
Command:/tmp/morte.sh4.elf
PID:5493
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: morte.sh4.elfAvira: detected
Source: morte.sh4.elfVirustotal: Detection: 37%Perma Link
Source: morte.sh4.elfReversingLabs: Detection: 39%
Source: global trafficTCP traffic: 192.168.2.14:56666 -> 176.65.134.62:7777
Source: /tmp/morte.sh4.elf (PID: 5495)Socket: 127.0.0.1:65407Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.134.62
Source: ELF static info symbol of initial sample.symtab present: no
Source: /tmp/morte.sh4.elf (PID: 5531)SIGKILL sent: pid: 5529, result: successfulJump to behavior
Source: classification engineClassification label: mal56.linELF@0/0@0/0
Source: /tmp/morte.sh4.elf (PID: 5493)Queries kernel information via 'uname': Jump to behavior
Source: morte.sh4.elf, 5493.1.00007ffcddb36000.00007ffcddb57000.rw-.sdmp, morte.sh4.elf, 5497.1.00007ffcddb36000.00007ffcddb57000.rw-.sdmp, morte.sh4.elf, 5529.1.00007ffcddb36000.00007ffcddb57000.rw-.sdmp, morte.sh4.elf, 5531.1.00007ffcddb36000.00007ffcddb57000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sh4
Source: morte.sh4.elf, 5493.1.00007ffcddb36000.00007ffcddb57000.rw-.sdmp, morte.sh4.elf, 5497.1.00007ffcddb36000.00007ffcddb57000.rw-.sdmp, morte.sh4.elf, 5529.1.00007ffcddb36000.00007ffcddb57000.rw-.sdmp, morte.sh4.elf, 5531.1.00007ffcddb36000.00007ffcddb57000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-sh4/tmp/morte.sh4.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/morte.sh4.elf
Source: morte.sh4.elf, 5493.1.000056500a85b000.000056500a8be000.rw-.sdmp, morte.sh4.elf, 5497.1.000056500a85b000.000056500a8be000.rw-.sdmp, morte.sh4.elf, 5529.1.000056500a85b000.000056500a8be000.rw-.sdmp, morte.sh4.elf, 5531.1.000056500a85b000.000056500a8be000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sh4
Source: morte.sh4.elf, 5493.1.000056500a85b000.000056500a8be000.rw-.sdmp, morte.sh4.elf, 5497.1.000056500a85b000.000056500a8be000.rw-.sdmp, morte.sh4.elf, 5529.1.000056500a85b000.000056500a8be000.rw-.sdmp, morte.sh4.elf, 5531.1.000056500a85b000.000056500a8be000.rw-.sdmpBinary or memory string: PV5!/etc/qemu-binfmt/sh4
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1635833 Sample: morte.sh4.elf Startdate: 12/03/2025 Architecture: LINUX Score: 56 19 176.65.134.62, 56666, 56668, 56670 DIOGELO-ASGB Germany 2->19 21 Antivirus / Scanner detection for submitted sample 2->21 23 Multi AV Scanner detection for submitted file 2->23 9 morte.sh4.elf 2->9         started        signatures3 process4 process5 11 morte.sh4.elf 9->11         started        process6 13 morte.sh4.elf 11->13         started        15 morte.sh4.elf 11->15         started        process7 17 morte.sh4.elf 13->17         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
morte.sh4.elf38%VirustotalBrowse
morte.sh4.elf39%ReversingLabsLinux.Exploit.Mirai
morte.sh4.elf100%AviraEXP/ELF.Mirai.N
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
176.65.134.62
unknownGermany
56325DIOGELO-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
176.65.134.62morte.mpsl.elfGet hashmaliciousUnknownBrowse
    morte.ppc.elfGet hashmaliciousUnknownBrowse
      morte.arm.elfGet hashmaliciousUnknownBrowse
        morte.mips.elfGet hashmaliciousUnknownBrowse
          morte.mpsl.elfGet hashmaliciousUnknownBrowse
            morte.x86.elfGet hashmaliciousUnknownBrowse
              morte.sh4.elfGet hashmaliciousUnknownBrowse
                morte.m68k.elfGet hashmaliciousUnknownBrowse
                  morte.arm7.elfGet hashmaliciousUnknownBrowse
                    morte.arm7.elfGet hashmaliciousMiraiBrowse
                      No context
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      DIOGELO-ASGBmorte.mpsl.elfGet hashmaliciousUnknownBrowse
                      • 176.65.134.62
                      morte.ppc.elfGet hashmaliciousUnknownBrowse
                      • 176.65.134.62
                      morte.arm.elfGet hashmaliciousUnknownBrowse
                      • 176.65.134.62
                      morte.mips.elfGet hashmaliciousUnknownBrowse
                      • 176.65.134.62
                      morte.mpsl.elfGet hashmaliciousUnknownBrowse
                      • 176.65.134.62
                      morte.x86.elfGet hashmaliciousUnknownBrowse
                      • 176.65.134.62
                      morte.sh4.elfGet hashmaliciousUnknownBrowse
                      • 176.65.134.62
                      morte.m68k.elfGet hashmaliciousUnknownBrowse
                      • 176.65.134.62
                      morte.arm7.elfGet hashmaliciousUnknownBrowse
                      • 176.65.134.62
                      morte.arm7.elfGet hashmaliciousMiraiBrowse
                      • 176.65.134.62
                      No context
                      No context
                      No created / dropped files found
                      File type:ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
                      Entropy (8bit):6.066658118043394
                      TrID:
                      • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                      File name:morte.sh4.elf
                      File size:105'060 bytes
                      MD5:3986d65e580873829f87ec7e1d161733
                      SHA1:e8402bd5f0e9e0874794e9491692e9f1eb8c1216
                      SHA256:6c3a059b488d6dff0097a9e41acc5a6e0560d8f76f0516c4a372a3fbad7022fe
                      SHA512:aa2326371099309ae63a2e8a1654c5b213cc309b676ac7c2b8af3919138ab4772613a99e9e15e7962b308f88a544889e9a297de040df6f710dafe97d61f48977
                      SSDEEP:1536:1aOlFpIg5z9sLxeAFrCJdKU4KC7wK86xMqUW4WfDc2g8:1plnIOzeL4AFr4EUjK8L/W1fD0
                      TLSH:24A33973C8266E9CD664E5B4B0B09F7D1B53A91592470FBE1566C3B88043D8DFA0A3F8
                      File Content Preview:.ELF..............*.......@.4...........4. ...(...............@...@.@I..@I...............P...PB..PB.hH..............Q.td............................././"O.n........#.*@........#.*@.,...o&O.n...l..............................././.../.a"O.!...n...a.b("...q.

                      ELF header

                      Class:ELF32
                      Data:2's complement, little endian
                      Version:1 (current)
                      Machine:<unknown>
                      Version Number:0x1
                      Type:EXEC (Executable file)
                      OS/ABI:UNIX - System V
                      ABI Version:0
                      Entry Point Address:0x4001a0
                      Flags:0x9
                      ELF Header Size:52
                      Program Header Offset:52
                      Program Header Size:32
                      Number of Program Headers:3
                      Section Header Offset:104620
                      Section Header Size:40
                      Number of Section Headers:11
                      Header String Table Index:10
                      NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                      NULL0x00x00x00x00x0000
                      .initPROGBITS0x4000940x940x300x00x6AX004
                      .textPROGBITS0x4000e00xe00x12c200x00x6AX0032
                      .finiPROGBITS0x412d000x12d000x240x00x6AX004
                      .rodataPROGBITS0x412d240x12d240x1c1c0x00x2A004
                      .ctorsPROGBITS0x4250000x150000xc0x00x3WA004
                      .dtorsPROGBITS0x42500c0x1500c0x80x00x3WA004
                      .dataPROGBITS0x4250200x150200x48340x00x3WA0032
                      .gotPROGBITS0x4298540x198540x140x40x3WA004
                      .bssNOBITS0x4298680x198680x46b40x00x3WA004
                      .shstrtabSTRTAB0x00x198680x430x00x0001
                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                      LOAD0x00x4000000x4000000x149400x149406.91530x5R E0x10000.init .text .fini .rodata
                      LOAD0x150000x4250000x4250000x48680x8f1c0.32100x6RW 0x10000.ctors .dtors .data .got .bss
                      GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                      TimestampSource PortDest PortSource IPDest IP
                      Mar 12, 2025 02:38:23.682094097 CET566667777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:23.686892986 CET777756666176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:23.686944008 CET566667777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:23.698554993 CET566667777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:23.703310966 CET777756666176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:23.703361988 CET566667777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:23.708091021 CET777756666176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:24.367404938 CET777756666176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:24.367501974 CET566667777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:24.367683887 CET566667777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:24.368408918 CET566687777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:24.373159885 CET777756668176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:24.373245001 CET566687777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:24.374257088 CET566687777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:24.378946066 CET777756668176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:24.379065990 CET566687777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:24.383727074 CET777756668176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:25.053634882 CET777756668176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:25.053761959 CET566687777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:25.053797960 CET566687777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:25.054255962 CET566707777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:25.059721947 CET777756670176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:25.059799910 CET566707777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:25.060585022 CET566707777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:25.065916061 CET777756670176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:25.065967083 CET566707777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:25.071664095 CET777756670176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:25.747963905 CET777756670176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:25.748203039 CET566707777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:25.748203039 CET566707777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:25.748594999 CET566727777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:25.753496885 CET777756672176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:25.753552914 CET566727777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:25.754106998 CET566727777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:25.759021044 CET777756672176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:25.759069920 CET566727777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:25.764141083 CET777756672176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:26.431878090 CET777756672176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:26.432082891 CET566727777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:26.432082891 CET566727777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:26.432457924 CET566747777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:26.437175035 CET777756674176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:26.437222958 CET566747777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:26.437838078 CET566747777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:26.442581892 CET777756674176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:26.442636967 CET566747777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:26.447386026 CET777756674176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:27.131231070 CET777756674176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:27.131443024 CET566747777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:27.131443024 CET566747777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:27.131814003 CET566767777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:27.136549950 CET777756676176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:27.136600971 CET566767777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:27.137217045 CET566767777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:27.300931931 CET777756676176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:27.301011086 CET566767777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:27.306013107 CET777756676176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:28.028800964 CET777756676176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:28.029027939 CET566767777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:28.029027939 CET566767777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:28.029408932 CET566787777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:28.034176111 CET777756678176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:28.034234047 CET566787777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:28.034842014 CET566787777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:28.039531946 CET777756678176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:28.039593935 CET566787777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:28.044363022 CET777756678176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:28.717067957 CET777756678176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:28.717385054 CET566787777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:28.717385054 CET566787777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:28.717848063 CET566807777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:28.722563982 CET777756680176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:28.722626925 CET566807777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:28.723301888 CET566807777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:28.728028059 CET777756680176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:28.728085041 CET566807777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:28.732831955 CET777756680176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:29.437378883 CET777756680176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:29.437587023 CET566807777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:29.437587023 CET566807777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:29.438080072 CET566827777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:29.442877054 CET777756682176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:29.442936897 CET566827777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:29.443662882 CET566827777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:29.448417902 CET777756682176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:29.448472023 CET566827777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:29.453191042 CET777756682176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:30.130105972 CET777756682176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:30.130327940 CET566827777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:30.130423069 CET566827777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:30.130968094 CET566847777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:30.135741949 CET777756684176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:30.135797024 CET566847777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:30.136461020 CET566847777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:30.141160011 CET777756684176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:30.141210079 CET566847777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:30.145873070 CET777756684176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:30.830874920 CET777756684176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:30.831068993 CET566847777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:30.831139088 CET566847777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:30.831624985 CET566867777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:30.836388111 CET777756686176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:30.836451054 CET566867777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:30.837074041 CET566867777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:30.841803074 CET777756686176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:30.841887951 CET566867777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:30.846602917 CET777756686176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:31.523809910 CET777756686176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:31.524032116 CET566867777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:31.524032116 CET566867777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:31.524599075 CET566887777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:31.529418945 CET777756688176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:31.529478073 CET566887777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:31.530141115 CET566887777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:31.534867048 CET777756688176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:31.534923077 CET566887777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:31.539655924 CET777756688176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:32.217199087 CET777756688176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:32.217426062 CET566887777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:32.217426062 CET566887777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:32.217818022 CET566907777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:32.222565889 CET777756690176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:32.222625971 CET566907777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:32.223242998 CET566907777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:32.227947950 CET777756690176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:32.227997065 CET566907777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:32.232665062 CET777756690176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:32.922682047 CET777756690176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:32.922961950 CET566907777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:32.922961950 CET566907777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:32.923409939 CET566927777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:32.928132057 CET777756692176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:32.928193092 CET566927777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:32.928788900 CET566927777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:32.933484077 CET777756692176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:32.933549881 CET566927777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:32.938203096 CET777756692176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:33.612196922 CET777756692176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:33.612390995 CET566927777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:33.612390995 CET566927777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:33.612812996 CET566947777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:33.617599010 CET777756694176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:33.617655993 CET566947777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:33.618302107 CET566947777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:33.623017073 CET777756694176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:33.623071909 CET566947777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:33.627870083 CET777756694176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:34.344254017 CET777756694176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:34.344444036 CET566947777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:34.344472885 CET566947777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:34.345000982 CET566967777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:34.349785089 CET777756696176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:34.349872112 CET566967777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:34.350647926 CET566967777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:34.355362892 CET777756696176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:34.355494976 CET566967777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:34.360212088 CET777756696176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:35.039397955 CET777756696176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:35.039845943 CET566967777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:35.039845943 CET566967777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:35.040656090 CET566987777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:35.045300961 CET777756698176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:35.045393944 CET566987777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:35.046350956 CET566987777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:35.051043987 CET777756698176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:35.051114082 CET566987777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:35.056952953 CET777756698176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:35.732856989 CET777756698176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:35.733071089 CET566987777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:35.733130932 CET566987777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:35.733722925 CET567007777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:35.738440990 CET777756700176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:35.738524914 CET567007777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:35.739250898 CET567007777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:35.743948936 CET777756700176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:35.744024038 CET567007777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:35.748953104 CET777756700176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:36.422403097 CET777756700176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:36.422676086 CET567007777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:36.422676086 CET567007777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:36.423216105 CET567027777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:36.428586960 CET777756702176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:36.428647041 CET567027777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:36.429450989 CET567027777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:36.435007095 CET777756702176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:36.435077906 CET567027777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:36.440237999 CET777756702176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:37.126564980 CET777756702176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:37.126820087 CET567027777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:37.126820087 CET567027777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:37.127492905 CET567047777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:37.132237911 CET777756704176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:37.132322073 CET567047777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:37.133133888 CET567047777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:37.137830973 CET777756704176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:37.137944937 CET567047777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:37.142630100 CET777756704176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:37.836920023 CET777756704176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:37.837191105 CET567047777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:37.837191105 CET567047777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:37.837702036 CET567067777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:37.842431068 CET777756706176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:37.842494011 CET567067777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:37.843297005 CET567067777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:37.847990036 CET777756706176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:37.848082066 CET567067777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:37.852823019 CET777756706176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:38.520953894 CET777756706176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:38.521121025 CET567067777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:38.521204948 CET567067777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:38.521823883 CET567087777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:38.526559114 CET777756708176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:38.526716948 CET567087777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:38.527424097 CET567087777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:38.532177925 CET777756708176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:38.532248020 CET567087777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:38.536993027 CET777756708176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:39.200551033 CET777756708176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:39.200793028 CET567087777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:39.200843096 CET567087777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:39.201405048 CET567107777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:39.206199884 CET777756710176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:39.206267118 CET567107777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:39.207061052 CET567107777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:39.211852074 CET777756710176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:39.211935043 CET567107777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:39.216672897 CET777756710176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:39.886960030 CET777756710176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:39.887203932 CET567107777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:39.887274981 CET567107777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:39.887875080 CET567127777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:39.892703056 CET777756712176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:39.892762899 CET567127777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:39.893685102 CET567127777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:39.898401022 CET777756712176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:39.898457050 CET567127777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:39.903151989 CET777756712176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:40.587949991 CET777756712176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:40.588191986 CET567127777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:40.588248014 CET567127777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:40.588829041 CET567147777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:40.593553066 CET777756714176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:40.593605042 CET567147777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:40.594492912 CET567147777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:40.599217892 CET777756714176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:40.599272966 CET567147777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:40.604029894 CET777756714176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:41.293287039 CET777756714176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:41.293416023 CET567147777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:41.293493032 CET567147777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:41.294013977 CET567167777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:41.298748970 CET777756716176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:41.298851013 CET567167777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:41.299837112 CET567167777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:41.304570913 CET777756716176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:41.304626942 CET567167777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:41.309324026 CET777756716176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:41.996133089 CET777756716176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:41.996257067 CET567167777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:41.996324062 CET567167777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:41.996782064 CET567187777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:42.001512051 CET777756718176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:42.001563072 CET567187777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:42.002166033 CET567187777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:42.007143974 CET777756718176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:42.007196903 CET567187777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:42.011959076 CET777756718176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:42.763951063 CET777756718176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:42.764103889 CET567187777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:42.764136076 CET567187777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:42.764585018 CET567207777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:42.770044088 CET777756720176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:42.770092010 CET567207777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:42.770855904 CET567207777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:42.775552034 CET777756720176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:42.775594950 CET567207777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:42.780299902 CET777756720176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:43.455048084 CET777756720176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:43.455204964 CET567207777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:43.455250025 CET567207777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:43.455661058 CET567227777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:43.460428953 CET777756722176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:43.460481882 CET567227777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:43.461190939 CET567227777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:43.465913057 CET777756722176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:43.465960026 CET567227777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:43.470680952 CET777756722176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:53.471371889 CET567227777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:38:53.476073980 CET777756722176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:53.683902979 CET777756722176.65.134.62192.168.2.14
                      Mar 12, 2025 02:38:53.684072018 CET567227777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:39:11.068897963 CET777756722176.65.134.62192.168.2.14
                      Mar 12, 2025 02:39:11.069169044 CET567227777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:40:01.113404036 CET567227777192.168.2.14176.65.134.62
                      Mar 12, 2025 02:40:01.118190050 CET777756722176.65.134.62192.168.2.14
                      Mar 12, 2025 02:40:01.326212883 CET777756722176.65.134.62192.168.2.14
                      Mar 12, 2025 02:40:01.326333046 CET567227777192.168.2.14176.65.134.62

                      System Behavior

                      Start time (UTC):01:38:22
                      Start date (UTC):12/03/2025
                      Path:/tmp/morte.sh4.elf
                      Arguments:/tmp/morte.sh4.elf
                      File size:4139976 bytes
                      MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                      Start time (UTC):01:38:22
                      Start date (UTC):12/03/2025
                      Path:/tmp/morte.sh4.elf
                      Arguments:-
                      File size:4139976 bytes
                      MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                      Start time (UTC):01:38:22
                      Start date (UTC):12/03/2025
                      Path:/tmp/morte.sh4.elf
                      Arguments:-
                      File size:4139976 bytes
                      MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                      Start time (UTC):01:39:10
                      Start date (UTC):12/03/2025
                      Path:/tmp/morte.sh4.elf
                      Arguments:-
                      File size:4139976 bytes
                      MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                      Start time (UTC):01:39:10
                      Start date (UTC):12/03/2025
                      Path:/tmp/morte.sh4.elf
                      Arguments:-
                      File size:4139976 bytes
                      MD5 hash:8943e5f8f8c280467b4472c15ae93ba9