Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
zmap.sh4.elf

Overview

General Information

Sample name:zmap.sh4.elf
Analysis ID:1580405
MD5:8efd8091d55d8b7099d49db979b7bfbb
SHA1:4f3c58baf9ec7cea6fc5598cd352563b0196fd59
SHA256:81268c14f3075a5546559bfa6f73e83cc796a94545836ef6f80197e1438490a4
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai, Okiru
Score:84
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Yara detected Okiru
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1580405
Start date and time:2024-12-24 13:27:06 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 31s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:zmap.sh4.elf
Detection:MAL
Classification:mal84.troj.evad.linELF@0/0@26/0
  • VT rate limit hit for: zmap.sh4.elf
Command:/tmp/zmap.sh4.elf
PID:6213
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
VagneRHere
Standard Error:
  • system is lnxubuntu20
  • zmap.sh4.elf (PID: 6213, Parent: 6130, MD5: 8943e5f8f8c280467b4472c15ae93ba9) Arguments: /tmp/zmap.sh4.elf
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
zmap.sh4.elfJoeSecurity_OkiruYara detected OkiruJoe Security
    zmap.sh4.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      zmap.sh4.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0xd548:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd55c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd570:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd584:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd598:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd5ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd5c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd5d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd5e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd5fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd610:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd624:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd638:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd64c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd660:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd674:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd688:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd69c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd6b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd6c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xd6d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      SourceRuleDescriptionAuthorStrings
      6217.1.00007f476c400000.00007f476c410000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
        6217.1.00007f476c400000.00007f476c410000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          6217.1.00007f476c400000.00007f476c410000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
          • 0xd548:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd55c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd570:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd584:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd598:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd5ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd5c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd5d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd5e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd5fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd610:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd624:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd638:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd64c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd660:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd674:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd688:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd69c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd6b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd6c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xd6d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          6213.1.00007f476c400000.00007f476c410000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
            6213.1.00007f476c400000.00007f476c410000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
              Click to see the 7 entries
              No Suricata rule has matched

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: zmap.sh4.elfAvira: detected
              Source: zmap.sh4.elfReversingLabs: Detection: 60%
              Source: global trafficTCP traffic: 192.168.2.23:39528 -> 185.196.8.105:59962
              Source: /tmp/zmap.sh4.elf (PID: 6213)Socket: 127.0.0.1:39148Jump to behavior
              Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
              Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
              Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
              Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
              Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
              Source: global trafficDNS traffic detected: DNS query: srvy.vlrt-gap.com
              Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

              System Summary

              barindex
              Source: zmap.sh4.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: 6217.1.00007f476c400000.00007f476c410000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: 6213.1.00007f476c400000.00007f476c410000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: Process Memory Space: zmap.sh4.elf PID: 6213, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: Process Memory Space: zmap.sh4.elf PID: 6217, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: ELF static info symbol of initial sample.symtab present: no
              Source: zmap.sh4.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: 6217.1.00007f476c400000.00007f476c410000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: 6213.1.00007f476c400000.00007f476c410000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: Process Memory Space: zmap.sh4.elf PID: 6213, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: Process Memory Space: zmap.sh4.elf PID: 6217, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: classification engineClassification label: mal84.troj.evad.linELF@0/0@26/0

              Hooking and other Techniques for Hiding and Protection

              barindex
              Source: /tmp/zmap.sh4.elf (PID: 6213)File: /tmp/zmap.sh4.elfJump to behavior
              Source: /tmp/zmap.sh4.elf (PID: 6213)Queries kernel information via 'uname': Jump to behavior
              Source: zmap.sh4.elf, 6213.1.00007ffdde258000.00007ffdde279000.rw-.sdmp, zmap.sh4.elf, 6217.1.00007ffdde258000.00007ffdde279000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-sh4/tmp/zmap.sh4.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/zmap.sh4.elf
              Source: zmap.sh4.elf, 6213.1.00007ffdde258000.00007ffdde279000.rw-.sdmp, zmap.sh4.elf, 6217.1.00007ffdde258000.00007ffdde279000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sh4
              Source: zmap.sh4.elf, 6213.1.00005611f98ae000.00005611f9911000.rw-.sdmp, zmap.sh4.elf, 6217.1.00005611f98ae000.00005611f9911000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sh4
              Source: zmap.sh4.elf, 6213.1.00005611f98ae000.00005611f9911000.rw-.sdmp, zmap.sh4.elf, 6217.1.00005611f98ae000.00005611f9911000.rw-.sdmpBinary or memory string: V5!/etc/qemu-binfmt/sh4

              Stealing of Sensitive Information

              barindex
              Source: Yara matchFile source: zmap.sh4.elf, type: SAMPLE
              Source: Yara matchFile source: 6217.1.00007f476c400000.00007f476c410000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 6213.1.00007f476c400000.00007f476c410000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: zmap.sh4.elf PID: 6213, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: zmap.sh4.elf PID: 6217, type: MEMORYSTR
              Source: Yara matchFile source: zmap.sh4.elf, type: SAMPLE
              Source: Yara matchFile source: 6217.1.00007f476c400000.00007f476c410000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 6213.1.00007f476c400000.00007f476c410000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: zmap.sh4.elf PID: 6213, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: zmap.sh4.elf PID: 6217, type: MEMORYSTR

              Remote Access Functionality

              barindex
              Source: Yara matchFile source: zmap.sh4.elf, type: SAMPLE
              Source: Yara matchFile source: 6217.1.00007f476c400000.00007f476c410000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 6213.1.00007f476c400000.00007f476c410000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: zmap.sh4.elf PID: 6213, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: zmap.sh4.elf PID: 6217, type: MEMORYSTR
              Source: Yara matchFile source: zmap.sh4.elf, type: SAMPLE
              Source: Yara matchFile source: 6217.1.00007f476c400000.00007f476c410000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 6213.1.00007f476c400000.00007f476c410000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: zmap.sh4.elf PID: 6213, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: zmap.sh4.elf PID: 6217, type: MEMORYSTR
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
              File Deletion
              OS Credential Dumping11
              Security Software Discovery
              Remote ServicesData from Local System1
              Encrypted Channel
              Exfiltration Over Other Network MediumAbuse Accessibility Features
              CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
              Non-Standard Port
              Exfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
              Non-Application Layer Protocol
              Automated ExfiltrationData Encrypted for Impact
              Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
              Application Layer Protocol
              Traffic DuplicationData Destruction
              No configs have been found
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Number of created Files
              • Is malicious
              • Internet

              This section contains all screenshots as thumbnails, including those not shown in the slideshow.


              windows-stand
              SourceDetectionScannerLabelLink
              zmap.sh4.elf61%ReversingLabsLinux.Trojan.Mirai
              zmap.sh4.elf100%AviraEXP/ELF.Mirai.Z.A
              No Antivirus matches
              No Antivirus matches
              No Antivirus matches
              NameIPActiveMaliciousAntivirus DetectionReputation
              srvy.vlrt-gap.com
              185.196.8.105
              truefalse
                high
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                185.196.8.105
                srvy.vlrt-gap.comSwitzerland
                34888SIMPLECARRER2ITfalse
                109.202.202.202
                unknownSwitzerland
                13030INIT7CHfalse
                91.189.91.43
                unknownUnited Kingdom
                41231CANONICAL-ASGBfalse
                91.189.91.42
                unknownUnited Kingdom
                41231CANONICAL-ASGBfalse
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                185.196.8.105zmap.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                  zmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                    zmap.x86.elfGet hashmaliciousOkiruBrowse
                      zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                        109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                        • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                        91.189.91.43x86.elfGet hashmaliciousUnknownBrowse
                          zmap.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                            zmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                              zmap.x86.elfGet hashmaliciousOkiruBrowse
                                zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                  most-m68k.elfGet hashmaliciousUnknownBrowse
                                    arm7.elfGet hashmaliciousUnknownBrowse
                                      x86_64.nn.elfGet hashmaliciousOkiruBrowse
                                        nshppc.elfGet hashmaliciousUnknownBrowse
                                          nshsh4.elfGet hashmaliciousUnknownBrowse
                                            91.189.91.42x86.elfGet hashmaliciousUnknownBrowse
                                              zmap.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                                zmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                                                  zmap.x86.elfGet hashmaliciousOkiruBrowse
                                                    zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                                      most-m68k.elfGet hashmaliciousUnknownBrowse
                                                        arm7.elfGet hashmaliciousUnknownBrowse
                                                          x86_64.nn.elfGet hashmaliciousOkiruBrowse
                                                            nshppc.elfGet hashmaliciousUnknownBrowse
                                                              nshsh4.elfGet hashmaliciousUnknownBrowse
                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                srvy.vlrt-gap.comzmap.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                                                • 185.196.8.105
                                                                zmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                                                                • 185.196.8.105
                                                                zmap.x86.elfGet hashmaliciousOkiruBrowse
                                                                • 185.196.8.105
                                                                zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                                                • 185.196.8.105
                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                CANONICAL-ASGBx86.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                zmap.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                                                • 91.189.91.42
                                                                zmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                                                                • 91.189.91.42
                                                                zmap.x86.elfGet hashmaliciousOkiruBrowse
                                                                • 91.189.91.42
                                                                zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                                                • 91.189.91.42
                                                                most-m68k.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                arm7.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                x86_64.nn.elfGet hashmaliciousOkiruBrowse
                                                                • 91.189.91.42
                                                                nshppc.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                nshsh4.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                CANONICAL-ASGBx86.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                zmap.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                                                • 91.189.91.42
                                                                zmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                                                                • 91.189.91.42
                                                                zmap.x86.elfGet hashmaliciousOkiruBrowse
                                                                • 91.189.91.42
                                                                zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                                                • 91.189.91.42
                                                                most-m68k.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                arm7.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                x86_64.nn.elfGet hashmaliciousOkiruBrowse
                                                                • 91.189.91.42
                                                                nshppc.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                nshsh4.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                SIMPLECARRER2ITzmap.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                                                • 185.196.8.105
                                                                zmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                                                                • 185.196.8.105
                                                                zmap.x86.elfGet hashmaliciousOkiruBrowse
                                                                • 185.196.8.105
                                                                zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                                                • 185.196.8.105
                                                                DQmU06kq9I.exeGet hashmaliciousLiteHTTP BotBrowse
                                                                • 185.208.159.109
                                                                file.exeGet hashmaliciousLummaC, Amadey, Credential Flusher, LiteHTTP Bot, LummaC Stealer, Stealc, XmrigBrowse
                                                                • 185.208.159.109
                                                                file.exeGet hashmaliciousScreenConnect Tool, Amadey, RHADAMANTHYS, XWorm, XmrigBrowse
                                                                • 185.196.8.237
                                                                file.exeGet hashmaliciousAsyncRAT, VenomRATBrowse
                                                                • 185.208.158.187
                                                                Ziraat Bankasi Swift Mesaji.dqy.dllGet hashmaliciousAsyncRAT, VenomRATBrowse
                                                                • 185.208.158.187
                                                                file.exeGet hashmaliciousAsyncRAT, VenomRATBrowse
                                                                • 185.208.158.187
                                                                INIT7CHx86.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                zmap.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                                                • 109.202.202.202
                                                                zmap.spc.elfGet hashmaliciousMirai, OkiruBrowse
                                                                • 109.202.202.202
                                                                zmap.x86.elfGet hashmaliciousOkiruBrowse
                                                                • 109.202.202.202
                                                                zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                                                • 109.202.202.202
                                                                most-m68k.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                arm7.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                x86_64.nn.elfGet hashmaliciousOkiruBrowse
                                                                • 109.202.202.202
                                                                nshppc.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                nshsh4.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                No context
                                                                No context
                                                                No created / dropped files found
                                                                File type:ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
                                                                Entropy (8bit):6.906665833064167
                                                                TrID:
                                                                • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                File name:zmap.sh4.elf
                                                                File size:64'312 bytes
                                                                MD5:8efd8091d55d8b7099d49db979b7bfbb
                                                                SHA1:4f3c58baf9ec7cea6fc5598cd352563b0196fd59
                                                                SHA256:81268c14f3075a5546559bfa6f73e83cc796a94545836ef6f80197e1438490a4
                                                                SHA512:fc0925e81c612b0b47b7dca9f842ca04366598e8fd229992a87ee8afcf0ab53e3cb5bb4725c1c69d1df697af040fed06e5226b935e7722a702c67ed7cb16585f
                                                                SSDEEP:1536:qR2xNYObAIC9s/mRD2+y2FXLll/x9eKeNt7vKdkCZ76Fx:qRgC8AIC9s/mRD2+y2FXxlZ/erKdklFx
                                                                TLSH:89539D76E4262984C5860834B0B88E741FA3B1C0935B6EFB19DDC6B5604BEBCF449FE4
                                                                File Content Preview:.ELF..............*.......@.4...........4. ...(...............@...@...........................A...A......'..........Q.td............................././"O.n........#.*@........#.*@,....o&O.n...l..............................././.../.a"O.!...n...a.b("...q.

                                                                ELF header

                                                                Class:ELF32
                                                                Data:2's complement, little endian
                                                                Version:1 (current)
                                                                Machine:<unknown>
                                                                Version Number:0x1
                                                                Type:EXEC (Executable file)
                                                                OS/ABI:UNIX - System V
                                                                ABI Version:0
                                                                Entry Point Address:0x4001a0
                                                                Flags:0x9
                                                                ELF Header Size:52
                                                                Program Header Offset:52
                                                                Program Header Size:32
                                                                Number of Program Headers:3
                                                                Section Header Offset:63912
                                                                Section Header Size:40
                                                                Number of Section Headers:10
                                                                Header String Table Index:9
                                                                NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                NULL0x00x00x00x00x0000
                                                                .initPROGBITS0x4000940x940x300x00x6AX004
                                                                .textPROGBITS0x4000e00xe00xd4400x00x6AX0032
                                                                .finiPROGBITS0x40d5200xd5200x240x00x6AX004
                                                                .rodataPROGBITS0x40d5440xd5440x20800x00x2A004
                                                                .ctorsPROGBITS0x41f5c80xf5c80x80x00x3WA004
                                                                .dtorsPROGBITS0x41f5d00xf5d00x80x00x3WA004
                                                                .dataPROGBITS0x41f5dc0xf5dc0x38c0x00x3WA004
                                                                .bssNOBITS0x41f9680xf9680x24300x00x3WA004
                                                                .shstrtabSTRTAB0x00xf9680x3e0x00x0001
                                                                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                LOAD0x00x4000000x4000000xf5c40xf5c46.95350x5R E0x10000.init .text .fini .rodata
                                                                LOAD0xf5c80x41f5c80x41f5c80x3a00x27d03.12220x6RW 0x10000.ctors .dtors .data .bss
                                                                GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                                TimestampSource PortDest PortSource IPDest IP
                                                                Dec 24, 2024 13:27:45.674694061 CET43928443192.168.2.2391.189.91.42
                                                                Dec 24, 2024 13:27:46.271955967 CET3952859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:46.391504049 CET5996239528185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:46.392021894 CET3952859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:46.392916918 CET3952859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:46.512458086 CET5996239528185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:46.512640953 CET3952859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:46.632103920 CET5996239528185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:47.691318035 CET5996239528185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:47.691450119 CET3952859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:47.691616058 CET3952859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:48.054272890 CET3953059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:48.173979044 CET5996239530185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:48.174069881 CET3953059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:48.174925089 CET3953059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:48.294399977 CET5996239530185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:48.294524908 CET3953059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:48.414053917 CET5996239530185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:49.469697952 CET5996239530185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:49.469808102 CET3953059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:49.469953060 CET3953059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:49.605670929 CET3953259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:49.725131989 CET5996239532185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:49.725231886 CET3953259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:49.726308107 CET3953259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:49.845783949 CET5996239532185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:49.845886946 CET3953259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:49.965481997 CET5996239532185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:51.029416084 CET5996239532185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:51.029690027 CET3953259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:51.029721022 CET3953259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:51.165620089 CET3953459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:51.285200119 CET5996239534185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:51.285321951 CET3953459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:51.286386013 CET3953459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:51.306010008 CET42836443192.168.2.2391.189.91.43
                                                                Dec 24, 2024 13:27:51.405862093 CET5996239534185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:51.406054020 CET3953459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:51.525624037 CET5996239534185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:52.590221882 CET5996239534185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:52.590478897 CET3953459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:52.590596914 CET3953459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:52.726825953 CET3953659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:52.841730118 CET4251680192.168.2.23109.202.202.202
                                                                Dec 24, 2024 13:27:52.847893953 CET5996239536185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:52.848174095 CET3953659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:52.849525928 CET3953659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:52.969335079 CET5996239536185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:52.969650984 CET3953659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:53.089669943 CET5996239536185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:54.153621912 CET5996239536185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:54.153847933 CET3953659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:54.153908014 CET3953659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:54.517214060 CET3953859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:54.636663914 CET5996239538185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:54.636791945 CET3953859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:54.637841940 CET3953859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:54.757391930 CET5996239538185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:54.757541895 CET3953859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:54.877022982 CET5996239538185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:55.936044931 CET5996239538185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:55.936472893 CET3953859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:55.936472893 CET3953859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:56.296094894 CET3954059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:56.415651083 CET5996239540185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:56.415790081 CET3954059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:56.416876078 CET3954059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:56.536318064 CET5996239540185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:56.536436081 CET3954059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:56.655999899 CET5996239540185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:57.824654102 CET5996239540185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:57.825010061 CET3954059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:57.825128078 CET3954059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:58.184809923 CET3954259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:58.304434061 CET5996239542185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:58.304580927 CET3954259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:58.305938959 CET3954259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:58.434920073 CET5996239542185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:58.435187101 CET3954259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:58.554744005 CET5996239542185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:59.605238914 CET5996239542185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:59.605390072 CET3954259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:59.605664015 CET3954259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:59.742299080 CET3954459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:59.861836910 CET5996239544185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:59.862134933 CET3954459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:59.863483906 CET3954459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:27:59.983026028 CET5996239544185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:27:59.983294964 CET3954459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:00.102840900 CET5996239544185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:01.175587893 CET5996239544185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:01.175896883 CET3954459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:01.175987005 CET3954459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:01.540935993 CET3954659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:01.660542965 CET5996239546185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:01.660840034 CET3954659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:01.662643909 CET3954659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:01.782263041 CET5996239546185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:01.782394886 CET3954659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:01.902101994 CET5996239546185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:02.973190069 CET5996239546185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:02.973299980 CET3954659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:02.973366976 CET3954659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:03.110219955 CET3954859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:03.229757071 CET5996239548185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:03.229918957 CET3954859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:03.230901957 CET3954859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:03.350436926 CET5996239548185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:03.350498915 CET3954859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:03.470654011 CET5996239548185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:04.535669088 CET5996239548185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:04.535836935 CET3954859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:04.535914898 CET3954859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:04.673825979 CET3955059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:04.796077013 CET5996239550185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:04.796190977 CET3955059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:04.797429085 CET3955059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:04.917721033 CET5996239550185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:04.917872906 CET3955059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:05.037676096 CET5996239550185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:05.896039009 CET43928443192.168.2.2391.189.91.42
                                                                Dec 24, 2024 13:28:06.097996950 CET5996239550185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:06.098175049 CET3955059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:06.098244905 CET3955059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:06.462227106 CET3955259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:06.581758022 CET5996239552185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:06.581887007 CET3955259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:06.582868099 CET3955259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:06.702301025 CET5996239552185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:06.702435017 CET3955259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:06.821927071 CET5996239552185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:07.879407883 CET5996239552185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:07.879539967 CET3955259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:07.879564047 CET3955259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:08.003545046 CET3955459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:08.123321056 CET5996239554185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:08.123466969 CET3955459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:08.124716997 CET3955459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:08.244168997 CET5996239554185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:08.244498968 CET3955459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:08.364012003 CET5996239554185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:09.422003984 CET5996239554185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:09.422316074 CET3955459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:09.422414064 CET3955459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:09.559231997 CET3955659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:09.678833008 CET5996239556185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:09.679132938 CET3955659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:09.680310011 CET3955659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:09.799791098 CET5996239556185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:09.799922943 CET3955659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:09.919429064 CET5996239556185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:10.980204105 CET5996239556185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:10.980401993 CET3955659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:10.980523109 CET3955659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:11.104710102 CET3955859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:11.224303007 CET5996239558185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:11.224610090 CET3955859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:11.225812912 CET3955859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:11.345319986 CET5996239558185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:11.345443010 CET3955859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:11.464993000 CET5996239558185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:12.538827896 CET5996239558185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:12.539006948 CET3955859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:12.539098024 CET3955859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:12.675636053 CET3956059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:12.795490980 CET5996239560185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:12.795806885 CET3956059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:12.797394037 CET3956059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:12.917053938 CET5996239560185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:12.917300940 CET3956059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:13.036880016 CET5996239560185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:14.110086918 CET5996239560185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:14.110177994 CET3956059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:14.110343933 CET3956059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:14.246717930 CET3956259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:14.366319895 CET5996239562185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:14.366492033 CET3956259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:14.368043900 CET3956259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:14.487571955 CET5996239562185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:14.487657070 CET3956259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:14.607217073 CET5996239562185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:15.680495977 CET5996239562185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:15.680798054 CET3956259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:15.680896997 CET3956259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:15.816973925 CET3956459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:15.936491966 CET5996239564185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:15.936640978 CET3956459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:15.937866926 CET3956459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:16.059041977 CET5996239564185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:16.059303045 CET3956459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:16.178862095 CET5996239564185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:18.182393074 CET42836443192.168.2.2391.189.91.43
                                                                Dec 24, 2024 13:28:22.277769089 CET4251680192.168.2.23109.202.202.202
                                                                Dec 24, 2024 13:28:25.946743965 CET3956459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:26.066442013 CET5996239564185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:26.353022099 CET5996239564185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:26.353184938 CET3956459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:26.353239059 CET3956459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:26.472893953 CET5996239564185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:27.492702961 CET3956659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:27.612207890 CET5996239566185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:27.612385035 CET3956659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:27.613935947 CET3956659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:27.733515024 CET5996239566185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:27.733655930 CET3956659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:27.853238106 CET5996239566185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:28.684828043 CET5996239566185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:28.685256958 CET3956659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:28.804968119 CET5996239566185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:29.822549105 CET3956859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:29.942150116 CET5996239568185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:29.942262888 CET3956859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:29.943850994 CET3956859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:30.063420057 CET5996239568185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:30.063553095 CET3956859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:30.183007956 CET5996239568185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:31.297925949 CET5996239568185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:31.298172951 CET3956859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:31.298389912 CET3956859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:31.424206018 CET3957059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:31.543834925 CET5996239570185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:31.544002056 CET3957059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:31.545095921 CET3957059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:31.664581060 CET5996239570185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:31.664644957 CET3957059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:31.784168005 CET5996239570185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:32.869618893 CET5996239570185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:32.870033026 CET3957059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:32.870033026 CET3957059962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:33.005665064 CET3957259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:33.125200987 CET5996239572185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:33.125437975 CET3957259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:33.126312017 CET3957259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:33.245850086 CET5996239572185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:33.246033907 CET3957259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:33.365564108 CET5996239572185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:34.436722994 CET5996239572185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:34.436990023 CET3957259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:34.436990976 CET3957259962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:34.561625957 CET3957459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:34.681185007 CET5996239574185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:34.681298971 CET3957459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:34.682380915 CET3957459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:34.801958084 CET5996239574185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:34.802215099 CET3957459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:34.921740055 CET5996239574185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:35.986563921 CET5996239574185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:35.986856937 CET3957459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:35.986884117 CET3957459962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:36.123001099 CET3957659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:36.242655039 CET5996239576185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:36.242832899 CET3957659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:36.244060993 CET3957659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:36.363678932 CET5996239576185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:36.364037991 CET3957659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:36.483715057 CET5996239576185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:37.552393913 CET5996239576185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:37.552525997 CET3957659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:37.552614927 CET3957659962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:37.688695908 CET3957859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:37.808295012 CET5996239578185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:37.808466911 CET3957859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:37.809559107 CET3957859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:37.929155111 CET5996239578185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:37.929306984 CET3957859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:28:38.049010038 CET5996239578185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:28:46.850454092 CET43928443192.168.2.2391.189.91.42
                                                                Dec 24, 2024 13:29:37.847863913 CET3957859962192.168.2.23185.196.8.105
                                                                Dec 24, 2024 13:29:37.967674971 CET5996239578185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:29:38.267853022 CET5996239578185.196.8.105192.168.2.23
                                                                Dec 24, 2024 13:29:38.268178940 CET3957859962192.168.2.23185.196.8.105
                                                                TimestampSource PortDest PortSource IPDest IP
                                                                Dec 24, 2024 13:27:45.911016941 CET4275553192.168.2.238.8.8.8
                                                                Dec 24, 2024 13:27:46.270858049 CET53427558.8.8.8192.168.2.23
                                                                Dec 24, 2024 13:27:47.692979097 CET4893953192.168.2.238.8.8.8
                                                                Dec 24, 2024 13:27:48.053771973 CET53489398.8.8.8192.168.2.23
                                                                Dec 24, 2024 13:27:49.470963955 CET4121353192.168.2.238.8.8.8
                                                                Dec 24, 2024 13:27:49.605051041 CET53412138.8.8.8192.168.2.23
                                                                Dec 24, 2024 13:27:51.030754089 CET4300553192.168.2.238.8.8.8
                                                                Dec 24, 2024 13:27:51.164967060 CET53430058.8.8.8192.168.2.23
                                                                Dec 24, 2024 13:27:52.591979027 CET4682253192.168.2.238.8.8.8
                                                                Dec 24, 2024 13:27:52.725830078 CET53468228.8.8.8192.168.2.23
                                                                Dec 24, 2024 13:27:54.154926062 CET4429653192.168.2.238.8.8.8
                                                                Dec 24, 2024 13:27:54.516367912 CET53442968.8.8.8192.168.2.23
                                                                Dec 24, 2024 13:27:55.937473059 CET4653253192.168.2.238.8.8.8
                                                                Dec 24, 2024 13:27:56.295211077 CET53465328.8.8.8192.168.2.23
                                                                Dec 24, 2024 13:27:57.826309919 CET3668253192.168.2.238.8.8.8
                                                                Dec 24, 2024 13:27:58.183718920 CET53366828.8.8.8192.168.2.23
                                                                Dec 24, 2024 13:27:59.607044935 CET4959453192.168.2.238.8.8.8
                                                                Dec 24, 2024 13:27:59.741419077 CET53495948.8.8.8192.168.2.23
                                                                Dec 24, 2024 13:28:01.177419901 CET5454753192.168.2.238.8.8.8
                                                                Dec 24, 2024 13:28:01.540015936 CET53545478.8.8.8192.168.2.23
                                                                Dec 24, 2024 13:28:02.974261045 CET4701053192.168.2.238.8.8.8
                                                                Dec 24, 2024 13:28:03.109246969 CET53470108.8.8.8192.168.2.23
                                                                Dec 24, 2024 13:28:04.537254095 CET3321653192.168.2.238.8.8.8
                                                                Dec 24, 2024 13:28:04.672951937 CET53332168.8.8.8192.168.2.23
                                                                Dec 24, 2024 13:28:06.099613905 CET6013353192.168.2.238.8.8.8
                                                                Dec 24, 2024 13:28:06.461330891 CET53601338.8.8.8192.168.2.23
                                                                Dec 24, 2024 13:28:07.880471945 CET6007953192.168.2.238.8.8.8
                                                                Dec 24, 2024 13:28:08.002921104 CET53600798.8.8.8192.168.2.23
                                                                Dec 24, 2024 13:28:09.423852921 CET3913253192.168.2.238.8.8.8
                                                                Dec 24, 2024 13:28:09.558698893 CET53391328.8.8.8192.168.2.23
                                                                Dec 24, 2024 13:28:10.981646061 CET4241553192.168.2.238.8.8.8
                                                                Dec 24, 2024 13:28:11.103919983 CET53424158.8.8.8192.168.2.23
                                                                Dec 24, 2024 13:28:12.540235043 CET5973453192.168.2.238.8.8.8
                                                                Dec 24, 2024 13:28:12.674623966 CET53597348.8.8.8192.168.2.23
                                                                Dec 24, 2024 13:28:14.111695051 CET4613653192.168.2.238.8.8.8
                                                                Dec 24, 2024 13:28:14.245599985 CET53461368.8.8.8192.168.2.23
                                                                Dec 24, 2024 13:28:15.682090998 CET5988553192.168.2.238.8.8.8
                                                                Dec 24, 2024 13:28:15.815918922 CET53598858.8.8.8192.168.2.23
                                                                Dec 24, 2024 13:28:27.357248068 CET5858553192.168.2.238.8.8.8
                                                                Dec 24, 2024 13:28:27.491447926 CET53585858.8.8.8192.168.2.23
                                                                Dec 24, 2024 13:28:29.687598944 CET3563753192.168.2.238.8.8.8
                                                                Dec 24, 2024 13:28:29.821445942 CET53356378.8.8.8192.168.2.23
                                                                Dec 24, 2024 13:28:31.299705029 CET4959553192.168.2.238.8.8.8
                                                                Dec 24, 2024 13:28:31.423237085 CET53495958.8.8.8192.168.2.23
                                                                Dec 24, 2024 13:28:32.871118069 CET5899253192.168.2.238.8.8.8
                                                                Dec 24, 2024 13:28:33.004808903 CET53589928.8.8.8192.168.2.23
                                                                Dec 24, 2024 13:28:34.438359022 CET5450253192.168.2.238.8.8.8
                                                                Dec 24, 2024 13:28:34.560714006 CET53545028.8.8.8192.168.2.23
                                                                Dec 24, 2024 13:28:35.988130093 CET5799553192.168.2.238.8.8.8
                                                                Dec 24, 2024 13:28:36.122106075 CET53579958.8.8.8192.168.2.23
                                                                Dec 24, 2024 13:28:37.553371906 CET4901953192.168.2.238.8.8.8
                                                                Dec 24, 2024 13:28:37.688033104 CET53490198.8.8.8192.168.2.23
                                                                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                Dec 24, 2024 13:27:45.911016941 CET192.168.2.238.8.8.80x2fa7Standard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:27:47.692979097 CET192.168.2.238.8.8.80xcdc6Standard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:27:49.470963955 CET192.168.2.238.8.8.80x28c0Standard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:27:51.030754089 CET192.168.2.238.8.8.80x9c60Standard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:27:52.591979027 CET192.168.2.238.8.8.80x3e17Standard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:27:54.154926062 CET192.168.2.238.8.8.80xc7a3Standard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:27:55.937473059 CET192.168.2.238.8.8.80x60beStandard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:27:57.826309919 CET192.168.2.238.8.8.80xdaa5Standard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:27:59.607044935 CET192.168.2.238.8.8.80x891bStandard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:01.177419901 CET192.168.2.238.8.8.80x40a4Standard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:02.974261045 CET192.168.2.238.8.8.80xf80aStandard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:04.537254095 CET192.168.2.238.8.8.80x778eStandard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:06.099613905 CET192.168.2.238.8.8.80x77e7Standard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:07.880471945 CET192.168.2.238.8.8.80x65beStandard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:09.423852921 CET192.168.2.238.8.8.80x2c0dStandard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:10.981646061 CET192.168.2.238.8.8.80x7113Standard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:12.540235043 CET192.168.2.238.8.8.80x68e3Standard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:14.111695051 CET192.168.2.238.8.8.80x2849Standard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:15.682090998 CET192.168.2.238.8.8.80xac52Standard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:27.357248068 CET192.168.2.238.8.8.80xf7d9Standard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:29.687598944 CET192.168.2.238.8.8.80x4ef3Standard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:31.299705029 CET192.168.2.238.8.8.80x28fcStandard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:32.871118069 CET192.168.2.238.8.8.80x735aStandard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:34.438359022 CET192.168.2.238.8.8.80x536bStandard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:35.988130093 CET192.168.2.238.8.8.80x7db0Standard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:37.553371906 CET192.168.2.238.8.8.80x3988Standard query (0)srvy.vlrt-gap.comA (IP address)IN (0x0001)false
                                                                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                Dec 24, 2024 13:27:46.270858049 CET8.8.8.8192.168.2.230x2fa7No error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:27:48.053771973 CET8.8.8.8192.168.2.230xcdc6No error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:27:49.605051041 CET8.8.8.8192.168.2.230x28c0No error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:27:51.164967060 CET8.8.8.8192.168.2.230x9c60No error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:27:52.725830078 CET8.8.8.8192.168.2.230x3e17No error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:27:54.516367912 CET8.8.8.8192.168.2.230xc7a3No error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:27:56.295211077 CET8.8.8.8192.168.2.230x60beNo error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:27:58.183718920 CET8.8.8.8192.168.2.230xdaa5No error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:27:59.741419077 CET8.8.8.8192.168.2.230x891bNo error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:01.540015936 CET8.8.8.8192.168.2.230x40a4No error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:03.109246969 CET8.8.8.8192.168.2.230xf80aNo error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:04.672951937 CET8.8.8.8192.168.2.230x778eNo error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:06.461330891 CET8.8.8.8192.168.2.230x77e7No error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:08.002921104 CET8.8.8.8192.168.2.230x65beNo error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:09.558698893 CET8.8.8.8192.168.2.230x2c0dNo error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:11.103919983 CET8.8.8.8192.168.2.230x7113No error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:12.674623966 CET8.8.8.8192.168.2.230x68e3No error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:14.245599985 CET8.8.8.8192.168.2.230x2849No error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:15.815918922 CET8.8.8.8192.168.2.230xac52No error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:27.491447926 CET8.8.8.8192.168.2.230xf7d9No error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:29.821445942 CET8.8.8.8192.168.2.230x4ef3No error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:31.423237085 CET8.8.8.8192.168.2.230x28fcNo error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:33.004808903 CET8.8.8.8192.168.2.230x735aNo error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:34.560714006 CET8.8.8.8192.168.2.230x536bNo error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:36.122106075 CET8.8.8.8192.168.2.230x7db0No error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false
                                                                Dec 24, 2024 13:28:37.688033104 CET8.8.8.8192.168.2.230x3988No error (0)srvy.vlrt-gap.com185.196.8.105A (IP address)IN (0x0001)false

                                                                System Behavior

                                                                Start time (UTC):12:27:44
                                                                Start date (UTC):24/12/2024
                                                                Path:/tmp/zmap.sh4.elf
                                                                Arguments:/tmp/zmap.sh4.elf
                                                                File size:4139976 bytes
                                                                MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                                                Start time (UTC):12:27:44
                                                                Start date (UTC):24/12/2024
                                                                Path:/tmp/zmap.sh4.elf
                                                                Arguments:-
                                                                File size:4139976 bytes
                                                                MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                                                Start time (UTC):12:27:44
                                                                Start date (UTC):24/12/2024
                                                                Path:/tmp/zmap.sh4.elf
                                                                Arguments:-
                                                                File size:4139976 bytes
                                                                MD5 hash:8943e5f8f8c280467b4472c15ae93ba9