Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
Aqua.arm4.elf

Overview

General Information

Sample name:Aqua.arm4.elf
Analysis ID:1581787
MD5:69039bfe2718fb4235b4d6f54a364ad1
SHA1:60bce12363986fe5e5bad07edf575ff7ea6583a7
SHA256:80798a1196b63f9c18ffb84719cbb0506a3d24e735e4a3f205ae5d1450e8d14b
Tags:elfuser-abuse_ch
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Sample deletes itself
Sends malformed DNS queries
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1581787
Start date and time:2024-12-29 00:09:39 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 37s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Aqua.arm4.elf
Detection:MAL
Classification:mal64.troj.evad.linELF@0/1@56/0
  • VT rate limit hit for: Aqua.arm4.elf
Command:/tmp/Aqua.arm4.elf
PID:5597
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
about to cum inside a femboy btw
Standard Error:
  • system is lnxubuntu20
  • Aqua.arm4.elf (PID: 5597, Parent: 5521, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/Aqua.arm4.elf
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Aqua.arm4.elfAvira: detected
Source: Aqua.arm4.elfReversingLabs: Detection: 43%

Networking

barindex
Source: global trafficDNS traffic detected: malformed DNS query: raw.intenseapi.com. [malformed]
Source: global trafficTCP traffic: 192.168.2.15:41346 -> 193.200.78.37:33966
Source: global trafficDNS traffic detected: DNS query: raw.intenseapi.com
Source: global trafficDNS traffic detected: DNS query: raw.intenseapi.com. [malformed]
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal64.troj.evad.linELF@0/1@56/0

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/Aqua.arm4.elf (PID: 5599)File: /tmp/Aqua.arm4.elfJump to behavior
Source: /tmp/Aqua.arm4.elf (PID: 5597)Queries kernel information via 'uname': Jump to behavior
Source: Aqua.arm4.elf, 5597.1.00007ffcc8f04000.00007ffcc8f25000.rw-.sdmpBinary or memory string: /tmp/qemu-open.5frjnq
Source: Aqua.arm4.elf, 5597.1.00007ffcc8f04000.00007ffcc8f25000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/Aqua.arm4.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Aqua.arm4.elf
Source: Aqua.arm4.elf, 5597.1.0000561cae608000.0000561cae736000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: Aqua.arm4.elf, 5597.1.0000561cae608000.0000561cae736000.rw-.sdmpBinary or memory string: V!/etc/qemu-binfmt/arm
Source: Aqua.arm4.elf, 5597.1.00007ffcc8f04000.00007ffcc8f25000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: Aqua.arm4.elf, 5597.1.00007ffcc8f04000.00007ffcc8f25000.rw-.sdmpBinary or memory string: V/tmp/qemu-open.5frjnq:
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
SourceDetectionScannerLabelLink
Aqua.arm4.elf43%ReversingLabsLinux.Backdoor.Mirai
Aqua.arm4.elf100%AviraEXP/ELF.Mirai.W
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
raw.intenseapi.com
193.200.78.37
truefalse
    high
    raw.intenseapi.com. [malformed]
    unknown
    unknowntrue
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      193.200.78.37
      raw.intenseapi.comSwitzerland
      29496LINK-SERVICE-ASUAfalse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      193.200.78.37Aqua.dbg.elfGet hashmaliciousUnknownBrowse
        Aqua.m68k.elfGet hashmaliciousUnknownBrowse
          Aqua.m68k.elfGet hashmaliciousUnknownBrowse
            Aqua.sh4.elfGet hashmaliciousUnknownBrowse
              Aqua.spc.elfGet hashmaliciousUnknownBrowse
                Aqua.x86_64.elfGet hashmaliciousUnknownBrowse
                  Aqua.mips.elfGet hashmaliciousUnknownBrowse
                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                    raw.intenseapi.comAqua.dbg.elfGet hashmaliciousUnknownBrowse
                    • 193.200.78.37
                    Aqua.spc.elfGet hashmaliciousUnknownBrowse
                    • 193.200.78.37
                    Aqua.x86_64.elfGet hashmaliciousUnknownBrowse
                    • 193.200.78.37
                    Aqua.mips.elfGet hashmaliciousUnknownBrowse
                    • 193.200.78.37
                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                    LINK-SERVICE-ASUAAqua.dbg.elfGet hashmaliciousUnknownBrowse
                    • 193.200.78.37
                    Aqua.m68k.elfGet hashmaliciousUnknownBrowse
                    • 193.200.78.37
                    Aqua.m68k.elfGet hashmaliciousUnknownBrowse
                    • 193.200.78.37
                    Aqua.sh4.elfGet hashmaliciousUnknownBrowse
                    • 193.200.78.37
                    Aqua.spc.elfGet hashmaliciousUnknownBrowse
                    • 193.200.78.37
                    Aqua.x86_64.elfGet hashmaliciousUnknownBrowse
                    • 193.200.78.37
                    Aqua.mips.elfGet hashmaliciousUnknownBrowse
                    • 193.200.78.37
                    KCmfLMBjHJ.elfGet hashmaliciousUnknownBrowse
                    • 193.200.79.115
                    assailant.i586Get hashmaliciousMiraiBrowse
                    • 194.146.110.216
                    9CSfviwl3lGet hashmaliciousMiraiBrowse
                    • 193.200.79.137
                    No context
                    No context
                    Process:/tmp/Aqua.arm4.elf
                    File Type:data
                    Category:dropped
                    Size (bytes):29
                    Entropy (8bit):4.1162646156680225
                    Encrypted:false
                    SSDEEP:3:Tg10J5oHJN:Tg10J5aJN
                    MD5:A112D952263191E835214AE26416ABBC
                    SHA1:349E32C34582E368CAC130154198CB6CD69DEBA8
                    SHA-256:2297F112B5819C8C8761662897BD7D67EA1C90C0B34719B1ACFC6338371CF666
                    SHA-512:907499D43E86878AE33DC88E09A22A69FE8E8487FCB31491D625C5BB5BE5E6444DA4FF33B3B2BB50C59A29E8DEB941BD54B13B8A34216AE9110CD7D1C7E43FDC
                    Malicious:false
                    Reputation:low
                    Preview:/tmp/Aqua.arm4.elf.nwlrbbmqbh
                    File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
                    Entropy (8bit):6.05488596937032
                    TrID:
                    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                    File name:Aqua.arm4.elf
                    File size:54'900 bytes
                    MD5:69039bfe2718fb4235b4d6f54a364ad1
                    SHA1:60bce12363986fe5e5bad07edf575ff7ea6583a7
                    SHA256:80798a1196b63f9c18ffb84719cbb0506a3d24e735e4a3f205ae5d1450e8d14b
                    SHA512:6936658d67b65bd8034cc7a702954c8a3c59ddb80e09b0ba7c298c5bef230d554fcd2ddb1216b94118f0867457afc1b58e62d6d9395636e7bb3280c318a329ae
                    SSDEEP:768:n1CST8G7qe2vcp4ImAld0mTtWzhqVMZYLMMYNvzjd1W/LMN7BuKaX6btvVIeI:gSIG732Kd0m4UTMvPtN7CKbtae
                    TLSH:7C332982B8829613C6D412BBFB6E418D772617A8E2DF3207DD166F10379692F0E77711
                    File Content Preview:.ELF...a..........(.........4...........4. ...(.........................................................x%..........Q.td..................................-...L."..../..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

                    ELF header

                    Class:ELF32
                    Data:2's complement, little endian
                    Version:1 (current)
                    Machine:ARM
                    Version Number:0x1
                    Type:EXEC (Executable file)
                    OS/ABI:ARM - ABI
                    ABI Version:0
                    Entry Point Address:0x8190
                    Flags:0x202
                    ELF Header Size:52
                    Program Header Offset:52
                    Program Header Size:32
                    Number of Program Headers:3
                    Section Header Offset:54500
                    Section Header Size:40
                    Number of Section Headers:10
                    Header String Table Index:9
                    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                    NULL0x00x00x00x00x0000
                    .initPROGBITS0x80940x940x180x00x6AX004
                    .textPROGBITS0x80b00xb00xbf0c0x00x6AX0016
                    .finiPROGBITS0x13fbc0xbfbc0x140x00x6AX004
                    .rodataPROGBITS0x13fd00xbfd00x11200x00x2A004
                    .ctorsPROGBITS0x1d0f40xd0f40x80x00x3WA004
                    .dtorsPROGBITS0x1d0fc0xd0fc0x80x00x3WA004
                    .dataPROGBITS0x1d1080xd1080x39c0x00x3WA004
                    .bssNOBITS0x1d4a40xd4a40x21c80x00x3WA004
                    .shstrtabSTRTAB0x00xd4a40x3e0x00x0001
                    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                    LOAD0x00x80000x80000xd0f00xd0f06.09080x5R E0x8000.init .text .fini .rodata
                    LOAD0xd0f40x1d0f40x1d0f40x3b00x25783.21460x6RW 0x8000.ctors .dtors .data .bss
                    GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                    TimestampSource PortDest PortSource IPDest IP
                    Dec 29, 2024 00:10:39.222870111 CET4134633966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:39.342427015 CET3396641346193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:39.342614889 CET4134633966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:39.344022989 CET4134633966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:39.463469982 CET3396641346193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:39.463736057 CET4134633966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:39.583225012 CET3396641346193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:40.678308010 CET3396641346193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:40.678584099 CET4134633966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:40.678702116 CET4134633966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:41.924014091 CET4134833966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:42.045037985 CET3396641348193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:42.045239925 CET4134833966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:42.046075106 CET4134833966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:42.167340040 CET3396641348193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:42.167429924 CET4134833966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:42.289980888 CET3396641348193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:43.328593016 CET3396641348193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:43.328751087 CET4134833966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:43.328752041 CET4134833966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:44.570652008 CET4135033966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:44.690264940 CET3396641350193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:44.690495014 CET4135033966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:44.691365957 CET4135033966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:44.811553955 CET3396641350193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:44.811795950 CET4135033966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:44.931628942 CET3396641350193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:45.979782104 CET3396641350193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:45.980091095 CET4135033966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:45.980091095 CET4135033966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:47.223628044 CET4135233966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:47.344791889 CET3396641352193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:47.345190048 CET4135233966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:47.346095085 CET4135233966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:47.465509892 CET3396641352193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:47.465912104 CET4135233966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:47.585427999 CET3396641352193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:48.581391096 CET3396641352193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:48.581629992 CET4135233966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:48.581700087 CET4135233966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:49.822721004 CET4135433966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:49.943517923 CET3396641354193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:49.943702936 CET4135433966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:49.944822073 CET4135433966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:50.065694094 CET3396641354193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:50.065942049 CET4135433966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:50.187330961 CET3396641354193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:51.263451099 CET3396641354193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:51.263622999 CET4135433966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:51.263897896 CET4135433966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:52.519454956 CET4135633966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:52.640940905 CET3396641356193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:52.641207933 CET4135633966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:52.642663002 CET4135633966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:52.764256001 CET3396641356193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:52.764519930 CET4135633966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:52.886315107 CET3396641356193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:53.978446007 CET3396641356193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:53.978621006 CET4135633966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:53.978715897 CET4135633966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:55.222328901 CET4135833966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:55.341934919 CET3396641358193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:55.342058897 CET4135833966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:55.343132973 CET4135833966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:55.462723017 CET3396641358193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:55.462954998 CET4135833966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:55.582561016 CET3396641358193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:56.631524086 CET3396641358193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:56.631781101 CET4135833966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:56.631891012 CET4135833966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:57.880018950 CET4136033966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:57.999641895 CET3396641360193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:57.999882936 CET4136033966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:58.001271963 CET4136033966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:58.120760918 CET3396641360193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:58.120997906 CET4136033966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:58.240643978 CET3396641360193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:59.235563040 CET3396641360193.200.78.37192.168.2.15
                    Dec 29, 2024 00:10:59.235996962 CET4136033966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:10:59.236150980 CET4136033966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:11:00.488018990 CET4136233966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:11:00.609004021 CET3396641362193.200.78.37192.168.2.15
                    Dec 29, 2024 00:11:00.609196901 CET4136233966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:11:00.610213041 CET4136233966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:11:00.731972933 CET3396641362193.200.78.37192.168.2.15
                    Dec 29, 2024 00:11:00.732295036 CET4136233966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:11:00.853372097 CET3396641362193.200.78.37192.168.2.15
                    Dec 29, 2024 00:11:01.846406937 CET3396641362193.200.78.37192.168.2.15
                    Dec 29, 2024 00:11:01.846632957 CET4136233966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:11:01.846709967 CET4136233966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:11:03.095724106 CET4136433966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:11:03.217047930 CET3396641364193.200.78.37192.168.2.15
                    Dec 29, 2024 00:11:03.217547894 CET4136433966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:11:03.218807936 CET4136433966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:11:03.339924097 CET3396641364193.200.78.37192.168.2.15
                    Dec 29, 2024 00:11:03.340157032 CET4136433966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:11:03.461329937 CET3396641364193.200.78.37192.168.2.15
                    Dec 29, 2024 00:11:04.509064913 CET3396641364193.200.78.37192.168.2.15
                    Dec 29, 2024 00:11:04.509552002 CET4136433966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:11:04.509552002 CET4136433966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:11:05.744579077 CET4136633966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:11:05.864173889 CET3396641366193.200.78.37192.168.2.15
                    Dec 29, 2024 00:11:05.864284039 CET4136633966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:11:05.865037918 CET4136633966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:11:05.984544992 CET3396641366193.200.78.37192.168.2.15
                    Dec 29, 2024 00:11:05.984607935 CET4136633966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:11:06.104348898 CET3396641366193.200.78.37192.168.2.15
                    Dec 29, 2024 00:12:15.920365095 CET4136633966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:12:16.040236950 CET3396641366193.200.78.37192.168.2.15
                    Dec 29, 2024 00:12:16.322663069 CET3396641366193.200.78.37192.168.2.15
                    Dec 29, 2024 00:12:16.322758913 CET4136633966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:12:26.332813025 CET4136633966192.168.2.15193.200.78.37
                    Dec 29, 2024 00:12:26.454071045 CET3396641366193.200.78.37192.168.2.15
                    Dec 29, 2024 00:12:26.732777119 CET3396641366193.200.78.37192.168.2.15
                    Dec 29, 2024 00:12:26.732940912 CET4136633966192.168.2.15193.200.78.37
                    TimestampSource PortDest PortSource IPDest IP
                    Dec 29, 2024 00:10:38.363713980 CET4471253192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:38.603543043 CET53447128.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:38.604918957 CET4722753192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:38.727420092 CET53472278.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:38.728564024 CET5905553192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:38.851006985 CET53590558.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:38.852169991 CET5227753192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:38.974421978 CET53522778.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:38.975702047 CET5920453192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:39.098167896 CET53592048.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:39.099538088 CET5586853192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:39.222045898 CET53558688.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:40.679584980 CET4284753192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:40.801791906 CET53428478.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:40.802978992 CET3549353192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:40.926732063 CET53354938.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:40.927752018 CET4483253192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:41.050005913 CET53448328.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:41.051182032 CET4705053192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:41.173469067 CET53470508.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:41.174652100 CET4716653192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:41.297039032 CET53471668.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:41.298402071 CET4778653192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:41.422455072 CET53477868.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:41.423598051 CET5201553192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:41.547703028 CET53520158.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:41.548860073 CET4531953192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:41.672902107 CET53453198.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:41.674227953 CET4057753192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:41.798209906 CET53405778.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:41.799262047 CET3441453192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:41.923362970 CET53344148.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:43.329814911 CET3922553192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:43.451996088 CET53392258.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:43.453136921 CET6089653192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:43.575753927 CET53608968.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:43.576987982 CET5004953192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:43.699297905 CET53500498.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:43.700344086 CET5595753192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:43.823333025 CET53559578.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:43.824367046 CET5242953192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:43.948041916 CET53524298.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:43.949050903 CET5924553192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:44.071258068 CET53592458.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:44.072388887 CET4419353192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:44.196130991 CET53441938.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:44.197276115 CET5788053192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:44.321275949 CET53578808.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:44.322350979 CET5580453192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:44.446516037 CET53558048.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:44.447617054 CET5821753192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:44.569914103 CET53582178.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:45.981101990 CET3429153192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:46.103354931 CET53342918.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:46.104579926 CET5548653192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:46.226979017 CET53554868.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:46.227947950 CET5664053192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:46.350786924 CET53566408.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:46.351649046 CET5966853192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:46.474664927 CET53596688.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:46.475677013 CET5419153192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:46.599299908 CET53541918.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:46.600148916 CET3539553192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:46.723892927 CET53353958.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:46.724641085 CET4327453192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:46.848524094 CET53432748.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:46.849462032 CET5850353192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:46.972997904 CET53585038.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:46.973751068 CET3414953192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:47.098397017 CET53341498.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:47.099288940 CET3713753192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:47.222891092 CET53371378.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:48.582930088 CET4025553192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:48.706854105 CET53402558.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:48.708055973 CET5256553192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:48.831969023 CET53525658.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:48.832870960 CET4214553192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:48.956661940 CET53421458.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:48.957617044 CET4929553192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:49.079891920 CET53492958.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:49.080915928 CET5033453192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:49.203356028 CET53503348.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:49.204318047 CET4358153192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:49.326689959 CET53435818.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:49.327533007 CET4971753192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:49.449878931 CET53497178.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:49.450861931 CET4327253192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:49.573158026 CET53432728.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:49.574640989 CET5824253192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:49.696970940 CET53582428.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:49.698076010 CET4705353192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:49.821984053 CET53470538.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:51.265268087 CET3819953192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:51.389008045 CET53381998.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:51.390331984 CET4143153192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:51.514180899 CET53414318.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:51.515742064 CET3546053192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:51.639698982 CET53354608.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:51.641299963 CET5379453192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:51.765028000 CET53537948.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:51.766614914 CET5599453192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:51.890815973 CET53559948.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:51.892474890 CET5975753192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:52.016587019 CET53597578.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:52.018337965 CET5739453192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:52.142437935 CET53573948.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:52.143884897 CET4021153192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:52.267558098 CET53402118.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:52.269002914 CET5485253192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:52.392971039 CET53548528.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:52.394377947 CET4281353192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:52.518449068 CET53428138.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:53.980043888 CET5930853192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:54.102343082 CET53593088.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:54.103768110 CET3715453192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:54.226046085 CET53371548.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:54.229347944 CET4625153192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:54.351672888 CET53462518.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:54.353032112 CET5031753192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:54.475708961 CET53503178.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:54.477438927 CET4419753192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:54.601643085 CET53441978.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:54.603096008 CET4398553192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:54.725383997 CET53439858.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:54.726708889 CET4967353192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:54.849065065 CET53496738.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:54.850626945 CET3856953192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:54.973503113 CET53385698.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:54.975181103 CET3992453192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:55.097481966 CET53399248.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:55.098767996 CET5003053192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:55.221287012 CET53500308.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:56.633244991 CET5000253192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:56.755661964 CET53500028.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:56.757288933 CET3528153192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:56.879679918 CET53352818.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:56.881659031 CET4334053192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:57.003947973 CET53433408.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:57.005335093 CET4676853192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:57.127729893 CET53467688.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:57.129151106 CET4736853192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:57.251961946 CET53473688.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:57.253597975 CET3635353192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:57.377460003 CET53363538.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:57.378585100 CET4060553192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:57.502660990 CET53406058.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:57.503792048 CET5039853192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:57.628235102 CET53503988.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:57.629585981 CET4389053192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:57.753716946 CET53438908.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:57.755249023 CET5576553192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:57.878957987 CET53557658.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:59.237627029 CET4327253192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:59.361398935 CET53432728.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:59.362791061 CET5259053192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:59.486879110 CET53525908.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:59.487848997 CET3467653192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:59.612173080 CET53346768.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:59.613065004 CET4372753192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:59.736596107 CET53437278.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:59.737678051 CET4467253192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:59.861433029 CET53446728.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:59.862417936 CET6060753192.168.2.158.8.8.8
                    Dec 29, 2024 00:10:59.986032963 CET53606078.8.8.8192.168.2.15
                    Dec 29, 2024 00:10:59.987258911 CET4914353192.168.2.158.8.8.8
                    Dec 29, 2024 00:11:00.111434937 CET53491438.8.8.8192.168.2.15
                    Dec 29, 2024 00:11:00.112483978 CET3577853192.168.2.158.8.8.8
                    Dec 29, 2024 00:11:00.236357927 CET53357788.8.8.8192.168.2.15
                    Dec 29, 2024 00:11:00.237525940 CET4290153192.168.2.158.8.8.8
                    Dec 29, 2024 00:11:00.361902952 CET53429018.8.8.8192.168.2.15
                    Dec 29, 2024 00:11:00.363074064 CET5621553192.168.2.158.8.8.8
                    Dec 29, 2024 00:11:00.487189054 CET53562158.8.8.8192.168.2.15
                    Dec 29, 2024 00:11:01.847939014 CET5834353192.168.2.158.8.8.8
                    Dec 29, 2024 00:11:01.971939087 CET53583438.8.8.8192.168.2.15
                    Dec 29, 2024 00:11:01.972981930 CET3452453192.168.2.158.8.8.8
                    Dec 29, 2024 00:11:02.096582890 CET53345248.8.8.8192.168.2.15
                    Dec 29, 2024 00:11:02.097780943 CET4525753192.168.2.158.8.8.8
                    Dec 29, 2024 00:11:02.221887112 CET53452578.8.8.8192.168.2.15
                    Dec 29, 2024 00:11:02.223345041 CET5037453192.168.2.158.8.8.8
                    Dec 29, 2024 00:11:02.347789049 CET53503748.8.8.8192.168.2.15
                    Dec 29, 2024 00:11:02.349277973 CET4506053192.168.2.158.8.8.8
                    Dec 29, 2024 00:11:02.473474979 CET53450608.8.8.8192.168.2.15
                    Dec 29, 2024 00:11:02.474819899 CET5463553192.168.2.158.8.8.8
                    Dec 29, 2024 00:11:02.599123001 CET53546358.8.8.8192.168.2.15
                    Dec 29, 2024 00:11:02.600750923 CET5713753192.168.2.158.8.8.8
                    Dec 29, 2024 00:11:02.723166943 CET53571378.8.8.8192.168.2.15
                    Dec 29, 2024 00:11:02.724715948 CET4322053192.168.2.158.8.8.8
                    Dec 29, 2024 00:11:02.847029924 CET53432208.8.8.8192.168.2.15
                    Dec 29, 2024 00:11:02.848512888 CET6064953192.168.2.158.8.8.8
                    Dec 29, 2024 00:11:02.970839977 CET53606498.8.8.8192.168.2.15
                    Dec 29, 2024 00:11:02.971960068 CET4477953192.168.2.158.8.8.8
                    Dec 29, 2024 00:11:03.094825983 CET53447798.8.8.8192.168.2.15
                    Dec 29, 2024 00:11:04.510832071 CET5537953192.168.2.158.8.8.8
                    Dec 29, 2024 00:11:04.633121014 CET53553798.8.8.8192.168.2.15
                    Dec 29, 2024 00:11:04.634191036 CET5625553192.168.2.158.8.8.8
                    Dec 29, 2024 00:11:04.756499052 CET53562558.8.8.8192.168.2.15
                    Dec 29, 2024 00:11:04.757620096 CET4833753192.168.2.158.8.8.8
                    Dec 29, 2024 00:11:04.879978895 CET53483378.8.8.8192.168.2.15
                    Dec 29, 2024 00:11:04.880939960 CET4550253192.168.2.158.8.8.8
                    Dec 29, 2024 00:11:05.003348112 CET53455028.8.8.8192.168.2.15
                    Dec 29, 2024 00:11:05.004240036 CET3826053192.168.2.158.8.8.8
                    Dec 29, 2024 00:11:05.126902103 CET53382608.8.8.8192.168.2.15
                    Dec 29, 2024 00:11:05.127784967 CET3612653192.168.2.158.8.8.8
                    Dec 29, 2024 00:11:05.250190020 CET53361268.8.8.8192.168.2.15
                    Dec 29, 2024 00:11:05.250998974 CET5455453192.168.2.158.8.8.8
                    Dec 29, 2024 00:11:05.373198986 CET53545548.8.8.8192.168.2.15
                    Dec 29, 2024 00:11:05.373995066 CET3367353192.168.2.158.8.8.8
                    Dec 29, 2024 00:11:05.496517897 CET53336738.8.8.8192.168.2.15
                    Dec 29, 2024 00:11:05.498009920 CET3548153192.168.2.158.8.8.8
                    Dec 29, 2024 00:11:05.620620012 CET53354818.8.8.8192.168.2.15
                    Dec 29, 2024 00:11:05.621571064 CET4298053192.168.2.158.8.8.8
                    Dec 29, 2024 00:11:05.743935108 CET53429808.8.8.8192.168.2.15
                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                    Dec 29, 2024 00:10:38.363713980 CET192.168.2.158.8.8.80xa5dcStandard query (0)raw.intenseapi.comA (IP address)IN (0x0001)false
                    Dec 29, 2024 00:10:38.604918957 CET192.168.2.158.8.8.80x7887Standard query (0)raw.intenseapi.com. [malformed]256366false
                    Dec 29, 2024 00:10:38.728564024 CET192.168.2.158.8.8.80x7887Standard query (0)raw.intenseapi.com. [malformed]256366false
                    Dec 29, 2024 00:10:38.852169991 CET192.168.2.158.8.8.80x7887Standard query (0)raw.intenseapi.com. [malformed]256366false
                    Dec 29, 2024 00:10:38.975702047 CET192.168.2.158.8.8.80x7887Standard query (0)raw.intenseapi.com. [malformed]256367false
                    Dec 29, 2024 00:10:39.099538088 CET192.168.2.158.8.8.80x7887Standard query (0)raw.intenseapi.com. [malformed]256367false
                    Dec 29, 2024 00:10:41.298402071 CET192.168.2.158.8.8.80xb9e7Standard query (0)raw.intenseapi.com. [malformed]256369false
                    Dec 29, 2024 00:10:41.423598051 CET192.168.2.158.8.8.80xb9e7Standard query (0)raw.intenseapi.com. [malformed]256369false
                    Dec 29, 2024 00:10:41.548860073 CET192.168.2.158.8.8.80xb9e7Standard query (0)raw.intenseapi.com. [malformed]256369false
                    Dec 29, 2024 00:10:41.674227953 CET192.168.2.158.8.8.80xb9e7Standard query (0)raw.intenseapi.com. [malformed]256369false
                    Dec 29, 2024 00:10:41.799262047 CET192.168.2.158.8.8.80xb9e7Standard query (0)raw.intenseapi.com. [malformed]256369false
                    Dec 29, 2024 00:10:43.949050903 CET192.168.2.158.8.8.80xe6f5Standard query (0)raw.intenseapi.com. [malformed]256372false
                    Dec 29, 2024 00:10:44.072388887 CET192.168.2.158.8.8.80xe6f5Standard query (0)raw.intenseapi.com. [malformed]256372false
                    Dec 29, 2024 00:10:44.197276115 CET192.168.2.158.8.8.80xe6f5Standard query (0)raw.intenseapi.com. [malformed]256372false
                    Dec 29, 2024 00:10:44.322350979 CET192.168.2.158.8.8.80xe6f5Standard query (0)raw.intenseapi.com. [malformed]256372false
                    Dec 29, 2024 00:10:44.447617054 CET192.168.2.158.8.8.80xe6f5Standard query (0)raw.intenseapi.com. [malformed]256372false
                    Dec 29, 2024 00:10:46.600148916 CET192.168.2.158.8.8.80x10a5Standard query (0)raw.intenseapi.com. [malformed]256374false
                    Dec 29, 2024 00:10:46.724641085 CET192.168.2.158.8.8.80x10a5Standard query (0)raw.intenseapi.com. [malformed]256374false
                    Dec 29, 2024 00:10:46.849462032 CET192.168.2.158.8.8.80x10a5Standard query (0)raw.intenseapi.com. [malformed]256374false
                    Dec 29, 2024 00:10:46.973751068 CET192.168.2.158.8.8.80x10a5Standard query (0)raw.intenseapi.com. [malformed]256375false
                    Dec 29, 2024 00:10:47.099288940 CET192.168.2.158.8.8.80x10a5Standard query (0)raw.intenseapi.com. [malformed]256375false
                    Dec 29, 2024 00:10:49.204318047 CET192.168.2.158.8.8.80x78afStandard query (0)raw.intenseapi.com. [malformed]256377false
                    Dec 29, 2024 00:10:49.327533007 CET192.168.2.158.8.8.80x78afStandard query (0)raw.intenseapi.com. [malformed]256377false
                    Dec 29, 2024 00:10:49.450861931 CET192.168.2.158.8.8.80x78afStandard query (0)raw.intenseapi.com. [malformed]256377false
                    Dec 29, 2024 00:10:49.574640989 CET192.168.2.158.8.8.80x78afStandard query (0)raw.intenseapi.com. [malformed]256377false
                    Dec 29, 2024 00:10:49.698076010 CET192.168.2.158.8.8.80x78afStandard query (0)raw.intenseapi.com. [malformed]256377false
                    Dec 29, 2024 00:10:51.892474890 CET192.168.2.158.8.8.80x7816Standard query (0)raw.intenseapi.com. [malformed]256380false
                    Dec 29, 2024 00:10:52.018337965 CET192.168.2.158.8.8.80x7816Standard query (0)raw.intenseapi.com. [malformed]256380false
                    Dec 29, 2024 00:10:52.143884897 CET192.168.2.158.8.8.80x7816Standard query (0)raw.intenseapi.com. [malformed]256380false
                    Dec 29, 2024 00:10:52.269002914 CET192.168.2.158.8.8.80x7816Standard query (0)raw.intenseapi.com. [malformed]256380false
                    Dec 29, 2024 00:10:52.394377947 CET192.168.2.158.8.8.80x7816Standard query (0)raw.intenseapi.com. [malformed]256380false
                    Dec 29, 2024 00:10:54.603096008 CET192.168.2.158.8.8.80xbfb9Standard query (0)raw.intenseapi.com. [malformed]256382false
                    Dec 29, 2024 00:10:54.726708889 CET192.168.2.158.8.8.80xbfb9Standard query (0)raw.intenseapi.com. [malformed]256382false
                    Dec 29, 2024 00:10:54.850626945 CET192.168.2.158.8.8.80xbfb9Standard query (0)raw.intenseapi.com. [malformed]256382false
                    Dec 29, 2024 00:10:54.975181103 CET192.168.2.158.8.8.80xbfb9Standard query (0)raw.intenseapi.com. [malformed]256383false
                    Dec 29, 2024 00:10:55.098767996 CET192.168.2.158.8.8.80xbfb9Standard query (0)raw.intenseapi.com. [malformed]256383false
                    Dec 29, 2024 00:10:57.253597975 CET192.168.2.158.8.8.80x9d0aStandard query (0)raw.intenseapi.com. [malformed]256385false
                    Dec 29, 2024 00:10:57.378585100 CET192.168.2.158.8.8.80x9d0aStandard query (0)raw.intenseapi.com. [malformed]256385false
                    Dec 29, 2024 00:10:57.503792048 CET192.168.2.158.8.8.80x9d0aStandard query (0)raw.intenseapi.com. [malformed]256385false
                    Dec 29, 2024 00:10:57.629585981 CET192.168.2.158.8.8.80x9d0aStandard query (0)raw.intenseapi.com. [malformed]256385false
                    Dec 29, 2024 00:10:57.755249023 CET192.168.2.158.8.8.80x9d0aStandard query (0)raw.intenseapi.com. [malformed]256385false
                    Dec 29, 2024 00:10:59.862417936 CET192.168.2.158.8.8.80x8124Standard query (0)raw.intenseapi.com. [malformed]256387false
                    Dec 29, 2024 00:10:59.987258911 CET192.168.2.158.8.8.80x8124Standard query (0)raw.intenseapi.com. [malformed]256388false
                    Dec 29, 2024 00:11:00.112483978 CET192.168.2.158.8.8.80x8124Standard query (0)raw.intenseapi.com. [malformed]256388false
                    Dec 29, 2024 00:11:00.237525940 CET192.168.2.158.8.8.80x8124Standard query (0)raw.intenseapi.com. [malformed]256388false
                    Dec 29, 2024 00:11:00.363074064 CET192.168.2.158.8.8.80x8124Standard query (0)raw.intenseapi.com. [malformed]256388false
                    Dec 29, 2024 00:11:02.474819899 CET192.168.2.158.8.8.80x76d9Standard query (0)raw.intenseapi.com. [malformed]256390false
                    Dec 29, 2024 00:11:02.600750923 CET192.168.2.158.8.8.80x76d9Standard query (0)raw.intenseapi.com. [malformed]256390false
                    Dec 29, 2024 00:11:02.724715948 CET192.168.2.158.8.8.80x76d9Standard query (0)raw.intenseapi.com. [malformed]256390false
                    Dec 29, 2024 00:11:02.848512888 CET192.168.2.158.8.8.80x76d9Standard query (0)raw.intenseapi.com. [malformed]256390false
                    Dec 29, 2024 00:11:02.971960068 CET192.168.2.158.8.8.80x76d9Standard query (0)raw.intenseapi.com. [malformed]256391false
                    Dec 29, 2024 00:11:05.127784967 CET192.168.2.158.8.8.80x236dStandard query (0)raw.intenseapi.com. [malformed]256393false
                    Dec 29, 2024 00:11:05.250998974 CET192.168.2.158.8.8.80x236dStandard query (0)raw.intenseapi.com. [malformed]256393false
                    Dec 29, 2024 00:11:05.373995066 CET192.168.2.158.8.8.80x236dStandard query (0)raw.intenseapi.com. [malformed]256393false
                    Dec 29, 2024 00:11:05.498009920 CET192.168.2.158.8.8.80x236dStandard query (0)raw.intenseapi.com. [malformed]256393false
                    Dec 29, 2024 00:11:05.621571064 CET192.168.2.158.8.8.80x236dStandard query (0)raw.intenseapi.com. [malformed]256393false
                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                    Dec 29, 2024 00:10:38.603543043 CET8.8.8.8192.168.2.150xa5dcNo error (0)raw.intenseapi.com193.200.78.37A (IP address)IN (0x0001)false

                    System Behavior

                    Start time (UTC):23:10:37
                    Start date (UTC):28/12/2024
                    Path:/tmp/Aqua.arm4.elf
                    Arguments:/tmp/Aqua.arm4.elf
                    File size:4956856 bytes
                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                    Start time (UTC):23:10:37
                    Start date (UTC):28/12/2024
                    Path:/tmp/Aqua.arm4.elf
                    Arguments:-
                    File size:4956856 bytes
                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1