Edit tour

Linux Analysis Report
sync.arm4.elf

Overview

General Information

Sample name:sync.arm4.elf
Analysis ID:1642619
MD5:d7f76a4a1c38e3058338bc2c22a9cd73
SHA1:0c12aa1b744d4af78e709ef7e8db7d43f277b27f
SHA256:f0530ea42e4f43f31dc0161ce6764619f0b45461d3ae4e43b9a117d0fff4b3b7
Tags:elfuser-abuse_ch
Infos:

Detection

Score:64
Range:0 - 100

Signatures

Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Performs DNS TXT record lookups
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sleeps for long times indicative of sandbox evasion
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1642619
Start date and time:2025-03-19 08:57:16 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 36s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:sync.arm4.elf
Detection:MAL
Classification:mal64.evad.linELF@0/0@78/0
Command:/tmp/sync.arm4.elf
PID:6237
Exit Code:1
Exit Code Info:
Killed:False
Standard Output:
sync
Standard Error:
  • system is lnxubuntu20
  • sync.arm4.elf (PID: 6237, Parent: 6157, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/sync.arm4.elf
  • cleanup
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-03-19T08:58:29.777416+010020135141A Network Trojan was detected192.168.2.23537848.8.4.453UDP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: sync.arm4.elfReversingLabs: Detection: 50%

Networking

barindex
Source: Network trafficSuricata IDS: 2013514 - Severity 1 - ET MALWARE Potential DNS Command and Control via TXT queries : 192.168.2.23:53784 -> 8.8.4.4:53
Source: global trafficTCP traffic: 192.168.2.23:41006 -> 185.194.205.79:61005
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownDNS traffic detected: query: dnsresolve.socialgains.cf replaycode: Name error (3)
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: global trafficDNS traffic detected: DNS query: dnsresolve.socialgains.cf
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal64.evad.linELF@0/0@78/0

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/sync.arm4.elf (PID: 6237)File: /tmp/sync.arm4.elfJump to behavior
Source: /tmp/sync.arm4.elf (PID: 6241)Sleeps longer then 60s: 60.0sJump to behavior
Source: /tmp/sync.arm4.elf (PID: 6241)Sleeps longer then 60s: 60.0sJump to behavior
Source: /tmp/sync.arm4.elf (PID: 6237)Queries kernel information via 'uname': Jump to behavior
Source: sync.arm4.elf, 6237.1.00007ffd08282000.00007ffd082a3000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/sync.arm4.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/sync.arm4.elf
Source: sync.arm4.elf, 6237.1.0000560cfc79c000.0000560cfc8ca000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: sync.arm4.elf, 6237.1.00007ffd08282000.00007ffd082a3000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: sync.arm4.elf, 6237.1.0000560cfc79c000.0000560cfc8ca000.rw-.sdmpBinary or memory string: V!/etc/qemu-binfmt/arm

HIPS / PFW / Operating System Protection Evasion

barindex
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Virtualization/Sandbox Evasion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
File Deletion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1642619 Sample: sync.arm4.elf Startdate: 19/03/2025 Architecture: LINUX Score: 64 15 dnsresolve.socialgains.cf 2->15 17 109.202.202.202, 80 INIT7CH Switzerland 2->17 19 3 other IPs or domains 2->19 21 Suricata IDS alerts for network traffic 2->21 23 Multi AV Scanner detection for submitted file 2->23 8 sync.arm4.elf 2->8         started        signatures3 25 Performs DNS TXT record lookups 15->25 process4 signatures5 27 Sample deletes itself 8->27 11 sync.arm4.elf 8->11         started        process6 process7 13 sync.arm4.elf 11->13         started       
SourceDetectionScannerLabelLink
sync.arm4.elf50%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
dnsresolve.socialgains.cf
unknown
unknownfalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    185.194.205.79
    unknownFrance
    204145HTSENSEFRfalse
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    185.194.205.79sync.x86_64.elfGet hashmaliciousUnknownBrowse
      sync.m68k.elfGet hashmaliciousMiraiBrowse
        sync.mipsel.elfGet hashmaliciousUnknownBrowse
          sync.arm5.elfGet hashmaliciousUnknownBrowse
            sync.arm7.elfGet hashmaliciousUnknownBrowse
              sync.sparc.elfGet hashmaliciousUnknownBrowse
                sync.powerpc.elfGet hashmaliciousUnknownBrowse
                  sync.superh.elfGet hashmaliciousUnknownBrowse
                    sync.sh4.elfGet hashmaliciousUnknownBrowse
                      sync.arm7.elfGet hashmaliciousUnknownBrowse
                        109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                        • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                        91.189.91.43sync.x86_64.elfGet hashmaliciousUnknownBrowse
                          na.elfGet hashmaliciousPrometeiBrowse
                            sync.m68k.elfGet hashmaliciousMiraiBrowse
                              na.elfGet hashmaliciousPrometeiBrowse
                                na.elfGet hashmaliciousPrometeiBrowse
                                  na.elfGet hashmaliciousPrometeiBrowse
                                    sync.powerpc.elfGet hashmaliciousUnknownBrowse
                                      sync.arm6.elfGet hashmaliciousUnknownBrowse
                                        na.elfGet hashmaliciousPrometeiBrowse
                                          na.elfGet hashmaliciousPrometeiBrowse
                                            91.189.91.42sync.x86_64.elfGet hashmaliciousUnknownBrowse
                                              na.elfGet hashmaliciousPrometeiBrowse
                                                sync.m68k.elfGet hashmaliciousMiraiBrowse
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                        sync.powerpc.elfGet hashmaliciousUnknownBrowse
                                                          sync.arm6.elfGet hashmaliciousUnknownBrowse
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                                No context
                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                CANONICAL-ASGBsync.x86_64.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 91.189.91.42
                                                                sync.m68k.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 91.189.91.42
                                                                sync.mipsel.elfGet hashmaliciousUnknownBrowse
                                                                • 185.125.190.26
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 91.189.91.42
                                                                sync.powerpc.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                sync.arm6.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 91.189.91.42
                                                                CANONICAL-ASGBsync.x86_64.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 91.189.91.42
                                                                sync.m68k.elfGet hashmaliciousMiraiBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 91.189.91.42
                                                                sync.mipsel.elfGet hashmaliciousUnknownBrowse
                                                                • 185.125.190.26
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 91.189.91.42
                                                                sync.powerpc.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                sync.arm6.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 91.189.91.42
                                                                HTSENSEFRsync.x86_64.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                sync.m68k.elfGet hashmaliciousMiraiBrowse
                                                                • 185.194.205.79
                                                                sync.mipsel.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                sync.arm5.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                sync.arm7.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                sync.sparc.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                sync.powerpc.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                sync.superh.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                sync.sh4.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                sync.arm7.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                INIT7CHsync.x86_64.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 109.202.202.202
                                                                sync.m68k.elfGet hashmaliciousMiraiBrowse
                                                                • 109.202.202.202
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 109.202.202.202
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 109.202.202.202
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 109.202.202.202
                                                                sync.powerpc.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                sync.arm6.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 109.202.202.202
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 109.202.202.202
                                                                No context
                                                                No context
                                                                No created / dropped files found
                                                                File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
                                                                Entropy (8bit):6.103259904960722
                                                                TrID:
                                                                • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                File name:sync.arm4.elf
                                                                File size:64'864 bytes
                                                                MD5:d7f76a4a1c38e3058338bc2c22a9cd73
                                                                SHA1:0c12aa1b744d4af78e709ef7e8db7d43f277b27f
                                                                SHA256:f0530ea42e4f43f31dc0161ce6764619f0b45461d3ae4e43b9a117d0fff4b3b7
                                                                SHA512:0816012375efe5c9f2ee036b0ea44b7c7ae4ddabb7134314035dc91dc4a25d6ecfee3f3791d722b55159c83eac8b7ebb8cf3330967effdd3c3636709e48106ec
                                                                SSDEEP:1536:I9hojoLxYbpGiOlDbW+prjvZpvs9Dvh/:4CGiOlDbFprlZSh/
                                                                TLSH:54534B46F982A613C5E05676FA4F82CC331257E8E2DF3603DE2A5F21379746B0EA7911
                                                                File Content Preview:.ELF...a..........(.........4...........4. ...(.....................................................................Q.td..................................-...L."....6..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

                                                                ELF header

                                                                Class:ELF32
                                                                Data:2's complement, little endian
                                                                Version:1 (current)
                                                                Machine:ARM
                                                                Version Number:0x1
                                                                Type:EXEC (Executable file)
                                                                OS/ABI:ARM - ABI
                                                                ABI Version:0
                                                                Entry Point Address:0x8190
                                                                Flags:0x202
                                                                ELF Header Size:52
                                                                Program Header Offset:52
                                                                Program Header Size:32
                                                                Number of Program Headers:3
                                                                Section Header Offset:64464
                                                                Section Header Size:40
                                                                Number of Section Headers:10
                                                                Header String Table Index:9
                                                                NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                NULL0x00x00x00x00x0000
                                                                .initPROGBITS0x80940x940x180x00x6AX004
                                                                .textPROGBITS0x80b00xb00xdc200x00x6AX0016
                                                                .finiPROGBITS0x15cd00xdcd00x140x00x6AX004
                                                                .rodataPROGBITS0x15ce40xdce40x1ab40x00x2A004
                                                                .ctorsPROGBITS0x1f79c0xf79c0x80x00x3WA004
                                                                .dtorsPROGBITS0x1f7a40xf7a40x80x00x3WA004
                                                                .dataPROGBITS0x1f7b00xf7b00x3e00x00x3WA004
                                                                .bssNOBITS0x1fb900xfb900xa2fc0x00x3WA004
                                                                .shstrtabSTRTAB0x00xfb900x3e0x00x0001
                                                                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                LOAD0x00x80000x80000xf7980xf7986.13410x5R E0x8000.init .text .fini .rodata
                                                                LOAD0xf79c0x1f79c0x1f79c0x3f40xa6f03.53060x6RW 0x8000.ctors .dtors .data .bss
                                                                GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                                                                Download Network PCAP: filteredfull

                                                                TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                                2025-03-19T08:58:29.777416+01002013514ET MALWARE Potential DNS Command and Control via TXT queries1192.168.2.23537848.8.4.453UDP
                                                                • Total Packets: 148
                                                                • 61005 undefined
                                                                • 443 (HTTPS)
                                                                • 80 (HTTP)
                                                                • 53 (DNS)
                                                                TimestampSource PortDest PortSource IPDest IP
                                                                Mar 19, 2025 08:58:02.150804996 CET43928443192.168.2.2391.189.91.42
                                                                Mar 19, 2025 08:58:07.781927109 CET42836443192.168.2.2391.189.91.43
                                                                Mar 19, 2025 08:58:09.317718983 CET4251680192.168.2.23109.202.202.202
                                                                Mar 19, 2025 08:58:09.825309992 CET4100661005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:09.830029011 CET6100541006185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:58:09.830094099 CET4100661005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:09.830153942 CET4100661005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:09.834799051 CET6100541006185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:58:11.607778072 CET6100541006185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:58:11.608675003 CET4100661005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:11.613903999 CET6100541006185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:58:17.846776962 CET4100861005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:17.851902008 CET6100541008185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:58:17.852006912 CET4100861005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:17.852046013 CET4100861005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:17.857417107 CET6100541008185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:58:19.639856100 CET6100541008185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:58:19.640141964 CET4100861005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:19.644948959 CET6100541008185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:58:22.372253895 CET43928443192.168.2.2391.189.91.42
                                                                Mar 19, 2025 08:58:25.959985971 CET4101061005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:25.966968060 CET6100541010185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:58:25.967097998 CET4101061005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:25.967128992 CET4101061005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:25.971815109 CET6100541010185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:58:27.753396988 CET6100541010185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:58:27.753936052 CET4101061005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:27.758708000 CET6100541010185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:58:34.002389908 CET4101261005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:34.008429050 CET6100541012185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:58:34.008548021 CET4101261005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:34.008577108 CET4101261005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:34.015433073 CET6100541012185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:58:34.658328056 CET42836443192.168.2.2391.189.91.43
                                                                Mar 19, 2025 08:58:35.797486067 CET6100541012185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:58:35.797746897 CET4101261005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:35.802810907 CET6100541012185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:58:38.753703117 CET4251680192.168.2.23109.202.202.202
                                                                Mar 19, 2025 08:58:41.919349909 CET4101461005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:41.924191952 CET6100541014185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:58:41.924282074 CET4101461005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:41.924319983 CET4101461005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:41.928932905 CET6100541014185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:58:41.929008961 CET4101461005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:41.933645964 CET6100541014185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:58:43.702574015 CET6100541014185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:58:43.703099966 CET4101461005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:43.708113909 CET6100541014185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:58:49.950440884 CET4101661005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:49.955116034 CET6100541016185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:58:49.955243111 CET4101661005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:49.955243111 CET4101661005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:49.959882021 CET6100541016185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:58:51.750063896 CET6100541016185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:58:51.750701904 CET4101661005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:51.755335093 CET6100541016185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:58:57.890852928 CET4101861005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:57.895910978 CET6100541018185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:58:57.896011114 CET4101861005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:57.896106005 CET4101861005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:57.900746107 CET6100541018185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:58:59.707129955 CET6100541018185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:58:59.707735062 CET4101861005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:58:59.712541103 CET6100541018185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:03.326560020 CET43928443192.168.2.2391.189.91.42
                                                                Mar 19, 2025 08:59:05.862894058 CET4102061005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:05.867763042 CET6100541020185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:05.867876053 CET4102061005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:05.867917061 CET4102061005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:05.872584105 CET6100541020185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:07.655958891 CET6100541020185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:07.656250954 CET4102061005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:07.660914898 CET6100541020185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:13.968755007 CET4102261005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:13.973601103 CET6100541022185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:13.973901033 CET4102261005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:13.973994017 CET4102261005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:13.979360104 CET6100541022185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:13.979423046 CET4102261005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:13.985044956 CET6100541022185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:15.765326023 CET6100541022185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:15.765822887 CET4102261005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:15.773319006 CET6100541022185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:22.004967928 CET4102461005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:22.009809017 CET6100541024185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:22.009932041 CET4102461005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:22.009999990 CET4102461005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:22.014631987 CET6100541024185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:23.784415007 CET6100541024185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:23.784794092 CET4102461005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:23.790926933 CET6100541024185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:30.113895893 CET4102661005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:30.118741989 CET6100541026185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:30.118834972 CET4102661005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:30.118891954 CET4102661005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:30.123548031 CET6100541026185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:31.921468019 CET6100541026185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:31.921920061 CET4102661005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:31.926613092 CET6100541026185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:38.135761976 CET4102861005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:38.140784025 CET6100541028185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:38.140868902 CET4102861005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:38.140911102 CET4102861005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:38.145626068 CET6100541028185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:39.922913074 CET6100541028185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:39.923180103 CET4102861005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:39.928544998 CET6100541028185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:46.245479107 CET4103061005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:46.250394106 CET6100541030185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:46.250494003 CET4103061005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:46.250564098 CET4103061005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:46.255260944 CET6100541030185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:46.255341053 CET4103061005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:46.260041952 CET6100541030185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:48.033205032 CET6100541030185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:48.033394098 CET4103061005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:48.038099051 CET6100541030185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:54.171679974 CET4103261005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:54.176682949 CET6100541032185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:54.176798105 CET4103261005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:54.176860094 CET4103261005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:54.181473017 CET6100541032185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:55.973081112 CET6100541032185.194.205.79192.168.2.23
                                                                Mar 19, 2025 08:59:55.973484039 CET4103261005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 08:59:55.978322029 CET6100541032185.194.205.79192.168.2.23
                                                                Mar 19, 2025 09:00:02.241054058 CET4103461005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 09:00:02.245898962 CET6100541034185.194.205.79192.168.2.23
                                                                Mar 19, 2025 09:00:02.246048927 CET4103461005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 09:00:02.246175051 CET4103461005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 09:00:02.250824928 CET6100541034185.194.205.79192.168.2.23
                                                                Mar 19, 2025 09:00:04.017864943 CET6100541034185.194.205.79192.168.2.23
                                                                Mar 19, 2025 09:00:04.018054962 CET4103461005192.168.2.23185.194.205.79
                                                                Mar 19, 2025 09:00:04.025672913 CET6100541034185.194.205.79192.168.2.23
                                                                TimestampSource PortDest PortSource IPDest IP
                                                                Mar 19, 2025 08:58:04.514594078 CET3807153192.168.2.231.0.0.1
                                                                Mar 19, 2025 08:58:04.638020039 CET53380711.0.0.1192.168.2.23
                                                                Mar 19, 2025 08:58:05.647830963 CET5887753192.168.2.231.1.1.1
                                                                Mar 19, 2025 08:58:05.674372911 CET53588771.1.1.1192.168.2.23
                                                                Mar 19, 2025 08:58:06.679436922 CET5960853192.168.2.238.8.8.8
                                                                Mar 19, 2025 08:58:06.694658995 CET53596088.8.8.8192.168.2.23
                                                                Mar 19, 2025 08:58:07.697613001 CET5872453192.168.2.238.8.8.8
                                                                Mar 19, 2025 08:58:07.712959051 CET53587248.8.8.8192.168.2.23
                                                                Mar 19, 2025 08:58:08.716568947 CET5284353192.168.2.231.1.1.1
                                                                Mar 19, 2025 08:58:08.822300911 CET53528431.1.1.1192.168.2.23
                                                                Mar 19, 2025 08:58:12.612023115 CET3658153192.168.2.238.8.8.8
                                                                Mar 19, 2025 08:58:12.628179073 CET53365818.8.8.8192.168.2.23
                                                                Mar 19, 2025 08:58:13.631313086 CET6012753192.168.2.238.8.4.4
                                                                Mar 19, 2025 08:58:13.646677017 CET53601278.8.4.4192.168.2.23
                                                                Mar 19, 2025 08:58:14.653311014 CET4394153192.168.2.231.0.0.1
                                                                Mar 19, 2025 08:58:14.791577101 CET53439411.0.0.1192.168.2.23
                                                                Mar 19, 2025 08:58:15.795775890 CET5584553192.168.2.238.8.8.8
                                                                Mar 19, 2025 08:58:15.824673891 CET53558458.8.8.8192.168.2.23
                                                                Mar 19, 2025 08:58:16.828008890 CET4811653192.168.2.238.8.4.4
                                                                Mar 19, 2025 08:58:16.843574047 CET53481168.8.4.4192.168.2.23
                                                                Mar 19, 2025 08:58:20.643419027 CET4090253192.168.2.231.0.0.1
                                                                Mar 19, 2025 08:58:20.667754889 CET53409021.0.0.1192.168.2.23
                                                                Mar 19, 2025 08:58:21.670759916 CET4772553192.168.2.231.0.0.1
                                                                Mar 19, 2025 08:58:21.792846918 CET53477251.0.0.1192.168.2.23
                                                                Mar 19, 2025 08:58:22.797049999 CET5344853192.168.2.238.8.4.4
                                                                Mar 19, 2025 08:58:22.812958002 CET53534488.8.4.4192.168.2.23
                                                                Mar 19, 2025 08:58:23.816819906 CET3714353192.168.2.231.0.0.1
                                                                Mar 19, 2025 08:58:23.841618061 CET53371431.0.0.1192.168.2.23
                                                                Mar 19, 2025 08:58:24.845846891 CET4204653192.168.2.231.0.0.1
                                                                Mar 19, 2025 08:58:24.956720114 CET53420461.0.0.1192.168.2.23
                                                                Mar 19, 2025 08:58:28.757844925 CET5157753192.168.2.238.8.8.8
                                                                Mar 19, 2025 08:58:28.773839951 CET53515778.8.8.8192.168.2.23
                                                                Mar 19, 2025 08:58:29.777415991 CET5378453192.168.2.238.8.4.4
                                                                Mar 19, 2025 08:58:29.805685043 CET53537848.8.4.4192.168.2.23
                                                                Mar 19, 2025 08:58:30.809678078 CET3654953192.168.2.231.0.0.1
                                                                Mar 19, 2025 08:58:30.947248936 CET53365491.0.0.1192.168.2.23
                                                                Mar 19, 2025 08:58:31.951345921 CET3715953192.168.2.238.8.8.8
                                                                Mar 19, 2025 08:58:31.967448950 CET53371598.8.8.8192.168.2.23
                                                                Mar 19, 2025 08:58:32.971741915 CET5645953192.168.2.231.1.1.1
                                                                Mar 19, 2025 08:58:32.998972893 CET53564591.1.1.1192.168.2.23
                                                                Mar 19, 2025 08:58:36.801345110 CET5947853192.168.2.231.1.1.1
                                                                Mar 19, 2025 08:58:36.826153040 CET53594781.1.1.1192.168.2.23
                                                                Mar 19, 2025 08:58:37.830132961 CET4158853192.168.2.238.8.4.4
                                                                Mar 19, 2025 08:58:37.845865011 CET53415888.8.4.4192.168.2.23
                                                                Mar 19, 2025 08:58:38.850064993 CET4407353192.168.2.238.8.8.8
                                                                Mar 19, 2025 08:58:38.865853071 CET53440738.8.8.8192.168.2.23
                                                                Mar 19, 2025 08:58:39.869695902 CET3898153192.168.2.238.8.8.8
                                                                Mar 19, 2025 08:58:39.884566069 CET53389818.8.8.8192.168.2.23
                                                                Mar 19, 2025 08:58:40.890527964 CET4131353192.168.2.231.0.0.1
                                                                Mar 19, 2025 08:58:40.915637016 CET53413131.0.0.1192.168.2.23
                                                                Mar 19, 2025 08:58:44.707828045 CET5034253192.168.2.231.0.0.1
                                                                Mar 19, 2025 08:58:44.732654095 CET53503421.0.0.1192.168.2.23
                                                                Mar 19, 2025 08:58:45.736682892 CET6007753192.168.2.238.8.4.4
                                                                Mar 19, 2025 08:58:45.751837969 CET53600778.8.4.4192.168.2.23
                                                                Mar 19, 2025 08:58:46.756328106 CET5496853192.168.2.238.8.4.4
                                                                Mar 19, 2025 08:58:46.785569906 CET53549688.8.4.4192.168.2.23
                                                                Mar 19, 2025 08:58:47.790503025 CET4932453192.168.2.238.8.8.8
                                                                Mar 19, 2025 08:58:47.805401087 CET53493248.8.8.8192.168.2.23
                                                                Mar 19, 2025 08:58:48.809432983 CET5111953192.168.2.231.1.1.1
                                                                Mar 19, 2025 08:58:48.947081089 CET53511191.1.1.1192.168.2.23
                                                                Mar 19, 2025 08:58:52.755320072 CET4298753192.168.2.231.0.0.1
                                                                Mar 19, 2025 08:58:52.781833887 CET53429871.0.0.1192.168.2.23
                                                                Mar 19, 2025 08:58:53.785341978 CET4165853192.168.2.231.1.1.1
                                                                Mar 19, 2025 08:58:53.810746908 CET53416581.1.1.1192.168.2.23
                                                                Mar 19, 2025 08:58:54.814136982 CET5705353192.168.2.231.0.0.1
                                                                Mar 19, 2025 08:58:54.839596033 CET53570531.0.0.1192.168.2.23
                                                                Mar 19, 2025 08:58:55.844333887 CET4147353192.168.2.231.0.0.1
                                                                Mar 19, 2025 08:58:55.868555069 CET53414731.0.0.1192.168.2.23
                                                                Mar 19, 2025 08:58:56.872648954 CET3482253192.168.2.238.8.8.8
                                                                Mar 19, 2025 08:58:56.887609959 CET53348228.8.8.8192.168.2.23
                                                                Mar 19, 2025 08:59:00.712656021 CET4673053192.168.2.238.8.8.8
                                                                Mar 19, 2025 08:59:00.741863012 CET53467308.8.8.8192.168.2.23
                                                                Mar 19, 2025 08:59:01.748122931 CET4894553192.168.2.238.8.8.8
                                                                Mar 19, 2025 08:59:01.776393890 CET53489458.8.8.8192.168.2.23
                                                                Mar 19, 2025 08:59:02.781964064 CET5079953192.168.2.238.8.8.8
                                                                Mar 19, 2025 08:59:02.797117949 CET53507998.8.8.8192.168.2.23
                                                                Mar 19, 2025 08:59:03.803663015 CET4532753192.168.2.231.1.1.1
                                                                Mar 19, 2025 08:59:03.829236984 CET53453271.1.1.1192.168.2.23
                                                                Mar 19, 2025 08:59:04.834784985 CET4984853192.168.2.231.0.0.1
                                                                Mar 19, 2025 08:59:04.859519958 CET53498481.0.0.1192.168.2.23
                                                                Mar 19, 2025 08:59:08.660430908 CET4329553192.168.2.231.1.1.1
                                                                Mar 19, 2025 08:59:08.762463093 CET53432951.1.1.1192.168.2.23
                                                                Mar 19, 2025 08:59:09.766482115 CET5552953192.168.2.238.8.4.4
                                                                Mar 19, 2025 08:59:09.781441927 CET53555298.8.4.4192.168.2.23
                                                                Mar 19, 2025 08:59:10.785809040 CET5893853192.168.2.238.8.8.8
                                                                Mar 19, 2025 08:59:10.801830053 CET53589388.8.8.8192.168.2.23
                                                                Mar 19, 2025 08:59:11.806528091 CET5693653192.168.2.238.8.8.8
                                                                Mar 19, 2025 08:59:11.821618080 CET53569368.8.8.8192.168.2.23
                                                                Mar 19, 2025 08:59:12.824522972 CET4917253192.168.2.231.0.0.1
                                                                Mar 19, 2025 08:59:12.965039968 CET53491721.0.0.1192.168.2.23
                                                                Mar 19, 2025 08:59:16.768461943 CET3992553192.168.2.238.8.8.8
                                                                Mar 19, 2025 08:59:16.797204971 CET53399258.8.8.8192.168.2.23
                                                                Mar 19, 2025 08:59:17.800621986 CET4542253192.168.2.238.8.4.4
                                                                Mar 19, 2025 08:59:17.815371037 CET53454228.8.4.4192.168.2.23
                                                                Mar 19, 2025 08:59:18.818430901 CET4574453192.168.2.231.0.0.1
                                                                Mar 19, 2025 08:59:18.955737114 CET53457441.0.0.1192.168.2.23
                                                                Mar 19, 2025 08:59:19.959270000 CET5749653192.168.2.231.0.0.1
                                                                Mar 19, 2025 08:59:19.984297991 CET53574961.0.0.1192.168.2.23
                                                                Mar 19, 2025 08:59:20.986888885 CET5992253192.168.2.238.8.8.8
                                                                Mar 19, 2025 08:59:21.002429962 CET53599228.8.8.8192.168.2.23
                                                                Mar 19, 2025 08:59:24.789271116 CET4381553192.168.2.231.0.0.1
                                                                Mar 19, 2025 08:59:24.814414024 CET53438151.0.0.1192.168.2.23
                                                                Mar 19, 2025 08:59:25.818000078 CET5676653192.168.2.238.8.4.4
                                                                Mar 19, 2025 08:59:25.833904982 CET53567668.8.4.4192.168.2.23
                                                                Mar 19, 2025 08:59:26.837384939 CET6011053192.168.2.231.0.0.1
                                                                Mar 19, 2025 08:59:27.046916962 CET53601101.0.0.1192.168.2.23
                                                                Mar 19, 2025 08:59:28.050328970 CET3551153192.168.2.238.8.4.4
                                                                Mar 19, 2025 08:59:28.078623056 CET53355118.8.4.4192.168.2.23
                                                                Mar 19, 2025 08:59:29.082339048 CET5489153192.168.2.231.0.0.1
                                                                Mar 19, 2025 08:59:29.110620975 CET53548911.0.0.1192.168.2.23
                                                                Mar 19, 2025 08:59:32.925936937 CET4669253192.168.2.238.8.8.8
                                                                Mar 19, 2025 08:59:32.944523096 CET53466928.8.8.8192.168.2.23
                                                                Mar 19, 2025 08:59:33.949692965 CET4209253192.168.2.238.8.4.4
                                                                Mar 19, 2025 08:59:33.965709925 CET53420928.8.4.4192.168.2.23
                                                                Mar 19, 2025 08:59:34.969914913 CET5706853192.168.2.238.8.4.4
                                                                Mar 19, 2025 08:59:34.989775896 CET53570688.8.4.4192.168.2.23
                                                                Mar 19, 2025 08:59:35.993438005 CET5387953192.168.2.238.8.8.8
                                                                Mar 19, 2025 08:59:36.009005070 CET53538798.8.8.8192.168.2.23
                                                                Mar 19, 2025 08:59:37.012403965 CET3755553192.168.2.231.1.1.1
                                                                Mar 19, 2025 08:59:37.133446932 CET53375551.1.1.1192.168.2.23
                                                                Mar 19, 2025 08:59:40.927067041 CET4282553192.168.2.231.1.1.1
                                                                Mar 19, 2025 08:59:41.031443119 CET53428251.1.1.1192.168.2.23
                                                                Mar 19, 2025 08:59:42.036343098 CET4659353192.168.2.231.1.1.1
                                                                Mar 19, 2025 08:59:42.160058975 CET53465931.1.1.1192.168.2.23
                                                                Mar 19, 2025 08:59:43.164158106 CET5907553192.168.2.238.8.8.8
                                                                Mar 19, 2025 08:59:43.179734945 CET53590758.8.8.8192.168.2.23
                                                                Mar 19, 2025 08:59:44.182858944 CET3852453192.168.2.238.8.4.4
                                                                Mar 19, 2025 08:59:44.210894108 CET53385248.8.4.4192.168.2.23
                                                                Mar 19, 2025 08:59:45.213830948 CET5110253192.168.2.238.8.4.4
                                                                Mar 19, 2025 08:59:45.242981911 CET53511028.8.4.4192.168.2.23
                                                                Mar 19, 2025 08:59:49.038265944 CET4529453192.168.2.238.8.4.4
                                                                Mar 19, 2025 08:59:49.053762913 CET53452948.8.4.4192.168.2.23
                                                                Mar 19, 2025 08:59:50.058180094 CET3857153192.168.2.238.8.4.4
                                                                Mar 19, 2025 08:59:50.073973894 CET53385718.8.4.4192.168.2.23
                                                                Mar 19, 2025 08:59:51.078845978 CET5459853192.168.2.231.0.0.1
                                                                Mar 19, 2025 08:59:51.104372978 CET53545981.0.0.1192.168.2.23
                                                                Mar 19, 2025 08:59:52.108438969 CET4195553192.168.2.231.1.1.1
                                                                Mar 19, 2025 08:59:52.134181976 CET53419551.1.1.1192.168.2.23
                                                                Mar 19, 2025 08:59:53.138911009 CET4017953192.168.2.238.8.4.4
                                                                Mar 19, 2025 08:59:53.168391943 CET53401798.8.4.4192.168.2.23
                                                                Mar 19, 2025 08:59:56.977950096 CET3640453192.168.2.231.1.1.1
                                                                Mar 19, 2025 08:59:57.002288103 CET53364041.1.1.1192.168.2.23
                                                                Mar 19, 2025 08:59:58.006743908 CET3659553192.168.2.231.0.0.1
                                                                Mar 19, 2025 08:59:58.055218935 CET53365951.0.0.1192.168.2.23
                                                                Mar 19, 2025 08:59:59.059317112 CET4341253192.168.2.231.1.1.1
                                                                Mar 19, 2025 08:59:59.083849907 CET53434121.1.1.1192.168.2.23
                                                                Mar 19, 2025 09:00:00.087760925 CET4607953192.168.2.231.1.1.1
                                                                Mar 19, 2025 09:00:00.208543062 CET53460791.1.1.1192.168.2.23
                                                                Mar 19, 2025 09:00:01.212755919 CET5550053192.168.2.231.0.0.1
                                                                Mar 19, 2025 09:00:01.238260984 CET53555001.0.0.1192.168.2.23
                                                                Mar 19, 2025 09:00:05.021330118 CET3930053192.168.2.231.1.1.1
                                                                Mar 19, 2025 09:00:05.141788006 CET53393001.1.1.1192.168.2.23
                                                                Mar 19, 2025 09:00:06.144642115 CET3666153192.168.2.238.8.4.4
                                                                Mar 19, 2025 09:00:06.316445112 CET53366618.8.4.4192.168.2.23
                                                                Mar 19, 2025 09:00:07.320209980 CET4041753192.168.2.231.0.0.1
                                                                Mar 19, 2025 09:00:07.440294981 CET53404171.0.0.1192.168.2.23
                                                                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                Mar 19, 2025 08:58:04.514594078 CET192.168.2.231.0.0.10xdf2Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:05.647830963 CET192.168.2.231.1.1.10xdf2Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:06.679436922 CET192.168.2.238.8.8.80xdf2Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:07.697613001 CET192.168.2.238.8.8.80xdf2Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:08.716568947 CET192.168.2.231.1.1.10xdf2Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:12.612023115 CET192.168.2.238.8.8.80x2c1bStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:13.631313086 CET192.168.2.238.8.4.40x2c1bStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:14.653311014 CET192.168.2.231.0.0.10x2c1bStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:15.795775890 CET192.168.2.238.8.8.80x2c1bStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:16.828008890 CET192.168.2.238.8.4.40x2c1bStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:20.643419027 CET192.168.2.231.0.0.10x6fa5Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:21.670759916 CET192.168.2.231.0.0.10x6fa5Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:22.797049999 CET192.168.2.238.8.4.40x6fa5Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:23.816819906 CET192.168.2.231.0.0.10x6fa5Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:24.845846891 CET192.168.2.231.0.0.10x6fa5Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:28.757844925 CET192.168.2.238.8.8.80x2c37Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:29.777415991 CET192.168.2.238.8.4.40x2c37Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:30.809678078 CET192.168.2.231.0.0.10x2c37Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:31.951345921 CET192.168.2.238.8.8.80x2c37Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:32.971741915 CET192.168.2.231.1.1.10x2c37Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:36.801345110 CET192.168.2.231.1.1.10xa15aStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:37.830132961 CET192.168.2.238.8.4.40xa15aStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:38.850064993 CET192.168.2.238.8.8.80xa15aStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:39.869695902 CET192.168.2.238.8.8.80xa15aStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:40.890527964 CET192.168.2.231.0.0.10xa15aStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:44.707828045 CET192.168.2.231.0.0.10x2d27Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:45.736682892 CET192.168.2.238.8.4.40x2d27Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:46.756328106 CET192.168.2.238.8.4.40x2d27Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:47.790503025 CET192.168.2.238.8.8.80x2d27Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:48.809432983 CET192.168.2.231.1.1.10x2d27Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:52.755320072 CET192.168.2.231.0.0.10x90aStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:53.785341978 CET192.168.2.231.1.1.10x90aStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:54.814136982 CET192.168.2.231.0.0.10x90aStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:55.844333887 CET192.168.2.231.0.0.10x90aStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:58:56.872648954 CET192.168.2.238.8.8.80x90aStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:00.712656021 CET192.168.2.238.8.8.80x2c41Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:01.748122931 CET192.168.2.238.8.8.80x2c41Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:02.781964064 CET192.168.2.238.8.8.80x2c41Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:03.803663015 CET192.168.2.231.1.1.10x2c41Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:04.834784985 CET192.168.2.231.0.0.10x2c41Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:08.660430908 CET192.168.2.231.1.1.10xc873Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:09.766482115 CET192.168.2.238.8.4.40xc873Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:10.785809040 CET192.168.2.238.8.8.80xc873Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:11.806528091 CET192.168.2.238.8.8.80xc873Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:12.824522972 CET192.168.2.231.0.0.10xc873Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:16.768461943 CET192.168.2.238.8.8.80x5931Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:17.800621986 CET192.168.2.238.8.4.40x5931Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:18.818430901 CET192.168.2.231.0.0.10x5931Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:19.959270000 CET192.168.2.231.0.0.10x5931Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:20.986888885 CET192.168.2.238.8.8.80x5931Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:24.789271116 CET192.168.2.231.0.0.10xd6d8Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:25.818000078 CET192.168.2.238.8.4.40xd6d8Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:26.837384939 CET192.168.2.231.0.0.10xd6d8Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:28.050328970 CET192.168.2.238.8.4.40xd6d8Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:29.082339048 CET192.168.2.231.0.0.10xd6d8Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:32.925936937 CET192.168.2.238.8.8.80x8746Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:33.949692965 CET192.168.2.238.8.4.40x8746Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:34.969914913 CET192.168.2.238.8.4.40x8746Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:35.993438005 CET192.168.2.238.8.8.80x8746Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:37.012403965 CET192.168.2.231.1.1.10x8746Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:40.927067041 CET192.168.2.231.1.1.10xfc0cStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:42.036343098 CET192.168.2.231.1.1.10xfc0cStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:43.164158106 CET192.168.2.238.8.8.80xfc0cStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:44.182858944 CET192.168.2.238.8.4.40xfc0cStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:45.213830948 CET192.168.2.238.8.4.40xfc0cStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:49.038265944 CET192.168.2.238.8.4.40x5667Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:50.058180094 CET192.168.2.238.8.4.40x5667Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:51.078845978 CET192.168.2.231.0.0.10x5667Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:52.108438969 CET192.168.2.231.1.1.10x5667Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:53.138911009 CET192.168.2.238.8.4.40x5667Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:56.977950096 CET192.168.2.231.1.1.10x40bcStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:58.006743908 CET192.168.2.231.0.0.10x40bcStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 08:59:59.059317112 CET192.168.2.231.1.1.10x40bcStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 09:00:00.087760925 CET192.168.2.231.1.1.10x40bcStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 09:00:01.212755919 CET192.168.2.231.0.0.10x40bcStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 09:00:05.021330118 CET192.168.2.231.1.1.10x6dfdStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 09:00:06.144642115 CET192.168.2.238.8.4.40x6dfdStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 19, 2025 09:00:07.320209980 CET192.168.2.231.0.0.10x6dfdStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                Mar 19, 2025 08:58:04.638020039 CET1.0.0.1192.168.2.230xdf2Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:05.674372911 CET1.1.1.1192.168.2.230xdf2Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:06.694658995 CET8.8.8.8192.168.2.230xdf2Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:07.712959051 CET8.8.8.8192.168.2.230xdf2Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:08.822300911 CET1.1.1.1192.168.2.230xdf2Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:12.628179073 CET8.8.8.8192.168.2.230x2c1bName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:13.646677017 CET8.8.4.4192.168.2.230x2c1bName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:14.791577101 CET1.0.0.1192.168.2.230x2c1bName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:15.824673891 CET8.8.8.8192.168.2.230x2c1bName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:16.843574047 CET8.8.4.4192.168.2.230x2c1bName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:20.667754889 CET1.0.0.1192.168.2.230x6fa5Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:21.792846918 CET1.0.0.1192.168.2.230x6fa5Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:22.812958002 CET8.8.4.4192.168.2.230x6fa5Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:23.841618061 CET1.0.0.1192.168.2.230x6fa5Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:24.956720114 CET1.0.0.1192.168.2.230x6fa5Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:28.773839951 CET8.8.8.8192.168.2.230x2c37Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:29.805685043 CET8.8.4.4192.168.2.230x2c37Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:30.947248936 CET1.0.0.1192.168.2.230x2c37Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:31.967448950 CET8.8.8.8192.168.2.230x2c37Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:32.998972893 CET1.1.1.1192.168.2.230x2c37Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:36.826153040 CET1.1.1.1192.168.2.230xa15aName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:37.845865011 CET8.8.4.4192.168.2.230xa15aName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:38.865853071 CET8.8.8.8192.168.2.230xa15aName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:39.884566069 CET8.8.8.8192.168.2.230xa15aName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:40.915637016 CET1.0.0.1192.168.2.230xa15aName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:44.732654095 CET1.0.0.1192.168.2.230x2d27Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:45.751837969 CET8.8.4.4192.168.2.230x2d27Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:46.785569906 CET8.8.4.4192.168.2.230x2d27Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:47.805401087 CET8.8.8.8192.168.2.230x2d27Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:48.947081089 CET1.1.1.1192.168.2.230x2d27Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:52.781833887 CET1.0.0.1192.168.2.230x90aName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:53.810746908 CET1.1.1.1192.168.2.230x90aName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:54.839596033 CET1.0.0.1192.168.2.230x90aName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:55.868555069 CET1.0.0.1192.168.2.230x90aName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:58:56.887609959 CET8.8.8.8192.168.2.230x90aName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:00.741863012 CET8.8.8.8192.168.2.230x2c41Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:01.776393890 CET8.8.8.8192.168.2.230x2c41Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:02.797117949 CET8.8.8.8192.168.2.230x2c41Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:03.829236984 CET1.1.1.1192.168.2.230x2c41Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:04.859519958 CET1.0.0.1192.168.2.230x2c41Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:08.762463093 CET1.1.1.1192.168.2.230xc873Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:09.781441927 CET8.8.4.4192.168.2.230xc873Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:10.801830053 CET8.8.8.8192.168.2.230xc873Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:11.821618080 CET8.8.8.8192.168.2.230xc873Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:12.965039968 CET1.0.0.1192.168.2.230xc873Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:16.797204971 CET8.8.8.8192.168.2.230x5931Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:17.815371037 CET8.8.4.4192.168.2.230x5931Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:18.955737114 CET1.0.0.1192.168.2.230x5931Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:19.984297991 CET1.0.0.1192.168.2.230x5931Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:21.002429962 CET8.8.8.8192.168.2.230x5931Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:24.814414024 CET1.0.0.1192.168.2.230xd6d8Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:25.833904982 CET8.8.4.4192.168.2.230xd6d8Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:27.046916962 CET1.0.0.1192.168.2.230xd6d8Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:28.078623056 CET8.8.4.4192.168.2.230xd6d8Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:29.110620975 CET1.0.0.1192.168.2.230xd6d8Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:32.944523096 CET8.8.8.8192.168.2.230x8746Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:33.965709925 CET8.8.4.4192.168.2.230x8746Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:34.989775896 CET8.8.4.4192.168.2.230x8746Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:36.009005070 CET8.8.8.8192.168.2.230x8746Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:37.133446932 CET1.1.1.1192.168.2.230x8746Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:41.031443119 CET1.1.1.1192.168.2.230xfc0cName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:42.160058975 CET1.1.1.1192.168.2.230xfc0cName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:43.179734945 CET8.8.8.8192.168.2.230xfc0cName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:44.210894108 CET8.8.4.4192.168.2.230xfc0cName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:45.242981911 CET8.8.4.4192.168.2.230xfc0cName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:49.053762913 CET8.8.4.4192.168.2.230x5667Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:50.073973894 CET8.8.4.4192.168.2.230x5667Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:51.104372978 CET1.0.0.1192.168.2.230x5667Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:52.134181976 CET1.1.1.1192.168.2.230x5667Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:53.168391943 CET8.8.4.4192.168.2.230x5667Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:57.002288103 CET1.1.1.1192.168.2.230x40bcName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:58.055218935 CET1.0.0.1192.168.2.230x40bcName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 08:59:59.083849907 CET1.1.1.1192.168.2.230x40bcName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 09:00:00.208543062 CET1.1.1.1192.168.2.230x40bcName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 09:00:01.238260984 CET1.0.0.1192.168.2.230x40bcName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 09:00:05.141788006 CET1.1.1.1192.168.2.230x6dfdName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 09:00:06.316445112 CET8.8.4.4192.168.2.230x6dfdName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 19, 2025 09:00:07.440294981 CET1.0.0.1192.168.2.230x6dfdName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false

                                                                System Behavior

                                                                Start time (UTC):07:58:03
                                                                Start date (UTC):19/03/2025
                                                                Path:/tmp/sync.arm4.elf
                                                                Arguments:/tmp/sync.arm4.elf
                                                                File size:4956856 bytes
                                                                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                Start time (UTC):07:58:03
                                                                Start date (UTC):19/03/2025
                                                                Path:/tmp/sync.arm4.elf
                                                                Arguments:-
                                                                File size:4956856 bytes
                                                                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                Start time (UTC):07:58:03
                                                                Start date (UTC):19/03/2025
                                                                Path:/tmp/sync.arm4.elf
                                                                Arguments:-
                                                                File size:4956856 bytes
                                                                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1