Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
tarm7.elf

Overview

General Information

Sample name:tarm7.elf
Analysis ID:1544639
MD5:283d2c9be4cca2978d131da65bf2050a
SHA1:92a9573b2ae418de74aab13e1cfe0943db899b8d
SHA256:2f5aebc64c61a50611cab64894853fdb96d2b1468abb4c82d58b5e4a96bc88d6
Tags:elfuser-abuse_ch
Infos:

Detection

Score:80
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Connects to many ports of the same IP (likely port scanning)
Sample reads /proc/mounts (often used for finding a writable filesystem)
Sample scans a subnet
Sends malformed DNS queries
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1544639
Start date and time:2024-10-29 16:56:08 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 43s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:tarm7.elf
Detection:MAL
Classification:mal80.spre.troj.linELF@0/0@35/0
  • VT rate limit hit for: tarm7.elf
Command:/tmp/tarm7.elf
PID:5497
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
All the china banks
Standard Error:
  • system is lnxubuntu20
  • tarm7.elf (PID: 5497, Parent: 5424, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/tarm7.elf
  • cleanup
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2024-10-29T16:57:00.166894+010020500661A Network Trojan was detected192.168.2.153802046.23.108.5824272TCP
2024-10-29T16:57:05.929893+010020500661A Network Trojan was detected192.168.2.154274646.23.108.2524840TCP
2024-10-29T16:57:26.727421+010020500661A Network Trojan was detected192.168.2.154274846.23.108.2524840TCP
2024-10-29T16:57:42.693304+010020500661A Network Trojan was detected192.168.2.154275046.23.108.2524840TCP
2024-10-29T16:57:48.459337+010020500661A Network Trojan was detected192.168.2.154125446.23.108.1092654TCP
2024-10-29T16:57:59.266172+010020500661A Network Trojan was detected192.168.2.154125646.23.108.1092654TCP
2024-10-29T16:58:11.076413+010020500661A Network Trojan was detected192.168.2.154476246.23.108.6421693TCP
2024-10-29T16:58:21.843805+010020500661A Network Trojan was detected192.168.2.155128046.23.108.552410TCP
2024-10-29T16:58:32.630230+010020500661A Network Trojan was detected192.168.2.153863446.23.108.6217532TCP
2024-10-29T16:58:43.406621+010020500661A Network Trojan was detected192.168.2.154426646.23.108.544051TCP
2024-10-29T16:58:49.427772+010020500661A Network Trojan was detected192.168.2.154168646.23.108.15922438TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: tarm7.elfAvira: detected
Source: tarm7.elfReversingLabs: Detection: 31%

Networking

barindex
Source: Network trafficSuricata IDS: 2050066 - Severity 1 - ET MALWARE Hailbot CnC Checkin : 192.168.2.15:42748 -> 46.23.108.252:4840
Source: Network trafficSuricata IDS: 2050066 - Severity 1 - ET MALWARE Hailbot CnC Checkin : 192.168.2.15:38020 -> 46.23.108.58:24272
Source: Network trafficSuricata IDS: 2050066 - Severity 1 - ET MALWARE Hailbot CnC Checkin : 192.168.2.15:51280 -> 46.23.108.55:2410
Source: Network trafficSuricata IDS: 2050066 - Severity 1 - ET MALWARE Hailbot CnC Checkin : 192.168.2.15:41254 -> 46.23.108.109:2654
Source: Network trafficSuricata IDS: 2050066 - Severity 1 - ET MALWARE Hailbot CnC Checkin : 192.168.2.15:42750 -> 46.23.108.252:4840
Source: Network trafficSuricata IDS: 2050066 - Severity 1 - ET MALWARE Hailbot CnC Checkin : 192.168.2.15:41686 -> 46.23.108.159:22438
Source: Network trafficSuricata IDS: 2050066 - Severity 1 - ET MALWARE Hailbot CnC Checkin : 192.168.2.15:42746 -> 46.23.108.252:4840
Source: Network trafficSuricata IDS: 2050066 - Severity 1 - ET MALWARE Hailbot CnC Checkin : 192.168.2.15:44762 -> 46.23.108.64:21693
Source: Network trafficSuricata IDS: 2050066 - Severity 1 - ET MALWARE Hailbot CnC Checkin : 192.168.2.15:38634 -> 46.23.108.62:17532
Source: Network trafficSuricata IDS: 2050066 - Severity 1 - ET MALWARE Hailbot CnC Checkin : 192.168.2.15:44266 -> 46.23.108.54:4051
Source: Network trafficSuricata IDS: 2050066 - Severity 1 - ET MALWARE Hailbot CnC Checkin : 192.168.2.15:41256 -> 46.23.108.109:2654
Source: global trafficTCP traffic: 46.23.108.62 ports 17532,1,2,3,5,7
Source: global trafficTCP traffic: 46.23.108.64 ports 21693,1,2,3,6,9
Source: ip trafficSubnet 46.23.108.0/24: 46.23.108.58, 46.23.108.109, 46.23.108.62, 46.23.108.54, 46.23.108.64, 46.23.108.55, 46.23.108.252, 46.23.108.159
Source: global trafficDNS traffic detected: malformed DNS query: repo.dyn. [malformed]
Source: global trafficDNS traffic detected: malformed DNS query: sandmen.geek. [malformed]
Source: global trafficDNS traffic detected: malformed DNS query: sliteyed.pirate. [malformed]
Source: global trafficTCP traffic: 192.168.2.15:38020 -> 46.23.108.58:24272
Source: global trafficTCP traffic: 192.168.2.15:42746 -> 46.23.108.252:4840
Source: global trafficTCP traffic: 192.168.2.15:41254 -> 46.23.108.109:2654
Source: global trafficTCP traffic: 192.168.2.15:44762 -> 46.23.108.64:21693
Source: global trafficTCP traffic: 192.168.2.15:51280 -> 46.23.108.55:2410
Source: global trafficTCP traffic: 192.168.2.15:38634 -> 46.23.108.62:17532
Source: global trafficTCP traffic: 192.168.2.15:44266 -> 46.23.108.54:4051
Source: global trafficTCP traffic: 192.168.2.15:41686 -> 46.23.108.159:22438
Source: /tmp/tarm7.elf (PID: 5497)Socket: 127.0.0.1:1172Jump to behavior
Source: unknownUDP traffic detected without corresponding DNS query: 64.176.6.48
Source: unknownUDP traffic detected without corresponding DNS query: 64.176.6.48
Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
Source: unknownUDP traffic detected without corresponding DNS query: 65.21.1.106
Source: unknownUDP traffic detected without corresponding DNS query: 65.21.1.106
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 137.220.52.23
Source: unknownUDP traffic detected without corresponding DNS query: 137.220.52.23
Source: unknownUDP traffic detected without corresponding DNS query: 80.152.203.134
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 80.152.203.134
Source: unknownUDP traffic detected without corresponding DNS query: 168.235.111.72
Source: unknownUDP traffic detected without corresponding DNS query: 168.235.111.72
Source: unknownUDP traffic detected without corresponding DNS query: 5.161.109.23
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 202.61.197.122
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 70.34.254.19
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 70.34.254.19
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 202.61.197.122
Source: unknownUDP traffic detected without corresponding DNS query: 139.84.165.176
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 202.61.197.122
Source: unknownUDP traffic detected without corresponding DNS query: 64.176.6.48
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 152.53.15.127
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 65.21.1.106
Source: global trafficDNS traffic detected: DNS query: dingdingrouter.pirate
Source: global trafficDNS traffic detected: DNS query: repo.dyn. [malformed]
Source: global trafficDNS traffic detected: DNS query: sandmen.geek
Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
Source: global trafficDNS traffic detected: DNS query: sliteyed.pirate
Source: global trafficDNS traffic detected: DNS query: sandmen.geek. [malformed]
Source: global trafficDNS traffic detected: DNS query: sliteyed.pirate. [malformed]
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal80.spre.troj.linELF@0/0@35/0

Persistence and Installation Behavior

barindex
Source: /tmp/tarm7.elf (PID: 5499)File: /proc/5499/mountsJump to behavior
Source: /tmp/tarm7.elf (PID: 5497)Queries kernel information via 'uname': Jump to behavior
Source: tarm7.elf, 5497.1.000056073018e000.0000560730305000.rw-.sdmp, tarm7.elf, 5499.1.000056073018e000.0000560730305000.rw-.sdmp, tarm7.elf, 5504.1.000056073018e000.0000560730305000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: tarm7.elf, 5497.1.000056073018e000.0000560730305000.rw-.sdmp, tarm7.elf, 5499.1.000056073018e000.0000560730305000.rw-.sdmp, tarm7.elf, 5504.1.000056073018e000.0000560730305000.rw-.sdmpBinary or memory string: V!/etc/qemu-binfmt/arm
Source: tarm7.elf, 5497.1.00007ffeb7d6c000.00007ffeb7d8d000.rw-.sdmp, tarm7.elf, 5499.1.00007ffeb7d6c000.00007ffeb7d8d000.rw-.sdmp, tarm7.elf, 5504.1.00007ffeb7d6c000.00007ffeb7d8d000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: tarm7.elf, 5504.1.00007ffeb7d6c000.00007ffeb7d8d000.rw-.sdmpBinary or memory string: qemu: uncaught target signal 11 (Segmentation fault) - core dumped
Source: tarm7.elf, 5497.1.00007ffeb7d6c000.00007ffeb7d8d000.rw-.sdmp, tarm7.elf, 5499.1.00007ffeb7d6c000.00007ffeb7d8d000.rw-.sdmp, tarm7.elf, 5504.1.00007ffeb7d6c000.00007ffeb7d8d000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/tarm7.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/tarm7.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory1
Network Service Discovery
Remote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account Manager1
File and Directory Discovery
SMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1544639 Sample: tarm7.elf Startdate: 29/10/2024 Architecture: LINUX Score: 80 17 sliteyed.pirate. [malformed] 2->17 19 sandmen.geek. [malformed] 2->19 21 11 other IPs or domains 2->21 23 Suricata IDS alerts for network traffic 2->23 25 Antivirus / Scanner detection for submitted sample 2->25 27 Multi AV Scanner detection for submitted file 2->27 31 2 other signatures 2->31 8 tarm7.elf 2->8         started        signatures3 29 Sends malformed DNS queries 19->29 process4 process5 10 tarm7.elf 8->10         started        13 tarm7.elf 8->13         started        signatures6 33 Sample reads /proc/mounts (often used for finding a writable filesystem) 10->33 15 tarm7.elf 10->15         started        process7

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
tarm7.elf32%ReversingLabsLinux.Backdoor.Mirai
tarm7.elf100%AviraANDROID/AVE.Mirai.ifadn
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
sandmen.geek
46.23.108.161
truetrue
    unknown
    daisy.ubuntu.com
    162.213.35.25
    truefalse
      unknown
      dingdingrouter.pirate
      46.23.108.62
      truetrue
        unknown
        sliteyed.pirate
        46.23.108.58
        truetrue
          unknown
          sliteyed.pirate. [malformed]
          unknown
          unknowntrue
            unknown
            sandmen.geek. [malformed]
            unknown
            unknowntrue
              unknown
              repo.dyn. [malformed]
              unknown
              unknowntrue
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                46.23.108.58
                sliteyed.pirateAzerbaijan
                15723AZERONLINEAZtrue
                46.23.108.109
                unknownAzerbaijan
                15723AZERONLINEAZtrue
                46.23.108.62
                dingdingrouter.pirateAzerbaijan
                15723AZERONLINEAZtrue
                46.23.108.54
                unknownAzerbaijan
                15723AZERONLINEAZtrue
                46.23.108.64
                unknownAzerbaijan
                15723AZERONLINEAZtrue
                46.23.108.55
                unknownAzerbaijan
                15723AZERONLINEAZtrue
                46.23.108.252
                unknownAzerbaijan
                15723AZERONLINEAZtrue
                46.23.108.159
                unknownAzerbaijan
                15723AZERONLINEAZtrue
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                46.23.108.58tarm5.elfGet hashmaliciousUnknownBrowse
                  xmpsl.elfGet hashmaliciousUnknownBrowse
                    ppc.elfGet hashmaliciousUnknownBrowse
                      mpsl.elfGet hashmaliciousUnknownBrowse
                        xmips.elfGet hashmaliciousUnknownBrowse
                          46.23.108.109tarm5.elfGet hashmaliciousUnknownBrowse
                            xmpsl.elfGet hashmaliciousUnknownBrowse
                              xmips.elfGet hashmaliciousUnknownBrowse
                                arm.elfGet hashmaliciousUnknownBrowse
                                  na.elfGet hashmaliciousUnknownBrowse
                                    46.23.108.252tarm5.elfGet hashmaliciousUnknownBrowse
                                      xmpsl.elfGet hashmaliciousUnknownBrowse
                                        x86.elfGet hashmaliciousUnknownBrowse
                                          ppc.elfGet hashmaliciousUnknownBrowse
                                            mpsl.elfGet hashmaliciousUnknownBrowse
                                              46.23.108.62tarm.elfGet hashmaliciousUnknownBrowse
                                                ppc.elfGet hashmaliciousUnknownBrowse
                                                  mpsl.elfGet hashmaliciousUnknownBrowse
                                                    arm.elfGet hashmaliciousUnknownBrowse
                                                      arm7.elfGet hashmaliciousUnknownBrowse
                                                        46.23.108.54tarm5.elfGet hashmaliciousUnknownBrowse
                                                          xmpsl.elfGet hashmaliciousUnknownBrowse
                                                            x86.elfGet hashmaliciousUnknownBrowse
                                                              ppc.elfGet hashmaliciousUnknownBrowse
                                                                arm.elfGet hashmaliciousUnknownBrowse
                                                                  arm7.elfGet hashmaliciousUnknownBrowse
                                                                    46.23.108.64tarm5.elfGet hashmaliciousUnknownBrowse
                                                                      xmpsl.elfGet hashmaliciousUnknownBrowse
                                                                        ppc.elfGet hashmaliciousUnknownBrowse
                                                                          mpsl.elfGet hashmaliciousUnknownBrowse
                                                                            arm.elfGet hashmaliciousUnknownBrowse
                                                                              46.23.108.55xmpsl.elfGet hashmaliciousUnknownBrowse
                                                                                tarm.elfGet hashmaliciousUnknownBrowse
                                                                                  ppc.elfGet hashmaliciousUnknownBrowse
                                                                                    mpsl.elfGet hashmaliciousUnknownBrowse
                                                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                      daisy.ubuntu.comgarm.elfGet hashmaliciousMiraiBrowse
                                                                                      • 162.213.35.25
                                                                                      tarm5.elfGet hashmaliciousUnknownBrowse
                                                                                      • 162.213.35.24
                                                                                      tsh4.elfGet hashmaliciousMiraiBrowse
                                                                                      • 162.213.35.24
                                                                                      tel.arm.elfGet hashmaliciousMiraiBrowse
                                                                                      • 162.213.35.24
                                                                                      dwhdbg.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                                                                                      • 162.213.35.25
                                                                                      x86.elfGet hashmaliciousUnknownBrowse
                                                                                      • 162.213.35.25
                                                                                      arm5.elfGet hashmaliciousMiraiBrowse
                                                                                      • 162.213.35.25
                                                                                      ppc.elfGet hashmaliciousUnknownBrowse
                                                                                      • 162.213.35.24
                                                                                      mpsl.elfGet hashmaliciousUnknownBrowse
                                                                                      • 162.213.35.25
                                                                                      zmap.x86_64.elfGet hashmaliciousOkiruBrowse
                                                                                      • 162.213.35.25
                                                                                      dingdingrouter.pirateparm.elfGet hashmaliciousMiraiBrowse
                                                                                      • 46.23.108.64
                                                                                      tel.x86.elfGet hashmaliciousMiraiBrowse
                                                                                      • 46.23.108.159
                                                                                      garm.elfGet hashmaliciousMiraiBrowse
                                                                                      • 46.23.108.133
                                                                                      tarm5.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.65
                                                                                      tsh4.elfGet hashmaliciousMiraiBrowse
                                                                                      • 46.23.108.161
                                                                                      xmpsl.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.61
                                                                                      tel.arm.elfGet hashmaliciousMiraiBrowse
                                                                                      • 46.23.108.111
                                                                                      tarm.elfGet hashmaliciousUnknownBrowse
                                                                                      • 45.148.10.51
                                                                                      parm5.elfGet hashmaliciousMiraiBrowse
                                                                                      • 46.23.108.110
                                                                                      x86.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.159
                                                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                      AZERONLINEAZtarm5.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.252
                                                                                      xmpsl.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.161
                                                                                      tarm.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.133
                                                                                      x86.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.159
                                                                                      ppc.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.161
                                                                                      mpsl.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.161
                                                                                      xmips.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.110
                                                                                      arm.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.111
                                                                                      arm7.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.133
                                                                                      x86.elfGet hashmaliciousMiraiBrowse
                                                                                      • 88.151.195.22
                                                                                      AZERONLINEAZtarm5.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.252
                                                                                      xmpsl.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.161
                                                                                      tarm.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.133
                                                                                      x86.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.159
                                                                                      ppc.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.161
                                                                                      mpsl.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.161
                                                                                      xmips.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.110
                                                                                      arm.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.111
                                                                                      arm7.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.133
                                                                                      x86.elfGet hashmaliciousMiraiBrowse
                                                                                      • 88.151.195.22
                                                                                      AZERONLINEAZtarm5.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.252
                                                                                      xmpsl.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.161
                                                                                      tarm.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.133
                                                                                      x86.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.159
                                                                                      ppc.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.161
                                                                                      mpsl.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.161
                                                                                      xmips.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.110
                                                                                      arm.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.111
                                                                                      arm7.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.133
                                                                                      x86.elfGet hashmaliciousMiraiBrowse
                                                                                      • 88.151.195.22
                                                                                      AZERONLINEAZtarm5.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.252
                                                                                      xmpsl.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.161
                                                                                      tarm.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.133
                                                                                      x86.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.159
                                                                                      ppc.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.161
                                                                                      mpsl.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.161
                                                                                      xmips.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.110
                                                                                      arm.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.111
                                                                                      arm7.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.133
                                                                                      x86.elfGet hashmaliciousMiraiBrowse
                                                                                      • 88.151.195.22
                                                                                      AZERONLINEAZtarm5.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.252
                                                                                      xmpsl.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.161
                                                                                      tarm.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.133
                                                                                      x86.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.159
                                                                                      ppc.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.161
                                                                                      mpsl.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.161
                                                                                      xmips.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.110
                                                                                      arm.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.111
                                                                                      arm7.elfGet hashmaliciousUnknownBrowse
                                                                                      • 46.23.108.133
                                                                                      x86.elfGet hashmaliciousMiraiBrowse
                                                                                      • 88.151.195.22
                                                                                      No context
                                                                                      No context
                                                                                      No created / dropped files found
                                                                                      File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
                                                                                      Entropy (8bit):6.1581914664695825
                                                                                      TrID:
                                                                                      • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                                      File name:tarm7.elf
                                                                                      File size:95'444 bytes
                                                                                      MD5:283d2c9be4cca2978d131da65bf2050a
                                                                                      SHA1:92a9573b2ae418de74aab13e1cfe0943db899b8d
                                                                                      SHA256:2f5aebc64c61a50611cab64894853fdb96d2b1468abb4c82d58b5e4a96bc88d6
                                                                                      SHA512:47749cbc970315487f522939d8d1d815c9616b857d85815c02d0227c8c590bc5085b4a46596d4f5d6fc24da47d4bbad465ab6e684e13a34c17a1151aa7a9bf7e
                                                                                      SSDEEP:1536:aKnAmvUH5/4/ANaTa35zv8a79dlPoiKO1GCqFHZJYHx/CYdP:qR4/saTa35zv3YO1GCqFHby/CqP
                                                                                      TLSH:2A931946B9819F12D4C631BAFBAE414933136FBDD3FA7101D920AF6027CA9DB0E76512
                                                                                      File Content Preview:.ELF..............(.........4....r......4. ...(........pl`..l...l....................................a...a...............a...a...a......(a...............a...a...a..................Q.td..................................-...L..................@-.,@...0....S

                                                                                      ELF header

                                                                                      Class:ELF32
                                                                                      Data:2's complement, little endian
                                                                                      Version:1 (current)
                                                                                      Machine:ARM
                                                                                      Version Number:0x1
                                                                                      Type:EXEC (Executable file)
                                                                                      OS/ABI:UNIX - System V
                                                                                      ABI Version:0
                                                                                      Entry Point Address:0x8194
                                                                                      Flags:0x4000002
                                                                                      ELF Header Size:52
                                                                                      Program Header Offset:52
                                                                                      Program Header Size:32
                                                                                      Number of Program Headers:5
                                                                                      Section Header Offset:94724
                                                                                      Section Header Size:40
                                                                                      Number of Section Headers:18
                                                                                      Header String Table Index:17
                                                                                      NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                                      NULL0x00x00x00x00x0000
                                                                                      .initPROGBITS0x80d40xd40x100x00x6AX004
                                                                                      .textPROGBITS0x80f00xf00x1477c0x00x6AX0016
                                                                                      .finiPROGBITS0x1c86c0x1486c0x100x00x6AX004
                                                                                      .rodataPROGBITS0x1c8800x148800x17d40x00x2A008
                                                                                      .ARM.extabPROGBITS0x1e0540x160540x180x00x2A004
                                                                                      .ARM.exidxARM_EXIDX0x1e06c0x1606c0x1180x00x82AL204
                                                                                      .eh_framePROGBITS0x261840x161840x40x00x3WA004
                                                                                      .tbssNOBITS0x261880x161880x80x00x403WAT004
                                                                                      .init_arrayINIT_ARRAY0x261880x161880x40x00x3WA004
                                                                                      .fini_arrayFINI_ARRAY0x2618c0x1618c0x40x00x3WA004
                                                                                      .jcrPROGBITS0x261900x161900x40x00x3WA004
                                                                                      .gotPROGBITS0x261940x161940xa80x40x3WA004
                                                                                      .dataPROGBITS0x2623c0x1623c0x22c0x00x3WA004
                                                                                      .bssNOBITS0x264680x164680x5e440x00x3WA004
                                                                                      .commentPROGBITS0x00x164680xcf40x00x0001
                                                                                      .ARM.attributesARM_ATTRIBUTES0x00x1715c0x160x00x0001
                                                                                      .shstrtabSTRTAB0x00x171720x910x00x0001
                                                                                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                      EXIDX0x1606c0x1e06c0x1e06c0x1180x1184.49440x4R 0x4.ARM.exidx
                                                                                      LOAD0x00x80000x80000x161840x161846.12500x5R E0x8000.init .text .fini .rodata .ARM.extab .ARM.exidx
                                                                                      LOAD0x161840x261840x261840x2e40x61284.09700x6RW 0x8000.eh_frame .tbss .init_array .fini_array .jcr .got .data .bss
                                                                                      TLS0x161880x261880x261880x00x80.00000x4R 0x4.tbss
                                                                                      GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                                                      TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                                                      2024-10-29T16:57:00.166894+01002050066ET MALWARE Hailbot CnC Checkin1192.168.2.153802046.23.108.5824272TCP
                                                                                      2024-10-29T16:57:05.929893+01002050066ET MALWARE Hailbot CnC Checkin1192.168.2.154274646.23.108.2524840TCP
                                                                                      2024-10-29T16:57:26.727421+01002050066ET MALWARE Hailbot CnC Checkin1192.168.2.154274846.23.108.2524840TCP
                                                                                      2024-10-29T16:57:42.693304+01002050066ET MALWARE Hailbot CnC Checkin1192.168.2.154275046.23.108.2524840TCP
                                                                                      2024-10-29T16:57:48.459337+01002050066ET MALWARE Hailbot CnC Checkin1192.168.2.154125446.23.108.1092654TCP
                                                                                      2024-10-29T16:57:59.266172+01002050066ET MALWARE Hailbot CnC Checkin1192.168.2.154125646.23.108.1092654TCP
                                                                                      2024-10-29T16:58:11.076413+01002050066ET MALWARE Hailbot CnC Checkin1192.168.2.154476246.23.108.6421693TCP
                                                                                      2024-10-29T16:58:21.843805+01002050066ET MALWARE Hailbot CnC Checkin1192.168.2.155128046.23.108.552410TCP
                                                                                      2024-10-29T16:58:32.630230+01002050066ET MALWARE Hailbot CnC Checkin1192.168.2.153863446.23.108.6217532TCP
                                                                                      2024-10-29T16:58:43.406621+01002050066ET MALWARE Hailbot CnC Checkin1192.168.2.154426646.23.108.544051TCP
                                                                                      2024-10-29T16:58:49.427772+01002050066ET MALWARE Hailbot CnC Checkin1192.168.2.154168646.23.108.15922438TCP
                                                                                      TimestampSource PortDest PortSource IPDest IP
                                                                                      Oct 29, 2024 16:57:00.159387112 CET3802024272192.168.2.1546.23.108.58
                                                                                      Oct 29, 2024 16:57:00.166594982 CET242723802046.23.108.58192.168.2.15
                                                                                      Oct 29, 2024 16:57:00.166753054 CET3802024272192.168.2.1546.23.108.58
                                                                                      Oct 29, 2024 16:57:00.166893959 CET3802024272192.168.2.1546.23.108.58
                                                                                      Oct 29, 2024 16:57:00.173248053 CET242723802046.23.108.58192.168.2.15
                                                                                      Oct 29, 2024 16:57:00.173324108 CET3802024272192.168.2.1546.23.108.58
                                                                                      Oct 29, 2024 16:57:00.179512978 CET242723802046.23.108.58192.168.2.15
                                                                                      Oct 29, 2024 16:57:00.902609110 CET242723802046.23.108.58192.168.2.15
                                                                                      Oct 29, 2024 16:57:00.902968884 CET3802024272192.168.2.1546.23.108.58
                                                                                      Oct 29, 2024 16:57:00.908845901 CET242723802046.23.108.58192.168.2.15
                                                                                      Oct 29, 2024 16:57:05.924048901 CET427464840192.168.2.1546.23.108.252
                                                                                      Oct 29, 2024 16:57:05.929625988 CET48404274646.23.108.252192.168.2.15
                                                                                      Oct 29, 2024 16:57:05.929686069 CET427464840192.168.2.1546.23.108.252
                                                                                      Oct 29, 2024 16:57:05.929893017 CET427464840192.168.2.1546.23.108.252
                                                                                      Oct 29, 2024 16:57:05.935209036 CET48404274646.23.108.252192.168.2.15
                                                                                      Oct 29, 2024 16:57:05.935331106 CET427464840192.168.2.1546.23.108.252
                                                                                      Oct 29, 2024 16:57:05.940839052 CET48404274646.23.108.252192.168.2.15
                                                                                      Oct 29, 2024 16:57:06.670619965 CET48404274646.23.108.252192.168.2.15
                                                                                      Oct 29, 2024 16:57:06.671094894 CET427464840192.168.2.1546.23.108.252
                                                                                      Oct 29, 2024 16:57:06.678869009 CET48404274646.23.108.252192.168.2.15
                                                                                      Oct 29, 2024 16:57:26.721544981 CET427484840192.168.2.1546.23.108.252
                                                                                      Oct 29, 2024 16:57:26.727334023 CET48404274846.23.108.252192.168.2.15
                                                                                      Oct 29, 2024 16:57:26.727401972 CET427484840192.168.2.1546.23.108.252
                                                                                      Oct 29, 2024 16:57:26.727421045 CET427484840192.168.2.1546.23.108.252
                                                                                      Oct 29, 2024 16:57:26.733383894 CET48404274846.23.108.252192.168.2.15
                                                                                      Oct 29, 2024 16:57:26.733428001 CET427484840192.168.2.1546.23.108.252
                                                                                      Oct 29, 2024 16:57:26.739213943 CET48404274846.23.108.252192.168.2.15
                                                                                      Oct 29, 2024 16:57:27.450797081 CET48404274846.23.108.252192.168.2.15
                                                                                      Oct 29, 2024 16:57:27.451253891 CET427484840192.168.2.1546.23.108.252
                                                                                      Oct 29, 2024 16:57:27.456820965 CET48404274846.23.108.252192.168.2.15
                                                                                      Oct 29, 2024 16:57:42.687720060 CET427504840192.168.2.1546.23.108.252
                                                                                      Oct 29, 2024 16:57:42.693166018 CET48404275046.23.108.252192.168.2.15
                                                                                      Oct 29, 2024 16:57:42.693248034 CET427504840192.168.2.1546.23.108.252
                                                                                      Oct 29, 2024 16:57:42.693304062 CET427504840192.168.2.1546.23.108.252
                                                                                      Oct 29, 2024 16:57:42.698769093 CET48404275046.23.108.252192.168.2.15
                                                                                      Oct 29, 2024 16:57:42.698832035 CET427504840192.168.2.1546.23.108.252
                                                                                      Oct 29, 2024 16:57:42.704222918 CET48404275046.23.108.252192.168.2.15
                                                                                      Oct 29, 2024 16:57:43.420509100 CET48404275046.23.108.252192.168.2.15
                                                                                      Oct 29, 2024 16:57:43.420823097 CET427504840192.168.2.1546.23.108.252
                                                                                      Oct 29, 2024 16:57:43.426172018 CET48404275046.23.108.252192.168.2.15
                                                                                      Oct 29, 2024 16:57:48.453775883 CET412542654192.168.2.1546.23.108.109
                                                                                      Oct 29, 2024 16:57:48.459160089 CET26544125446.23.108.109192.168.2.15
                                                                                      Oct 29, 2024 16:57:48.459295034 CET412542654192.168.2.1546.23.108.109
                                                                                      Oct 29, 2024 16:57:48.459336996 CET412542654192.168.2.1546.23.108.109
                                                                                      Oct 29, 2024 16:57:48.464724064 CET26544125446.23.108.109192.168.2.15
                                                                                      Oct 29, 2024 16:57:48.464818001 CET412542654192.168.2.1546.23.108.109
                                                                                      Oct 29, 2024 16:57:48.470168114 CET26544125446.23.108.109192.168.2.15
                                                                                      Oct 29, 2024 16:57:49.183907986 CET26544125446.23.108.109192.168.2.15
                                                                                      Oct 29, 2024 16:57:49.184456110 CET412542654192.168.2.1546.23.108.109
                                                                                      Oct 29, 2024 16:57:49.189892054 CET26544125446.23.108.109192.168.2.15
                                                                                      Oct 29, 2024 16:57:59.260651112 CET412562654192.168.2.1546.23.108.109
                                                                                      Oct 29, 2024 16:57:59.266057968 CET26544125646.23.108.109192.168.2.15
                                                                                      Oct 29, 2024 16:57:59.266134024 CET412562654192.168.2.1546.23.108.109
                                                                                      Oct 29, 2024 16:57:59.266171932 CET412562654192.168.2.1546.23.108.109
                                                                                      Oct 29, 2024 16:57:59.271641970 CET26544125646.23.108.109192.168.2.15
                                                                                      Oct 29, 2024 16:57:59.271704912 CET412562654192.168.2.1546.23.108.109
                                                                                      Oct 29, 2024 16:57:59.277091980 CET26544125646.23.108.109192.168.2.15
                                                                                      Oct 29, 2024 16:57:59.986885071 CET26544125646.23.108.109192.168.2.15
                                                                                      Oct 29, 2024 16:57:59.987287998 CET412562654192.168.2.1546.23.108.109
                                                                                      Oct 29, 2024 16:57:59.992717981 CET26544125646.23.108.109192.168.2.15
                                                                                      Oct 29, 2024 16:58:11.067945957 CET4476221693192.168.2.1546.23.108.64
                                                                                      Oct 29, 2024 16:58:11.076301098 CET216934476246.23.108.64192.168.2.15
                                                                                      Oct 29, 2024 16:58:11.076400042 CET4476221693192.168.2.1546.23.108.64
                                                                                      Oct 29, 2024 16:58:11.076412916 CET4476221693192.168.2.1546.23.108.64
                                                                                      Oct 29, 2024 16:58:11.082123041 CET216934476246.23.108.64192.168.2.15
                                                                                      Oct 29, 2024 16:58:11.082190990 CET4476221693192.168.2.1546.23.108.64
                                                                                      Oct 29, 2024 16:58:11.087470055 CET216934476246.23.108.64192.168.2.15
                                                                                      Oct 29, 2024 16:58:11.799185038 CET216934476246.23.108.64192.168.2.15
                                                                                      Oct 29, 2024 16:58:11.799665928 CET4476221693192.168.2.1546.23.108.64
                                                                                      Oct 29, 2024 16:58:11.805126905 CET216934476246.23.108.64192.168.2.15
                                                                                      Oct 29, 2024 16:58:21.837389946 CET512802410192.168.2.1546.23.108.55
                                                                                      Oct 29, 2024 16:58:21.843664885 CET24105128046.23.108.55192.168.2.15
                                                                                      Oct 29, 2024 16:58:21.843749046 CET512802410192.168.2.1546.23.108.55
                                                                                      Oct 29, 2024 16:58:21.843805075 CET512802410192.168.2.1546.23.108.55
                                                                                      Oct 29, 2024 16:58:21.849585056 CET24105128046.23.108.55192.168.2.15
                                                                                      Oct 29, 2024 16:58:21.849666119 CET512802410192.168.2.1546.23.108.55
                                                                                      Oct 29, 2024 16:58:21.855180025 CET24105128046.23.108.55192.168.2.15
                                                                                      Oct 29, 2024 16:58:22.565543890 CET24105128046.23.108.55192.168.2.15
                                                                                      Oct 29, 2024 16:58:22.565989017 CET512802410192.168.2.1546.23.108.55
                                                                                      Oct 29, 2024 16:58:22.571454048 CET24105128046.23.108.55192.168.2.15
                                                                                      Oct 29, 2024 16:58:32.624747992 CET3863417532192.168.2.1546.23.108.62
                                                                                      Oct 29, 2024 16:58:32.630117893 CET175323863446.23.108.62192.168.2.15
                                                                                      Oct 29, 2024 16:58:32.630193949 CET3863417532192.168.2.1546.23.108.62
                                                                                      Oct 29, 2024 16:58:32.630229950 CET3863417532192.168.2.1546.23.108.62
                                                                                      Oct 29, 2024 16:58:32.635976076 CET175323863446.23.108.62192.168.2.15
                                                                                      Oct 29, 2024 16:58:32.636077881 CET3863417532192.168.2.1546.23.108.62
                                                                                      Oct 29, 2024 16:58:32.641535044 CET175323863446.23.108.62192.168.2.15
                                                                                      Oct 29, 2024 16:58:33.349940062 CET175323863446.23.108.62192.168.2.15
                                                                                      Oct 29, 2024 16:58:33.350251913 CET3863417532192.168.2.1546.23.108.62
                                                                                      Oct 29, 2024 16:58:33.355726957 CET175323863446.23.108.62192.168.2.15
                                                                                      Oct 29, 2024 16:58:43.401026011 CET442664051192.168.2.1546.23.108.54
                                                                                      Oct 29, 2024 16:58:43.406470060 CET40514426646.23.108.54192.168.2.15
                                                                                      Oct 29, 2024 16:58:43.406589985 CET442664051192.168.2.1546.23.108.54
                                                                                      Oct 29, 2024 16:58:43.406620979 CET442664051192.168.2.1546.23.108.54
                                                                                      Oct 29, 2024 16:58:43.412009954 CET40514426646.23.108.54192.168.2.15
                                                                                      Oct 29, 2024 16:58:43.412065029 CET442664051192.168.2.1546.23.108.54
                                                                                      Oct 29, 2024 16:58:43.417437077 CET40514426646.23.108.54192.168.2.15
                                                                                      Oct 29, 2024 16:58:44.111500978 CET40514426646.23.108.54192.168.2.15
                                                                                      Oct 29, 2024 16:58:44.111946106 CET442664051192.168.2.1546.23.108.54
                                                                                      Oct 29, 2024 16:58:44.117965937 CET40514426646.23.108.54192.168.2.15
                                                                                      Oct 29, 2024 16:58:49.421924114 CET4168622438192.168.2.1546.23.108.159
                                                                                      Oct 29, 2024 16:58:49.427670956 CET224384168646.23.108.159192.168.2.15
                                                                                      Oct 29, 2024 16:58:49.427746058 CET4168622438192.168.2.1546.23.108.159
                                                                                      Oct 29, 2024 16:58:49.427772045 CET4168622438192.168.2.1546.23.108.159
                                                                                      Oct 29, 2024 16:58:49.433132887 CET224384168646.23.108.159192.168.2.15
                                                                                      Oct 29, 2024 16:58:49.433187008 CET4168622438192.168.2.1546.23.108.159
                                                                                      Oct 29, 2024 16:58:49.438519955 CET224384168646.23.108.159192.168.2.15
                                                                                      Oct 29, 2024 16:58:50.157601118 CET224384168646.23.108.159192.168.2.15
                                                                                      Oct 29, 2024 16:58:50.157958984 CET4168622438192.168.2.1546.23.108.159
                                                                                      Oct 29, 2024 16:58:50.163302898 CET224384168646.23.108.159192.168.2.15
                                                                                      TimestampSource PortDest PortSource IPDest IP
                                                                                      Oct 29, 2024 16:56:50.117150068 CET3385953192.168.2.1564.176.6.48
                                                                                      Oct 29, 2024 16:56:50.258833885 CET4354353192.168.2.1564.176.6.48
                                                                                      Oct 29, 2024 16:56:55.123862028 CET3766253192.168.2.15178.254.22.166
                                                                                      Oct 29, 2024 16:56:55.265497923 CET5822453192.168.2.15178.254.22.166
                                                                                      Oct 29, 2024 16:57:00.130327940 CET4883453192.168.2.1565.21.1.106
                                                                                      Oct 29, 2024 16:57:00.158267021 CET534883465.21.1.106192.168.2.15
                                                                                      Oct 29, 2024 16:57:00.271873951 CET3536353192.168.2.1565.21.1.106
                                                                                      Oct 29, 2024 16:57:00.301171064 CET533536365.21.1.106192.168.2.15
                                                                                      Oct 29, 2024 16:57:01.465912104 CET5266553192.168.2.151.1.1.1
                                                                                      Oct 29, 2024 16:57:01.465960026 CET5824253192.168.2.151.1.1.1
                                                                                      Oct 29, 2024 16:57:01.475107908 CET53582421.1.1.1192.168.2.15
                                                                                      Oct 29, 2024 16:57:01.475203037 CET53526651.1.1.1192.168.2.15
                                                                                      Oct 29, 2024 16:57:05.906219006 CET3846653192.168.2.1551.158.108.203
                                                                                      Oct 29, 2024 16:57:05.923038006 CET533846651.158.108.203192.168.2.15
                                                                                      Oct 29, 2024 16:57:11.672957897 CET5146753192.168.2.15137.220.52.23
                                                                                      Oct 29, 2024 16:57:16.679234028 CET4377553192.168.2.15137.220.52.23
                                                                                      Oct 29, 2024 16:57:21.686037064 CET6027153192.168.2.1580.152.203.134
                                                                                      Oct 29, 2024 16:57:26.692545891 CET4671253192.168.2.1581.169.136.222
                                                                                      Oct 29, 2024 16:57:26.720611095 CET534671281.169.136.222192.168.2.15
                                                                                      Oct 29, 2024 16:57:32.454590082 CET5755253192.168.2.1580.152.203.134
                                                                                      Oct 29, 2024 16:57:37.461453915 CET4188653192.168.2.15168.235.111.72
                                                                                      Oct 29, 2024 16:57:37.584464073 CET5341886168.235.111.72192.168.2.15
                                                                                      Oct 29, 2024 16:57:37.585803986 CET4880953192.168.2.15168.235.111.72
                                                                                      Oct 29, 2024 16:57:37.681487083 CET5348809168.235.111.72192.168.2.15
                                                                                      Oct 29, 2024 16:57:37.682837963 CET3575053192.168.2.155.161.109.23
                                                                                      Oct 29, 2024 16:57:48.423718929 CET4692153192.168.2.1551.158.108.203
                                                                                      Oct 29, 2024 16:57:48.439959049 CET534692151.158.108.203192.168.2.15
                                                                                      Oct 29, 2024 16:57:48.441370964 CET5640853192.168.2.15202.61.197.122
                                                                                      Oct 29, 2024 16:57:48.453031063 CET5356408202.61.197.122192.168.2.15
                                                                                      Oct 29, 2024 16:57:54.187818050 CET4867053192.168.2.1551.158.108.203
                                                                                      Oct 29, 2024 16:57:54.204531908 CET534867051.158.108.203192.168.2.15
                                                                                      Oct 29, 2024 16:57:54.206507921 CET4143353192.168.2.1570.34.254.19
                                                                                      Oct 29, 2024 16:57:59.213140965 CET4074253192.168.2.15194.36.144.87
                                                                                      Oct 29, 2024 16:57:59.225011110 CET5340742194.36.144.87192.168.2.15
                                                                                      Oct 29, 2024 16:57:59.226363897 CET5019353192.168.2.15185.181.61.24
                                                                                      Oct 29, 2024 16:57:59.260025978 CET5350193185.181.61.24192.168.2.15
                                                                                      Oct 29, 2024 16:58:04.990423918 CET3804253192.168.2.1570.34.254.19
                                                                                      Oct 29, 2024 16:58:09.996715069 CET5935553192.168.2.1581.169.136.222
                                                                                      Oct 29, 2024 16:58:11.066791058 CET535935581.169.136.222192.168.2.15
                                                                                      Oct 29, 2024 16:58:16.803610086 CET4590853192.168.2.15202.61.197.122
                                                                                      Oct 29, 2024 16:58:16.816318989 CET5345908202.61.197.122192.168.2.15
                                                                                      Oct 29, 2024 16:58:16.817805052 CET4754553192.168.2.15139.84.165.176
                                                                                      Oct 29, 2024 16:58:21.825234890 CET4850053192.168.2.15194.36.144.87
                                                                                      Oct 29, 2024 16:58:21.836374998 CET5348500194.36.144.87192.168.2.15
                                                                                      Oct 29, 2024 16:58:27.568595886 CET5676853192.168.2.15178.254.22.166
                                                                                      Oct 29, 2024 16:58:32.575741053 CET5825053192.168.2.1551.158.108.203
                                                                                      Oct 29, 2024 16:58:32.591866016 CET535825051.158.108.203192.168.2.15
                                                                                      Oct 29, 2024 16:58:32.593611956 CET3312753192.168.2.1551.158.108.203
                                                                                      Oct 29, 2024 16:58:32.611145020 CET533312751.158.108.203192.168.2.15
                                                                                      Oct 29, 2024 16:58:32.613205910 CET3894753192.168.2.15202.61.197.122
                                                                                      Oct 29, 2024 16:58:32.623892069 CET5338947202.61.197.122192.168.2.15
                                                                                      Oct 29, 2024 16:58:38.353430033 CET4034053192.168.2.1564.176.6.48
                                                                                      Oct 29, 2024 16:58:43.359860897 CET4585553192.168.2.15194.36.144.87
                                                                                      Oct 29, 2024 16:58:43.371139050 CET5345855194.36.144.87192.168.2.15
                                                                                      Oct 29, 2024 16:58:43.372348070 CET6080453192.168.2.15152.53.15.127
                                                                                      Oct 29, 2024 16:58:43.382930040 CET5360804152.53.15.127192.168.2.15
                                                                                      Oct 29, 2024 16:58:43.384002924 CET4175753192.168.2.1551.158.108.203
                                                                                      Oct 29, 2024 16:58:43.400420904 CET534175751.158.108.203192.168.2.15
                                                                                      Oct 29, 2024 16:58:49.114253044 CET3842353192.168.2.1551.158.108.203
                                                                                      Oct 29, 2024 16:58:49.391238928 CET533842351.158.108.203192.168.2.15
                                                                                      Oct 29, 2024 16:58:49.393513918 CET5405653192.168.2.1565.21.1.106
                                                                                      Oct 29, 2024 16:58:49.421199083 CET535405665.21.1.106192.168.2.15
                                                                                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                      Oct 29, 2024 16:56:50.117150068 CET192.168.2.1564.176.6.480x1cefStandard query (0)dingdingrouter.pirateA (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:56:55.123862028 CET192.168.2.15178.254.22.1660x40d6Standard query (0)repo.dyn. [malformed]256455false
                                                                                      Oct 29, 2024 16:57:00.130327940 CET192.168.2.1565.21.1.1060x7b81Standard query (0)sandmen.geekA (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:01.465912104 CET192.168.2.151.1.1.10x7570Standard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:01.465960026 CET192.168.2.151.1.1.10x648eStandard query (0)daisy.ubuntu.com28IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:05.906219006 CET192.168.2.1551.158.108.2030xa127Standard query (0)sliteyed.pirateA (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:11.672957897 CET192.168.2.15137.220.52.230xb5d7Standard query (0)sandmen.geek. [malformed]256476false
                                                                                      Oct 29, 2024 16:57:16.679234028 CET192.168.2.15137.220.52.230x7e46Standard query (0)dingdingrouter.pirateA (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:21.686037064 CET192.168.2.1580.152.203.1340xee61Standard query (0)repo.dyn. [malformed]256486false
                                                                                      Oct 29, 2024 16:57:26.692545891 CET192.168.2.1581.169.136.2220x820dStandard query (0)sliteyed.pirate. [malformed]256486false
                                                                                      Oct 29, 2024 16:57:32.454590082 CET192.168.2.1580.152.203.1340x61caStandard query (0)dingdingrouter.pirateA (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:37.461453915 CET192.168.2.15168.235.111.720xee0fStandard query (0)sliteyed.pirate. [malformed]256497false
                                                                                      Oct 29, 2024 16:57:37.585803986 CET192.168.2.15168.235.111.720x3a25Standard query (0)repo.dyn. [malformed]256497false
                                                                                      Oct 29, 2024 16:57:37.682837963 CET192.168.2.155.161.109.230x6355Standard query (0)sandmen.geekA (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:48.423718929 CET192.168.2.1551.158.108.2030x5699Standard query (0)repo.dyn. [malformed]256508false
                                                                                      Oct 29, 2024 16:57:48.441370964 CET192.168.2.15202.61.197.1220x8005Standard query (0)sandmen.geekA (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:54.187818050 CET192.168.2.1551.158.108.2030x7b41Standard query (0)repo.dyn. [malformed]256258false
                                                                                      Oct 29, 2024 16:57:54.206507921 CET192.168.2.1570.34.254.190xf74Standard query (0)dingdingrouter.pirateA (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:59.213140965 CET192.168.2.15194.36.144.870x51edStandard query (0)sliteyed.pirate. [malformed]256263false
                                                                                      Oct 29, 2024 16:57:59.226363897 CET192.168.2.15185.181.61.240xdd5bStandard query (0)sandmen.geek. [malformed]256263false
                                                                                      Oct 29, 2024 16:58:04.990423918 CET192.168.2.1570.34.254.190xd5bcStandard query (0)sliteyed.pirate. [malformed]256273false
                                                                                      Oct 29, 2024 16:58:09.996715069 CET192.168.2.1581.169.136.2220x7d96Standard query (0)dingdingrouter.pirateA (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:16.803610086 CET192.168.2.15202.61.197.1220xddf0Standard query (0)sliteyed.pirate. [malformed]256280false
                                                                                      Oct 29, 2024 16:58:16.817805052 CET192.168.2.15139.84.165.1760xc18aStandard query (0)repo.dyn. [malformed]256285false
                                                                                      Oct 29, 2024 16:58:21.825234890 CET192.168.2.15194.36.144.870xe891Standard query (0)dingdingrouter.pirateA (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:27.568595886 CET192.168.2.15178.254.22.1660xa511Standard query (0)dingdingrouter.pirateA (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:32.575741053 CET192.168.2.1551.158.108.2030x665bStandard query (0)sliteyed.pirate. [malformed]256296false
                                                                                      Oct 29, 2024 16:58:32.593611956 CET192.168.2.1551.158.108.2030xc9a8Standard query (0)repo.dyn. [malformed]256296false
                                                                                      Oct 29, 2024 16:58:32.613205910 CET192.168.2.15202.61.197.1220xef23Standard query (0)sandmen.geekA (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:38.353430033 CET192.168.2.1564.176.6.480xf12dStandard query (0)dingdingrouter.pirateA (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:43.359860897 CET192.168.2.15194.36.144.870x8d2dStandard query (0)sliteyed.pirate. [malformed]256307false
                                                                                      Oct 29, 2024 16:58:43.372348070 CET192.168.2.15152.53.15.1270xc51Standard query (0)repo.dyn. [malformed]256307false
                                                                                      Oct 29, 2024 16:58:43.384002924 CET192.168.2.1551.158.108.2030x4046Standard query (0)sandmen.geekA (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:49.114253044 CET192.168.2.1551.158.108.2030xd323Standard query (0)repo.dyn. [malformed]256313false
                                                                                      Oct 29, 2024 16:58:49.393513918 CET192.168.2.1565.21.1.1060x5606Standard query (0)dingdingrouter.pirateA (IP address)IN (0x0001)false
                                                                                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                      Oct 29, 2024 16:57:00.158267021 CET65.21.1.106192.168.2.150x7b81No error (0)sandmen.geek46.23.108.161A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:00.158267021 CET65.21.1.106192.168.2.150x7b81No error (0)sandmen.geek46.23.108.64A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:00.158267021 CET65.21.1.106192.168.2.150x7b81No error (0)sandmen.geek185.174.135.118A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:00.158267021 CET65.21.1.106192.168.2.150x7b81No error (0)sandmen.geek46.23.108.111A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:00.158267021 CET65.21.1.106192.168.2.150x7b81No error (0)sandmen.geek46.23.108.55A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:00.158267021 CET65.21.1.106192.168.2.150x7b81No error (0)sandmen.geek46.23.108.109A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:00.158267021 CET65.21.1.106192.168.2.150x7b81No error (0)sandmen.geek46.23.108.61A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:00.158267021 CET65.21.1.106192.168.2.150x7b81No error (0)sandmen.geek45.148.10.51A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:00.158267021 CET65.21.1.106192.168.2.150x7b81No error (0)sandmen.geek46.23.108.58A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:00.158267021 CET65.21.1.106192.168.2.150x7b81No error (0)sandmen.geek46.23.108.65A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:00.158267021 CET65.21.1.106192.168.2.150x7b81No error (0)sandmen.geek46.23.108.62A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:00.158267021 CET65.21.1.106192.168.2.150x7b81No error (0)sandmen.geek46.23.108.110A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:00.158267021 CET65.21.1.106192.168.2.150x7b81No error (0)sandmen.geek46.23.108.133A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:00.158267021 CET65.21.1.106192.168.2.150x7b81No error (0)sandmen.geek46.23.108.159A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:00.158267021 CET65.21.1.106192.168.2.150x7b81No error (0)sandmen.geek154.216.20.58A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:00.158267021 CET65.21.1.106192.168.2.150x7b81No error (0)sandmen.geek46.23.108.54A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:00.158267021 CET65.21.1.106192.168.2.150x7b81No error (0)sandmen.geek46.23.108.252A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:01.475203037 CET1.1.1.1192.168.2.150x7570No error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:01.475203037 CET1.1.1.1192.168.2.150x7570No error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:05.923038006 CET51.158.108.203192.168.2.150xa127No error (0)sliteyed.pirate46.23.108.58A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:05.923038006 CET51.158.108.203192.168.2.150xa127No error (0)sliteyed.pirate46.23.108.54A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:05.923038006 CET51.158.108.203192.168.2.150xa127No error (0)sliteyed.pirate46.23.108.252A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:05.923038006 CET51.158.108.203192.168.2.150xa127No error (0)sliteyed.pirate154.216.20.58A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:05.923038006 CET51.158.108.203192.168.2.150xa127No error (0)sliteyed.pirate185.174.135.118A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:05.923038006 CET51.158.108.203192.168.2.150xa127No error (0)sliteyed.pirate46.23.108.62A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:05.923038006 CET51.158.108.203192.168.2.150xa127No error (0)sliteyed.pirate46.23.108.159A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:05.923038006 CET51.158.108.203192.168.2.150xa127No error (0)sliteyed.pirate46.23.108.64A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:05.923038006 CET51.158.108.203192.168.2.150xa127No error (0)sliteyed.pirate46.23.108.109A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:05.923038006 CET51.158.108.203192.168.2.150xa127No error (0)sliteyed.pirate46.23.108.61A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:05.923038006 CET51.158.108.203192.168.2.150xa127No error (0)sliteyed.pirate46.23.108.111A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:05.923038006 CET51.158.108.203192.168.2.150xa127No error (0)sliteyed.pirate46.23.108.161A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:05.923038006 CET51.158.108.203192.168.2.150xa127No error (0)sliteyed.pirate46.23.108.65A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:05.923038006 CET51.158.108.203192.168.2.150xa127No error (0)sliteyed.pirate46.23.108.55A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:05.923038006 CET51.158.108.203192.168.2.150xa127No error (0)sliteyed.pirate46.23.108.110A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:05.923038006 CET51.158.108.203192.168.2.150xa127No error (0)sliteyed.pirate45.148.10.51A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:05.923038006 CET51.158.108.203192.168.2.150xa127No error (0)sliteyed.pirate46.23.108.133A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:48.439959049 CET51.158.108.203192.168.2.150x5699Format error (1)repo.dyn. [malformed]nonenone256508false
                                                                                      Oct 29, 2024 16:57:48.453031063 CET202.61.197.122192.168.2.150x8005No error (0)sandmen.geek46.23.108.58A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:48.453031063 CET202.61.197.122192.168.2.150x8005No error (0)sandmen.geek46.23.108.62A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:48.453031063 CET202.61.197.122192.168.2.150x8005No error (0)sandmen.geek46.23.108.109A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:48.453031063 CET202.61.197.122192.168.2.150x8005No error (0)sandmen.geek46.23.108.133A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:48.453031063 CET202.61.197.122192.168.2.150x8005No error (0)sandmen.geek46.23.108.252A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:48.453031063 CET202.61.197.122192.168.2.150x8005No error (0)sandmen.geek46.23.108.54A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:48.453031063 CET202.61.197.122192.168.2.150x8005No error (0)sandmen.geek46.23.108.161A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:48.453031063 CET202.61.197.122192.168.2.150x8005No error (0)sandmen.geek46.23.108.64A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:48.453031063 CET202.61.197.122192.168.2.150x8005No error (0)sandmen.geek46.23.108.55A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:48.453031063 CET202.61.197.122192.168.2.150x8005No error (0)sandmen.geek46.23.108.65A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:48.453031063 CET202.61.197.122192.168.2.150x8005No error (0)sandmen.geek45.148.10.51A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:48.453031063 CET202.61.197.122192.168.2.150x8005No error (0)sandmen.geek46.23.108.111A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:48.453031063 CET202.61.197.122192.168.2.150x8005No error (0)sandmen.geek46.23.108.110A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:48.453031063 CET202.61.197.122192.168.2.150x8005No error (0)sandmen.geek46.23.108.159A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:48.453031063 CET202.61.197.122192.168.2.150x8005No error (0)sandmen.geek46.23.108.61A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:48.453031063 CET202.61.197.122192.168.2.150x8005No error (0)sandmen.geek154.216.20.58A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:48.453031063 CET202.61.197.122192.168.2.150x8005No error (0)sandmen.geek185.174.135.118A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:57:54.204531908 CET51.158.108.203192.168.2.150x7b41Format error (1)repo.dyn. [malformed]nonenone256258false
                                                                                      Oct 29, 2024 16:57:59.225011110 CET194.36.144.87192.168.2.150x51edFormat error (1)sliteyed.pirate. [malformed]nonenone256263false
                                                                                      Oct 29, 2024 16:58:11.066791058 CET81.169.136.222192.168.2.150x7d96No error (0)dingdingrouter.pirate46.23.108.62A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:11.066791058 CET81.169.136.222192.168.2.150x7d96No error (0)dingdingrouter.pirate46.23.108.159A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:11.066791058 CET81.169.136.222192.168.2.150x7d96No error (0)dingdingrouter.pirate46.23.108.58A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:11.066791058 CET81.169.136.222192.168.2.150x7d96No error (0)dingdingrouter.pirate46.23.108.111A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:11.066791058 CET81.169.136.222192.168.2.150x7d96No error (0)dingdingrouter.pirate154.216.20.58A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:11.066791058 CET81.169.136.222192.168.2.150x7d96No error (0)dingdingrouter.pirate46.23.108.54A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:11.066791058 CET81.169.136.222192.168.2.150x7d96No error (0)dingdingrouter.pirate46.23.108.61A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:11.066791058 CET81.169.136.222192.168.2.150x7d96No error (0)dingdingrouter.pirate46.23.108.109A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:11.066791058 CET81.169.136.222192.168.2.150x7d96No error (0)dingdingrouter.pirate45.148.10.51A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:11.066791058 CET81.169.136.222192.168.2.150x7d96No error (0)dingdingrouter.pirate46.23.108.65A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:11.066791058 CET81.169.136.222192.168.2.150x7d96No error (0)dingdingrouter.pirate46.23.108.55A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:11.066791058 CET81.169.136.222192.168.2.150x7d96No error (0)dingdingrouter.pirate46.23.108.110A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:11.066791058 CET81.169.136.222192.168.2.150x7d96No error (0)dingdingrouter.pirate46.23.108.161A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:11.066791058 CET81.169.136.222192.168.2.150x7d96No error (0)dingdingrouter.pirate185.174.135.118A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:11.066791058 CET81.169.136.222192.168.2.150x7d96No error (0)dingdingrouter.pirate46.23.108.64A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:11.066791058 CET81.169.136.222192.168.2.150x7d96No error (0)dingdingrouter.pirate46.23.108.133A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:11.066791058 CET81.169.136.222192.168.2.150x7d96No error (0)dingdingrouter.pirate46.23.108.252A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:21.836374998 CET194.36.144.87192.168.2.150xe891No error (0)dingdingrouter.pirate46.23.108.161A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:21.836374998 CET194.36.144.87192.168.2.150xe891No error (0)dingdingrouter.pirate45.148.10.51A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:21.836374998 CET194.36.144.87192.168.2.150xe891No error (0)dingdingrouter.pirate46.23.108.61A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:21.836374998 CET194.36.144.87192.168.2.150xe891No error (0)dingdingrouter.pirate46.23.108.54A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:21.836374998 CET194.36.144.87192.168.2.150xe891No error (0)dingdingrouter.pirate46.23.108.133A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:21.836374998 CET194.36.144.87192.168.2.150xe891No error (0)dingdingrouter.pirate46.23.108.58A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:21.836374998 CET194.36.144.87192.168.2.150xe891No error (0)dingdingrouter.pirate46.23.108.110A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:21.836374998 CET194.36.144.87192.168.2.150xe891No error (0)dingdingrouter.pirate46.23.108.62A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:21.836374998 CET194.36.144.87192.168.2.150xe891No error (0)dingdingrouter.pirate46.23.108.64A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:21.836374998 CET194.36.144.87192.168.2.150xe891No error (0)dingdingrouter.pirate46.23.108.65A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:21.836374998 CET194.36.144.87192.168.2.150xe891No error (0)dingdingrouter.pirate46.23.108.159A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:21.836374998 CET194.36.144.87192.168.2.150xe891No error (0)dingdingrouter.pirate185.174.135.118A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:21.836374998 CET194.36.144.87192.168.2.150xe891No error (0)dingdingrouter.pirate154.216.20.58A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:21.836374998 CET194.36.144.87192.168.2.150xe891No error (0)dingdingrouter.pirate46.23.108.252A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:21.836374998 CET194.36.144.87192.168.2.150xe891No error (0)dingdingrouter.pirate46.23.108.55A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:21.836374998 CET194.36.144.87192.168.2.150xe891No error (0)dingdingrouter.pirate46.23.108.109A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:21.836374998 CET194.36.144.87192.168.2.150xe891No error (0)dingdingrouter.pirate46.23.108.111A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:32.591866016 CET51.158.108.203192.168.2.150x665bFormat error (1)sliteyed.pirate. [malformed]nonenone256296false
                                                                                      Oct 29, 2024 16:58:32.611145020 CET51.158.108.203192.168.2.150xc9a8Format error (1)repo.dyn. [malformed]nonenone256296false
                                                                                      Oct 29, 2024 16:58:32.623892069 CET202.61.197.122192.168.2.150xef23No error (0)sandmen.geek46.23.108.133A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:32.623892069 CET202.61.197.122192.168.2.150xef23No error (0)sandmen.geek46.23.108.161A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:32.623892069 CET202.61.197.122192.168.2.150xef23No error (0)sandmen.geek46.23.108.55A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:32.623892069 CET202.61.197.122192.168.2.150xef23No error (0)sandmen.geek46.23.108.110A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:32.623892069 CET202.61.197.122192.168.2.150xef23No error (0)sandmen.geek46.23.108.58A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:32.623892069 CET202.61.197.122192.168.2.150xef23No error (0)sandmen.geek46.23.108.62A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:32.623892069 CET202.61.197.122192.168.2.150xef23No error (0)sandmen.geek46.23.108.252A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:32.623892069 CET202.61.197.122192.168.2.150xef23No error (0)sandmen.geek46.23.108.65A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:32.623892069 CET202.61.197.122192.168.2.150xef23No error (0)sandmen.geek46.23.108.64A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:32.623892069 CET202.61.197.122192.168.2.150xef23No error (0)sandmen.geek46.23.108.54A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:32.623892069 CET202.61.197.122192.168.2.150xef23No error (0)sandmen.geek185.174.135.118A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:32.623892069 CET202.61.197.122192.168.2.150xef23No error (0)sandmen.geek45.148.10.51A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:32.623892069 CET202.61.197.122192.168.2.150xef23No error (0)sandmen.geek46.23.108.159A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:32.623892069 CET202.61.197.122192.168.2.150xef23No error (0)sandmen.geek46.23.108.61A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:32.623892069 CET202.61.197.122192.168.2.150xef23No error (0)sandmen.geek46.23.108.109A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:32.623892069 CET202.61.197.122192.168.2.150xef23No error (0)sandmen.geek154.216.20.58A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:32.623892069 CET202.61.197.122192.168.2.150xef23No error (0)sandmen.geek46.23.108.111A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:43.371139050 CET194.36.144.87192.168.2.150x8d2dFormat error (1)sliteyed.pirate. [malformed]nonenone256307false
                                                                                      Oct 29, 2024 16:58:43.382930040 CET152.53.15.127192.168.2.150xc51Format error (1)repo.dyn. [malformed]nonenone256307false
                                                                                      Oct 29, 2024 16:58:43.400420904 CET51.158.108.203192.168.2.150x4046No error (0)sandmen.geek46.23.108.109A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:43.400420904 CET51.158.108.203192.168.2.150x4046No error (0)sandmen.geek46.23.108.54A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:43.400420904 CET51.158.108.203192.168.2.150x4046No error (0)sandmen.geek45.148.10.51A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:43.400420904 CET51.158.108.203192.168.2.150x4046No error (0)sandmen.geek46.23.108.252A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:43.400420904 CET51.158.108.203192.168.2.150x4046No error (0)sandmen.geek46.23.108.62A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:43.400420904 CET51.158.108.203192.168.2.150x4046No error (0)sandmen.geek46.23.108.64A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:43.400420904 CET51.158.108.203192.168.2.150x4046No error (0)sandmen.geek46.23.108.58A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:43.400420904 CET51.158.108.203192.168.2.150x4046No error (0)sandmen.geek46.23.108.110A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:43.400420904 CET51.158.108.203192.168.2.150x4046No error (0)sandmen.geek46.23.108.65A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:43.400420904 CET51.158.108.203192.168.2.150x4046No error (0)sandmen.geek46.23.108.159A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:43.400420904 CET51.158.108.203192.168.2.150x4046No error (0)sandmen.geek46.23.108.133A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:43.400420904 CET51.158.108.203192.168.2.150x4046No error (0)sandmen.geek46.23.108.161A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:43.400420904 CET51.158.108.203192.168.2.150x4046No error (0)sandmen.geek154.216.20.58A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:43.400420904 CET51.158.108.203192.168.2.150x4046No error (0)sandmen.geek46.23.108.55A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:43.400420904 CET51.158.108.203192.168.2.150x4046No error (0)sandmen.geek46.23.108.111A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:43.400420904 CET51.158.108.203192.168.2.150x4046No error (0)sandmen.geek46.23.108.61A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:43.400420904 CET51.158.108.203192.168.2.150x4046No error (0)sandmen.geek185.174.135.118A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:49.391238928 CET51.158.108.203192.168.2.150xd323Format error (1)repo.dyn. [malformed]nonenone256313false
                                                                                      Oct 29, 2024 16:58:49.421199083 CET65.21.1.106192.168.2.150x5606No error (0)dingdingrouter.pirate46.23.108.61A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:49.421199083 CET65.21.1.106192.168.2.150x5606No error (0)dingdingrouter.pirate46.23.108.133A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:49.421199083 CET65.21.1.106192.168.2.150x5606No error (0)dingdingrouter.pirate46.23.108.161A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:49.421199083 CET65.21.1.106192.168.2.150x5606No error (0)dingdingrouter.pirate46.23.108.55A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:49.421199083 CET65.21.1.106192.168.2.150x5606No error (0)dingdingrouter.pirate46.23.108.58A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:49.421199083 CET65.21.1.106192.168.2.150x5606No error (0)dingdingrouter.pirate46.23.108.110A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:49.421199083 CET65.21.1.106192.168.2.150x5606No error (0)dingdingrouter.pirate45.148.10.51A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:49.421199083 CET65.21.1.106192.168.2.150x5606No error (0)dingdingrouter.pirate46.23.108.54A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:49.421199083 CET65.21.1.106192.168.2.150x5606No error (0)dingdingrouter.pirate46.23.108.64A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:49.421199083 CET65.21.1.106192.168.2.150x5606No error (0)dingdingrouter.pirate46.23.108.65A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:49.421199083 CET65.21.1.106192.168.2.150x5606No error (0)dingdingrouter.pirate46.23.108.252A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:49.421199083 CET65.21.1.106192.168.2.150x5606No error (0)dingdingrouter.pirate46.23.108.109A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:49.421199083 CET65.21.1.106192.168.2.150x5606No error (0)dingdingrouter.pirate185.174.135.118A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:49.421199083 CET65.21.1.106192.168.2.150x5606No error (0)dingdingrouter.pirate154.216.20.58A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:49.421199083 CET65.21.1.106192.168.2.150x5606No error (0)dingdingrouter.pirate46.23.108.159A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:49.421199083 CET65.21.1.106192.168.2.150x5606No error (0)dingdingrouter.pirate46.23.108.111A (IP address)IN (0x0001)false
                                                                                      Oct 29, 2024 16:58:49.421199083 CET65.21.1.106192.168.2.150x5606No error (0)dingdingrouter.pirate46.23.108.62A (IP address)IN (0x0001)false

                                                                                      System Behavior

                                                                                      Start time (UTC):15:56:48
                                                                                      Start date (UTC):29/10/2024
                                                                                      Path:/tmp/tarm7.elf
                                                                                      Arguments:/tmp/tarm7.elf
                                                                                      File size:4956856 bytes
                                                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                      Start time (UTC):15:56:48
                                                                                      Start date (UTC):29/10/2024
                                                                                      Path:/tmp/tarm7.elf
                                                                                      Arguments:-
                                                                                      File size:4956856 bytes
                                                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                      Start time (UTC):15:56:48
                                                                                      Start date (UTC):29/10/2024
                                                                                      Path:/tmp/tarm7.elf
                                                                                      Arguments:-
                                                                                      File size:4956856 bytes
                                                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                                      Start time (UTC):15:56:48
                                                                                      Start date (UTC):29/10/2024
                                                                                      Path:/tmp/tarm7.elf
                                                                                      Arguments:-
                                                                                      File size:4956856 bytes
                                                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1