Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
NnDBvZKtdN.elf

Overview

General Information

Sample name:NnDBvZKtdN.elf
renamed because original name is a hash value
Original sample name:8622bebd8e2cbc2b5771884826a0afe5.elf
Analysis ID:1427807
MD5:8622bebd8e2cbc2b5771884826a0afe5
SHA1:9563625717e0b5408a169c200182f81f6adc373a
SHA256:3242dc29b3aeffc6cfbb754278b327953eaccb1488fd6cdb5101d06baaf98e91
Tags:32elfintelmirai
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Machine Learning detection for sample
Enumerates processes within the "proc" file system
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Yara signature match

Classification

Analysis Advice

All domains contacted by the sample do not resolve. The sample is likely an old dropper which does no longer work.
Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1427807
Start date and time:2024-04-18 07:59:04 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 25s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:NnDBvZKtdN.elf
renamed because original name is a hash value
Original Sample Name:8622bebd8e2cbc2b5771884826a0afe5.elf
Detection:MAL
Classification:mal60.linELF@0/0@100/0
Command:/tmp/NnDBvZKtdN.elf
PID:5513
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
done.
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
NnDBvZKtdN.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xd178:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd18c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd1a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd1b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd1c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd1dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd1f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd204:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd218:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd22c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd240:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd254:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd268:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd27c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd290:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd2a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd2b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd2cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd2e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd2f4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd308:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
NnDBvZKtdN.elfLinux_Trojan_Mirai_3a56423bunknownunknown
  • 0x720b:$a: 24 1C 8B 44 24 20 0F B6 D0 C1 E8 08 89 54 24 24 89 44 24 20 BA 01 00
NnDBvZKtdN.elfLinux_Trojan_Mirai_dab39a25unknownunknown
  • 0x59ba:$a: 0E 75 20 50 6A 00 6A 00 6A 00 53 6A 0E FF 74 24 48 68 DD 00
NnDBvZKtdN.elfLinux_Trojan_Mirai_8aa7b5d3unknownunknown
  • 0x53a2:$a: 8B 4C 24 14 8B 74 24 0C 8B 5C 24 10 85 C9 74 0D 31 D2 8A 04 1A 88
SourceRuleDescriptionAuthorStrings
5513.1.0000000008048000.0000000008057000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xd178:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd18c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd1a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd1b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd1c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd1dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd1f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd204:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd218:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd22c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd240:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd254:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd268:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd27c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd290:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd2a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd2b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd2cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd2e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd2f4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd308:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5513.1.0000000008048000.0000000008057000.r-x.sdmpLinux_Trojan_Mirai_3a56423bunknownunknown
  • 0x720b:$a: 24 1C 8B 44 24 20 0F B6 D0 C1 E8 08 89 54 24 24 89 44 24 20 BA 01 00
5513.1.0000000008048000.0000000008057000.r-x.sdmpLinux_Trojan_Mirai_dab39a25unknownunknown
  • 0x59ba:$a: 0E 75 20 50 6A 00 6A 00 6A 00 53 6A 0E FF 74 24 48 68 DD 00
5513.1.0000000008048000.0000000008057000.r-x.sdmpLinux_Trojan_Mirai_8aa7b5d3unknownunknown
  • 0x53a2:$a: 8B 4C 24 14 8B 74 24 0C 8B 5C 24 10 85 C9 74 0D 31 D2 8A 04 1A 88
Process Memory Space: NnDBvZKtdN.elf PID: 5513Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x9d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x9ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa00:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa14:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa28:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa3c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa50:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa64:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa78:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa8c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaa0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xab4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xac8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xadc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaf0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb04:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb18:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb2c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb40:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb54:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb68:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: NnDBvZKtdN.elfReversingLabs: Detection: 60%
Source: NnDBvZKtdN.elfVirustotal: Detection: 50%Perma Link
Source: NnDBvZKtdN.elfJoe Sandbox ML: detected
Source: NnDBvZKtdN.elfString: HTTP/1.1 200 OKtop1hbt.armtop1hbt.arm5top1hbt.arm6top1hbt.arm7top1hbt.mipstop1hbt.mpsltop1hbt.x86_64top1hbt.sh4/proc/proc/%d/cmdlinenetstatwgetcurl/bin/busybox/proc//proc/%s/exe/proc/self/exevar/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdvar/tmp/soniahicorestm_hi3511_dvr/usr/lib/systemd/systemdshellmnt/sys/boot/media/srv/var/run/sbin/lib/etc/dev/home/Davincitelnetsshwatchdog/var/spool/var/Sofiasshd/usr/compress/bin//compress/bin/compress/usr/bashhttpdtelnetddropbearencodersystem/root/dvr_gui//root/dvr_app//anko-app//opt/anko-app/ankosample _8182T_1104/usr/libexec/openssh/sftp-serverabcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ3f
Source: unknownDNS traffic detected: query: cnc.condi.cloud replaycode: Server failure (2)
Source: unknownDNS traffic detected: queries for: cnc.condi.cloud

System Summary

barindex
Source: NnDBvZKtdN.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: NnDBvZKtdN.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_3a56423b Author: unknown
Source: NnDBvZKtdN.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_dab39a25 Author: unknown
Source: NnDBvZKtdN.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: 5513.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5513.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_3a56423b Author: unknown
Source: 5513.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_dab39a25 Author: unknown
Source: 5513.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: Process Memory Space: NnDBvZKtdN.elf PID: 5513, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Initial sampleString containing 'busybox' found: /bin/busybox
Source: Initial sampleString containing 'busybox' found: HTTP/1.1 200 OKtop1hbt.armtop1hbt.arm5top1hbt.arm6top1hbt.arm7top1hbt.mipstop1hbt.mpsltop1hbt.x86_64top1hbt.sh4/proc/proc/%d/cmdlinenetstatwgetcurl/bin/busybox/proc//proc/%s/exe/proc/self/exevar/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdvar/tmp/soniahicorestm_hi3511_dvr/usr/lib/systemd/systemdshellmnt/sys/boot/media/srv/var/run/sbin/lib/etc/dev/home/Davincitelnetsshwatchdog/var/spool/var/Sofiasshd/usr/compress/bin//compress/bin/compress/usr/bashhttpdtelnetddropbearencodersystem/root/dvr_gui//root/dvr_app//anko-app//opt/anko-app/ankosample _8182T_1104/usr/libexec/openssh/sftp-serverabcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ3f
Source: ELF static info symbol of initial sample.symtab present: no
Source: NnDBvZKtdN.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: NnDBvZKtdN.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_3a56423b os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 117d6eb47f000c9d475119ca0e6a1b49a91bbbece858758aaa3d7f30d0777d75, id = 3a56423b-c0cf-4483-87e3-552beb40563a, last_modified = 2021-09-16
Source: NnDBvZKtdN.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_dab39a25 reference_sample = 3e02fb63803110cabde08e809cf4acc1b8fb474ace531959a311858fdd578bab, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 5a628d9af9d6dccf29e78f780bb74a2fa25167954c34d4a1529bdea5ea891ac0, id = dab39a25-852b-441f-86ab-23d945daa62c, last_modified = 2022-01-26
Source: NnDBvZKtdN.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: 5513.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5513.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_3a56423b os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 117d6eb47f000c9d475119ca0e6a1b49a91bbbece858758aaa3d7f30d0777d75, id = 3a56423b-c0cf-4483-87e3-552beb40563a, last_modified = 2021-09-16
Source: 5513.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_dab39a25 reference_sample = 3e02fb63803110cabde08e809cf4acc1b8fb474ace531959a311858fdd578bab, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 5a628d9af9d6dccf29e78f780bb74a2fa25167954c34d4a1529bdea5ea891ac0, id = dab39a25-852b-441f-86ab-23d945daa62c, last_modified = 2022-01-26
Source: 5513.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: Process Memory Space: NnDBvZKtdN.elf PID: 5513, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal60.linELF@0/0@100/0
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/1583/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/2672/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/110/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/111/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/112/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/113/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/234/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/1577/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/114/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/235/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/115/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/116/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/117/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/118/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/119/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/10/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/917/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/11/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/12/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/13/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/14/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/15/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/16/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/17/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/18/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/19/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/1593/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/240/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/120/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/3094/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/121/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/242/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/3406/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/1/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/122/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/243/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/2/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/123/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/244/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/1589/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/3/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/124/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/245/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/1588/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/125/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/4/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/246/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/3402/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/126/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/5/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/247/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/127/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/6/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/248/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/128/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/7/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/249/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/8/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/129/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/800/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/9/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/801/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/3764/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/803/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/3765/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/3766/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/3767/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/20/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/806/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/21/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/807/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/928/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/22/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/23/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/24/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/25/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/26/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/27/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/28/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/29/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/3420/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/490/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/250/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/130/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/251/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/131/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/252/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/132/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/253/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/254/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/255/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/135/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/256/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/1599/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/257/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/378/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/258/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/3412/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/259/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/30/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/35/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/1371/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/260/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/261/cmdlineJump to behavior
Source: /tmp/NnDBvZKtdN.elf (PID: 5515)File opened: /proc/262/cmdlineJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid AccountsWindows Management Instrumentation1
Scripting
Path InterceptionDirect Volume Access1
OS Credential Dumping
System Service DiscoveryRemote ServicesData from Local System1
Non-Application Layer Protocol
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1427807 Sample: NnDBvZKtdN.elf Startdate: 18/04/2024 Architecture: LINUX Score: 60 14 cnc.condi.cloud 2->14 16 Malicious sample detected (through community Yara rule) 2->16 18 Multi AV Scanner detection for submitted file 2->18 20 Machine Learning detection for sample 2->20 8 NnDBvZKtdN.elf 2->8         started        signatures3 process4 process5 10 NnDBvZKtdN.elf 8->10         started        process6 12 NnDBvZKtdN.elf 10->12         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
NnDBvZKtdN.elf61%ReversingLabsLinux.Trojan.Mirai
NnDBvZKtdN.elf50%VirustotalBrowse
NnDBvZKtdN.elf100%Joe Sandbox ML
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
cnc.condi.cloud
unknown
unknowntrue
    unknown
    No contacted IP infos
    No context
    No context
    No context
    No context
    No context
    No created / dropped files found
    File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
    Entropy (8bit):6.32990306590306
    TrID:
    • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
    • ELF Executable and Linkable format (generic) (4004/1) 49.84%
    File name:NnDBvZKtdN.elf
    File size:62'316 bytes
    MD5:8622bebd8e2cbc2b5771884826a0afe5
    SHA1:9563625717e0b5408a169c200182f81f6adc373a
    SHA256:3242dc29b3aeffc6cfbb754278b327953eaccb1488fd6cdb5101d06baaf98e91
    SHA512:fa95d16673d24ed84aa3fd7f6eb49d9f268a84ae555203c4bcb8c3aef06d0727f53690f9cfa3bcc6139b4eabfb06bec760b04a82091ecd925e07cfc4364f7670
    SSDEEP:768:lXlW6Ur9L39tzOL1++vLoIC22mSAeao6fYkeUo6LEz3BvyPwXnVrUAM31g2yXMDd:hqL399OQsLQmSn9UoIwrU531g2y70r
    TLSH:5F533A94F743D4F1D8470930119BFB3A9A31EEE11160ED2BEB98FE72AC729129116B5C
    File Content Preview:.ELF....................T...4...........4. ...(.........................................t...tp..tp..(...............Q.td................................d.......................U......=.q...t..5.....p......p......u........t....h.p.............q........&...

    ELF header

    Class:ELF32
    Data:2's complement, little endian
    Version:1 (current)
    Machine:Intel 80386
    Version Number:0x1
    Type:EXEC (Executable file)
    OS/ABI:UNIX - System V
    ABI Version:0
    Entry Point Address:0x8048154
    Flags:0x0
    ELF Header Size:52
    Program Header Offset:52
    Program Header Size:32
    Number of Program Headers:3
    Section Header Offset:61916
    Section Header Size:40
    Number of Section Headers:10
    Header String Table Index:9
    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
    NULL0x00x00x00x00x0000
    .initPROGBITS0x80480940x940x110x00x6AX001
    .textPROGBITS0x80480b00xb00xcbe70x00x6AX0016
    .finiPROGBITS0x8054c970xcc970xc0x00x6AX001
    .rodataPROGBITS0x8054cc00xccc00x1ad40x00x2A0032
    .ctorsPROGBITS0x80570740xf0740x80x00x3WA004
    .dtorsPROGBITS0x805707c0xf07c0x80x00x3WA004
    .dataPROGBITS0x80570a00xf0a00xfc0x00x3WA0032
    .bssNOBITS0x80571a00xf19c0x8680x00x3WA0032
    .shstrtabSTRTAB0x00xf19c0x3e0x00x0001
    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
    LOAD0x00x80480000x80480000xe7940xe7946.48920x5R E0x1000.init .text .fini .rodata
    LOAD0xf0740x80570740x80570740x1280x9943.84890x6RW 0x1000.ctors .dtors .data .bss
    GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
    TimestampSource PortDest PortSource IPDest IP
    Apr 18, 2024 07:59:46.722132921 CEST4807453192.168.2.148.8.8.8
    Apr 18, 2024 07:59:46.948549986 CEST53480748.8.8.8192.168.2.14
    Apr 18, 2024 07:59:46.948668003 CEST3350853192.168.2.148.8.8.8
    Apr 18, 2024 07:59:47.131932974 CEST53335088.8.8.8192.168.2.14
    Apr 18, 2024 07:59:47.132056952 CEST3896153192.168.2.148.8.8.8
    Apr 18, 2024 07:59:47.334244967 CEST53389618.8.8.8192.168.2.14
    Apr 18, 2024 07:59:47.334382057 CEST4447053192.168.2.148.8.8.8
    Apr 18, 2024 07:59:47.517951965 CEST53444708.8.8.8192.168.2.14
    Apr 18, 2024 07:59:47.518098116 CEST5767853192.168.2.148.8.8.8
    Apr 18, 2024 07:59:47.701625109 CEST53576788.8.8.8192.168.2.14
    Apr 18, 2024 07:59:51.701713085 CEST4849553192.168.2.148.8.8.8
    Apr 18, 2024 07:59:51.898200989 CEST53484958.8.8.8192.168.2.14
    Apr 18, 2024 07:59:51.898422003 CEST5942453192.168.2.148.8.8.8
    Apr 18, 2024 07:59:52.081671000 CEST53594248.8.8.8192.168.2.14
    Apr 18, 2024 07:59:52.081803083 CEST5069853192.168.2.148.8.8.8
    Apr 18, 2024 07:59:52.265723944 CEST53506988.8.8.8192.168.2.14
    Apr 18, 2024 07:59:52.265842915 CEST5612053192.168.2.148.8.8.8
    Apr 18, 2024 07:59:52.450360060 CEST53561208.8.8.8192.168.2.14
    Apr 18, 2024 07:59:52.450486898 CEST4873353192.168.2.148.8.8.8
    Apr 18, 2024 07:59:52.633991003 CEST53487338.8.8.8192.168.2.14
    Apr 18, 2024 07:59:55.634138107 CEST5674253192.168.2.148.8.8.8
    Apr 18, 2024 07:59:55.817697048 CEST53567428.8.8.8192.168.2.14
    Apr 18, 2024 07:59:55.817804098 CEST5440453192.168.2.148.8.8.8
    Apr 18, 2024 07:59:56.019841909 CEST53544048.8.8.8192.168.2.14
    Apr 18, 2024 07:59:56.019948006 CEST4926253192.168.2.148.8.8.8
    Apr 18, 2024 07:59:56.203500032 CEST53492628.8.8.8192.168.2.14
    Apr 18, 2024 07:59:56.203716040 CEST4382153192.168.2.148.8.8.8
    Apr 18, 2024 07:59:56.386876106 CEST53438218.8.8.8192.168.2.14
    Apr 18, 2024 07:59:56.386971951 CEST4843453192.168.2.148.8.8.8
    Apr 18, 2024 07:59:56.570341110 CEST53484348.8.8.8192.168.2.14
    Apr 18, 2024 08:00:02.570354939 CEST5868653192.168.2.148.8.8.8
    Apr 18, 2024 08:00:02.754101038 CEST53586868.8.8.8192.168.2.14
    Apr 18, 2024 08:00:02.754283905 CEST4682953192.168.2.148.8.8.8
    Apr 18, 2024 08:00:02.937650919 CEST53468298.8.8.8192.168.2.14
    Apr 18, 2024 08:00:02.937827110 CEST5077753192.168.2.148.8.8.8
    Apr 18, 2024 08:00:03.121373892 CEST53507778.8.8.8192.168.2.14
    Apr 18, 2024 08:00:03.121526003 CEST3579253192.168.2.148.8.8.8
    Apr 18, 2024 08:00:03.308938026 CEST53357928.8.8.8192.168.2.14
    Apr 18, 2024 08:00:03.309092999 CEST3398453192.168.2.148.8.8.8
    Apr 18, 2024 08:00:03.542287111 CEST53339848.8.8.8192.168.2.14
    Apr 18, 2024 08:00:09.542417049 CEST6028253192.168.2.148.8.8.8
    Apr 18, 2024 08:00:09.726397991 CEST53602828.8.8.8192.168.2.14
    Apr 18, 2024 08:00:09.726835012 CEST3413253192.168.2.148.8.8.8
    Apr 18, 2024 08:00:09.942184925 CEST53341328.8.8.8192.168.2.14
    Apr 18, 2024 08:00:09.942492962 CEST4060253192.168.2.148.8.8.8
    Apr 18, 2024 08:00:10.155698061 CEST53406028.8.8.8192.168.2.14
    Apr 18, 2024 08:00:10.156008959 CEST3872453192.168.2.148.8.8.8
    Apr 18, 2024 08:00:10.339857101 CEST53387248.8.8.8192.168.2.14
    Apr 18, 2024 08:00:10.340142012 CEST3502853192.168.2.148.8.8.8
    Apr 18, 2024 08:00:10.524296999 CEST53350288.8.8.8192.168.2.14
    Apr 18, 2024 08:00:14.524583101 CEST4382753192.168.2.148.8.8.8
    Apr 18, 2024 08:00:14.721690893 CEST53438278.8.8.8192.168.2.14
    Apr 18, 2024 08:00:14.721966982 CEST4274453192.168.2.148.8.8.8
    Apr 18, 2024 08:00:14.906235933 CEST53427448.8.8.8192.168.2.14
    Apr 18, 2024 08:00:14.906497955 CEST4097153192.168.2.148.8.8.8
    Apr 18, 2024 08:00:15.132921934 CEST53409718.8.8.8192.168.2.14
    Apr 18, 2024 08:00:15.133162975 CEST3537753192.168.2.148.8.8.8
    Apr 18, 2024 08:00:15.336913109 CEST53353778.8.8.8192.168.2.14
    Apr 18, 2024 08:00:15.337348938 CEST3409753192.168.2.148.8.8.8
    Apr 18, 2024 08:00:15.540225983 CEST53340978.8.8.8192.168.2.14
    Apr 18, 2024 08:00:24.540326118 CEST4454653192.168.2.148.8.8.8
    Apr 18, 2024 08:00:24.724495888 CEST53445468.8.8.8192.168.2.14
    Apr 18, 2024 08:00:24.724708080 CEST3301253192.168.2.148.8.8.8
    Apr 18, 2024 08:00:24.921787024 CEST53330128.8.8.8192.168.2.14
    Apr 18, 2024 08:00:24.922116041 CEST5314953192.168.2.148.8.8.8
    Apr 18, 2024 08:00:25.119848967 CEST53531498.8.8.8192.168.2.14
    Apr 18, 2024 08:00:25.120151997 CEST5968753192.168.2.148.8.8.8
    Apr 18, 2024 08:00:25.316850901 CEST53596878.8.8.8192.168.2.14
    Apr 18, 2024 08:00:25.317167997 CEST5646553192.168.2.148.8.8.8
    Apr 18, 2024 08:00:25.513696909 CEST53564658.8.8.8192.168.2.14
    Apr 18, 2024 08:00:28.513968945 CEST4868353192.168.2.148.8.8.8
    Apr 18, 2024 08:00:28.710575104 CEST53486838.8.8.8192.168.2.14
    Apr 18, 2024 08:00:28.710853100 CEST4300053192.168.2.148.8.8.8
    Apr 18, 2024 08:00:28.893897057 CEST53430008.8.8.8192.168.2.14
    Apr 18, 2024 08:00:28.894148111 CEST5967553192.168.2.148.8.8.8
    Apr 18, 2024 08:00:29.090543032 CEST53596758.8.8.8192.168.2.14
    Apr 18, 2024 08:00:29.090799093 CEST4243153192.168.2.148.8.8.8
    Apr 18, 2024 08:00:29.273555040 CEST53424318.8.8.8192.168.2.14
    Apr 18, 2024 08:00:29.273793936 CEST3816153192.168.2.148.8.8.8
    Apr 18, 2024 08:00:29.470681906 CEST53381618.8.8.8192.168.2.14
    Apr 18, 2024 08:00:36.470777035 CEST4922753192.168.2.148.8.8.8
    Apr 18, 2024 08:00:36.673547029 CEST53492278.8.8.8192.168.2.14
    Apr 18, 2024 08:00:36.673829079 CEST4047753192.168.2.148.8.8.8
    Apr 18, 2024 08:00:36.905941963 CEST53404778.8.8.8192.168.2.14
    Apr 18, 2024 08:00:36.906481028 CEST4144253192.168.2.148.8.8.8
    Apr 18, 2024 08:00:37.132483959 CEST53414428.8.8.8192.168.2.14
    Apr 18, 2024 08:00:37.132772923 CEST5000353192.168.2.148.8.8.8
    Apr 18, 2024 08:00:37.316299915 CEST53500038.8.8.8192.168.2.14
    Apr 18, 2024 08:00:37.316576004 CEST5792653192.168.2.148.8.8.8
    Apr 18, 2024 08:00:37.500693083 CEST53579268.8.8.8192.168.2.14
    Apr 18, 2024 08:00:45.500744104 CEST4713853192.168.2.148.8.8.8
    Apr 18, 2024 08:00:45.698384047 CEST53471388.8.8.8192.168.2.14
    Apr 18, 2024 08:00:45.698914051 CEST4348553192.168.2.148.8.8.8
    Apr 18, 2024 08:00:45.901597023 CEST53434858.8.8.8192.168.2.14
    Apr 18, 2024 08:00:45.901865959 CEST3705353192.168.2.148.8.8.8
    Apr 18, 2024 08:00:46.087308884 CEST53370538.8.8.8192.168.2.14
    Apr 18, 2024 08:00:46.087587118 CEST5237453192.168.2.148.8.8.8
    Apr 18, 2024 08:00:46.283981085 CEST53523748.8.8.8192.168.2.14
    Apr 18, 2024 08:00:46.284224033 CEST5288553192.168.2.148.8.8.8
    Apr 18, 2024 08:00:46.468306065 CEST53528858.8.8.8192.168.2.14
    Apr 18, 2024 08:00:47.468625069 CEST5321553192.168.2.148.8.8.8
    Apr 18, 2024 08:00:47.684854984 CEST53532158.8.8.8192.168.2.14
    Apr 18, 2024 08:00:47.685142994 CEST4675653192.168.2.148.8.8.8
    Apr 18, 2024 08:00:47.868275881 CEST53467568.8.8.8192.168.2.14
    Apr 18, 2024 08:00:47.868506908 CEST5073153192.168.2.148.8.8.8
    Apr 18, 2024 08:00:48.094039917 CEST53507318.8.8.8192.168.2.14
    Apr 18, 2024 08:00:48.094263077 CEST3646653192.168.2.148.8.8.8
    Apr 18, 2024 08:00:48.278177977 CEST53364668.8.8.8192.168.2.14
    Apr 18, 2024 08:00:48.278492928 CEST5764653192.168.2.148.8.8.8
    Apr 18, 2024 08:00:48.460906029 CEST53576468.8.8.8192.168.2.14
    Apr 18, 2024 08:00:52.461404085 CEST4295553192.168.2.148.8.8.8
    Apr 18, 2024 08:00:52.644948006 CEST53429558.8.8.8192.168.2.14
    Apr 18, 2024 08:00:52.645221949 CEST4990553192.168.2.148.8.8.8
    Apr 18, 2024 08:00:52.829624891 CEST53499058.8.8.8192.168.2.14
    Apr 18, 2024 08:00:52.829895973 CEST4936253192.168.2.148.8.8.8
    Apr 18, 2024 08:00:53.026540995 CEST53493628.8.8.8192.168.2.14
    Apr 18, 2024 08:00:53.026676893 CEST3547953192.168.2.148.8.8.8
    Apr 18, 2024 08:00:53.242419958 CEST53354798.8.8.8192.168.2.14
    Apr 18, 2024 08:00:53.242758036 CEST6070653192.168.2.148.8.8.8
    Apr 18, 2024 08:00:53.426841021 CEST53607068.8.8.8192.168.2.14
    Apr 18, 2024 08:00:59.426836967 CEST5585753192.168.2.148.8.8.8
    Apr 18, 2024 08:00:59.622844934 CEST53558578.8.8.8192.168.2.14
    Apr 18, 2024 08:00:59.623032093 CEST5562853192.168.2.148.8.8.8
    Apr 18, 2024 08:00:59.835685968 CEST53556288.8.8.8192.168.2.14
    Apr 18, 2024 08:00:59.835867882 CEST4717253192.168.2.148.8.8.8
    Apr 18, 2024 08:01:00.061758995 CEST53471728.8.8.8192.168.2.14
    Apr 18, 2024 08:01:00.061909914 CEST5772553192.168.2.148.8.8.8
    Apr 18, 2024 08:01:00.245811939 CEST53577258.8.8.8192.168.2.14
    Apr 18, 2024 08:01:00.245999098 CEST5500553192.168.2.148.8.8.8
    Apr 18, 2024 08:01:00.429737091 CEST53550058.8.8.8192.168.2.14
    Apr 18, 2024 08:01:10.429635048 CEST4477653192.168.2.148.8.8.8
    Apr 18, 2024 08:01:10.629762888 CEST53447768.8.8.8192.168.2.14
    Apr 18, 2024 08:01:10.629947901 CEST4980253192.168.2.148.8.8.8
    Apr 18, 2024 08:01:10.813534975 CEST53498028.8.8.8192.168.2.14
    Apr 18, 2024 08:01:10.813967943 CEST5880653192.168.2.148.8.8.8
    Apr 18, 2024 08:01:10.997620106 CEST53588068.8.8.8192.168.2.14
    Apr 18, 2024 08:01:10.997807026 CEST4805653192.168.2.148.8.8.8
    Apr 18, 2024 08:01:11.195067883 CEST53480568.8.8.8192.168.2.14
    Apr 18, 2024 08:01:11.195262909 CEST5748953192.168.2.148.8.8.8
    Apr 18, 2024 08:01:11.379558086 CEST53574898.8.8.8192.168.2.14
    Apr 18, 2024 08:01:15.379915953 CEST5459653192.168.2.148.8.8.8
    Apr 18, 2024 08:01:15.564397097 CEST53545968.8.8.8192.168.2.14
    Apr 18, 2024 08:01:15.564615011 CEST6035953192.168.2.148.8.8.8
    Apr 18, 2024 08:01:15.762249947 CEST53603598.8.8.8192.168.2.14
    Apr 18, 2024 08:01:15.762404919 CEST5026153192.168.2.148.8.8.8
    Apr 18, 2024 08:01:15.946124077 CEST53502618.8.8.8192.168.2.14
    Apr 18, 2024 08:01:15.946310043 CEST5010353192.168.2.148.8.8.8
    Apr 18, 2024 08:01:16.143855095 CEST53501038.8.8.8192.168.2.14
    Apr 18, 2024 08:01:16.144068956 CEST3611053192.168.2.148.8.8.8
    Apr 18, 2024 08:01:16.375581026 CEST53361108.8.8.8192.168.2.14
    Apr 18, 2024 08:01:20.375941038 CEST3943053192.168.2.148.8.8.8
    Apr 18, 2024 08:01:20.560750008 CEST53394308.8.8.8192.168.2.14
    Apr 18, 2024 08:01:20.560976982 CEST4673353192.168.2.148.8.8.8
    Apr 18, 2024 08:01:20.774063110 CEST53467338.8.8.8192.168.2.14
    Apr 18, 2024 08:01:20.774378061 CEST5677753192.168.2.148.8.8.8
    Apr 18, 2024 08:01:20.958498955 CEST53567778.8.8.8192.168.2.14
    Apr 18, 2024 08:01:20.958971977 CEST5508253192.168.2.148.8.8.8
    Apr 18, 2024 08:01:21.142911911 CEST53550828.8.8.8192.168.2.14
    Apr 18, 2024 08:01:21.143315077 CEST4498653192.168.2.148.8.8.8
    Apr 18, 2024 08:01:22.034096956 CEST53449868.8.8.8192.168.2.14
    Apr 18, 2024 08:01:29.034472942 CEST3282953192.168.2.148.8.8.8
    Apr 18, 2024 08:01:29.225467920 CEST53328298.8.8.8192.168.2.14
    Apr 18, 2024 08:01:29.225641012 CEST4796353192.168.2.148.8.8.8
    Apr 18, 2024 08:01:29.428054094 CEST53479638.8.8.8192.168.2.14
    Apr 18, 2024 08:01:29.428212881 CEST4520653192.168.2.148.8.8.8
    Apr 18, 2024 08:01:29.619388103 CEST53452068.8.8.8192.168.2.14
    Apr 18, 2024 08:01:29.619556904 CEST3484753192.168.2.148.8.8.8
    Apr 18, 2024 08:01:29.836000919 CEST53348478.8.8.8192.168.2.14
    Apr 18, 2024 08:01:29.836229086 CEST4443453192.168.2.148.8.8.8
    Apr 18, 2024 08:01:30.039355993 CEST53444348.8.8.8192.168.2.14
    Apr 18, 2024 08:01:33.039669037 CEST5971153192.168.2.148.8.8.8
    Apr 18, 2024 08:01:33.224353075 CEST53597118.8.8.8192.168.2.14
    Apr 18, 2024 08:01:33.224528074 CEST3717953192.168.2.148.8.8.8
    Apr 18, 2024 08:01:33.421010017 CEST53371798.8.8.8192.168.2.14
    Apr 18, 2024 08:01:33.421174049 CEST5372853192.168.2.148.8.8.8
    Apr 18, 2024 08:01:33.604779959 CEST53537288.8.8.8192.168.2.14
    Apr 18, 2024 08:01:33.604924917 CEST5021453192.168.2.148.8.8.8
    Apr 18, 2024 08:01:33.788877010 CEST53502148.8.8.8192.168.2.14
    Apr 18, 2024 08:01:33.789006948 CEST5638253192.168.2.148.8.8.8
    Apr 18, 2024 08:01:33.972978115 CEST53563828.8.8.8192.168.2.14
    Apr 18, 2024 08:01:35.973198891 CEST4918853192.168.2.148.8.8.8
    Apr 18, 2024 08:01:36.187423944 CEST53491888.8.8.8192.168.2.14
    Apr 18, 2024 08:01:36.187644005 CEST3460253192.168.2.148.8.8.8
    Apr 18, 2024 08:01:36.384558916 CEST53346028.8.8.8192.168.2.14
    Apr 18, 2024 08:01:36.384691000 CEST4766553192.168.2.148.8.8.8
    Apr 18, 2024 08:01:36.599905014 CEST53476658.8.8.8192.168.2.14
    Apr 18, 2024 08:01:36.600141048 CEST5317153192.168.2.148.8.8.8
    Apr 18, 2024 08:01:36.827447891 CEST53531718.8.8.8192.168.2.14
    Apr 18, 2024 08:01:36.827614069 CEST4941153192.168.2.148.8.8.8
    Apr 18, 2024 08:01:37.040780067 CEST53494118.8.8.8192.168.2.14
    Apr 18, 2024 08:01:47.040591955 CEST5204353192.168.2.148.8.8.8
    Apr 18, 2024 08:01:47.238677979 CEST53520438.8.8.8192.168.2.14
    Apr 18, 2024 08:01:47.238810062 CEST5130453192.168.2.148.8.8.8
    Apr 18, 2024 08:01:47.465261936 CEST53513048.8.8.8192.168.2.14
    Apr 18, 2024 08:01:47.465373039 CEST4770953192.168.2.148.8.8.8
    Apr 18, 2024 08:01:47.654369116 CEST53477098.8.8.8192.168.2.14
    Apr 18, 2024 08:01:47.654547930 CEST5540453192.168.2.148.8.8.8
    Apr 18, 2024 08:01:47.850879908 CEST53554048.8.8.8192.168.2.14
    Apr 18, 2024 08:01:47.851057053 CEST4501253192.168.2.148.8.8.8
    Apr 18, 2024 08:01:48.034682989 CEST53450128.8.8.8192.168.2.14
    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
    Apr 18, 2024 07:59:46.722132921 CEST192.168.2.148.8.8.80xf6faStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 07:59:46.948668003 CEST192.168.2.148.8.8.80xf6faStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 07:59:47.132056952 CEST192.168.2.148.8.8.80xf6faStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 07:59:47.334382057 CEST192.168.2.148.8.8.80xf6faStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 07:59:47.518098116 CEST192.168.2.148.8.8.80xf6faStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 07:59:51.701713085 CEST192.168.2.148.8.8.80x468aStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 07:59:51.898422003 CEST192.168.2.148.8.8.80x468aStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 07:59:52.081803083 CEST192.168.2.148.8.8.80x468aStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 07:59:52.265842915 CEST192.168.2.148.8.8.80x468aStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 07:59:52.450486898 CEST192.168.2.148.8.8.80x468aStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 07:59:55.634138107 CEST192.168.2.148.8.8.80x2ff2Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 07:59:55.817804098 CEST192.168.2.148.8.8.80x2ff2Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 07:59:56.019948006 CEST192.168.2.148.8.8.80x2ff2Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 07:59:56.203716040 CEST192.168.2.148.8.8.80x2ff2Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 07:59:56.386971951 CEST192.168.2.148.8.8.80x2ff2Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:02.570354939 CEST192.168.2.148.8.8.80xcaa8Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:02.754283905 CEST192.168.2.148.8.8.80xcaa8Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:02.937827110 CEST192.168.2.148.8.8.80xcaa8Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:03.121526003 CEST192.168.2.148.8.8.80xcaa8Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:03.309092999 CEST192.168.2.148.8.8.80xcaa8Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:09.542417049 CEST192.168.2.148.8.8.80xa12eStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:09.726835012 CEST192.168.2.148.8.8.80xa12eStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:09.942492962 CEST192.168.2.148.8.8.80xa12eStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:10.156008959 CEST192.168.2.148.8.8.80xa12eStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:10.340142012 CEST192.168.2.148.8.8.80xa12eStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:14.524583101 CEST192.168.2.148.8.8.80x23a1Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:14.721966982 CEST192.168.2.148.8.8.80x23a1Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:14.906497955 CEST192.168.2.148.8.8.80x23a1Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:15.133162975 CEST192.168.2.148.8.8.80x23a1Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:15.337348938 CEST192.168.2.148.8.8.80x23a1Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:24.540326118 CEST192.168.2.148.8.8.80x660bStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:24.724708080 CEST192.168.2.148.8.8.80x660bStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:24.922116041 CEST192.168.2.148.8.8.80x660bStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:25.120151997 CEST192.168.2.148.8.8.80x660bStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:25.317167997 CEST192.168.2.148.8.8.80x660bStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:28.513968945 CEST192.168.2.148.8.8.80xea97Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:28.710853100 CEST192.168.2.148.8.8.80xea97Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:28.894148111 CEST192.168.2.148.8.8.80xea97Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:29.090799093 CEST192.168.2.148.8.8.80xea97Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:29.273793936 CEST192.168.2.148.8.8.80xea97Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:36.470777035 CEST192.168.2.148.8.8.80x69f3Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:36.673829079 CEST192.168.2.148.8.8.80x69f3Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:36.906481028 CEST192.168.2.148.8.8.80x69f3Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:37.132772923 CEST192.168.2.148.8.8.80x69f3Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:37.316576004 CEST192.168.2.148.8.8.80x69f3Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:45.500744104 CEST192.168.2.148.8.8.80x6c89Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:45.698914051 CEST192.168.2.148.8.8.80x6c89Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:45.901865959 CEST192.168.2.148.8.8.80x6c89Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:46.087587118 CEST192.168.2.148.8.8.80x6c89Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:46.284224033 CEST192.168.2.148.8.8.80x6c89Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:47.468625069 CEST192.168.2.148.8.8.80xba21Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:47.685142994 CEST192.168.2.148.8.8.80xba21Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:47.868506908 CEST192.168.2.148.8.8.80xba21Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:48.094263077 CEST192.168.2.148.8.8.80xba21Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:48.278492928 CEST192.168.2.148.8.8.80xba21Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:52.461404085 CEST192.168.2.148.8.8.80x57a7Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:52.645221949 CEST192.168.2.148.8.8.80x57a7Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:52.829895973 CEST192.168.2.148.8.8.80x57a7Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:53.026676893 CEST192.168.2.148.8.8.80x57a7Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:53.242758036 CEST192.168.2.148.8.8.80x57a7Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:59.426836967 CEST192.168.2.148.8.8.80x674fStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:59.623032093 CEST192.168.2.148.8.8.80x674fStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:59.835867882 CEST192.168.2.148.8.8.80x674fStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:00.061909914 CEST192.168.2.148.8.8.80x674fStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:00.245999098 CEST192.168.2.148.8.8.80x674fStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:10.429635048 CEST192.168.2.148.8.8.80xf09fStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:10.629947901 CEST192.168.2.148.8.8.80xf09fStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:10.813967943 CEST192.168.2.148.8.8.80xf09fStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:10.997807026 CEST192.168.2.148.8.8.80xf09fStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:11.195262909 CEST192.168.2.148.8.8.80xf09fStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:15.379915953 CEST192.168.2.148.8.8.80x5db4Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:15.564615011 CEST192.168.2.148.8.8.80x5db4Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:15.762404919 CEST192.168.2.148.8.8.80x5db4Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:15.946310043 CEST192.168.2.148.8.8.80x5db4Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:16.144068956 CEST192.168.2.148.8.8.80x5db4Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:20.375941038 CEST192.168.2.148.8.8.80x879fStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:20.560976982 CEST192.168.2.148.8.8.80x879fStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:20.774378061 CEST192.168.2.148.8.8.80x879fStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:20.958971977 CEST192.168.2.148.8.8.80x879fStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:21.143315077 CEST192.168.2.148.8.8.80x879fStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:29.034472942 CEST192.168.2.148.8.8.80xe204Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:29.225641012 CEST192.168.2.148.8.8.80xe204Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:29.428212881 CEST192.168.2.148.8.8.80xe204Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:29.619556904 CEST192.168.2.148.8.8.80xe204Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:29.836229086 CEST192.168.2.148.8.8.80xe204Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:33.039669037 CEST192.168.2.148.8.8.80x2917Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:33.224528074 CEST192.168.2.148.8.8.80x2917Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:33.421174049 CEST192.168.2.148.8.8.80x2917Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:33.604924917 CEST192.168.2.148.8.8.80x2917Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:33.789006948 CEST192.168.2.148.8.8.80x2917Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:35.973198891 CEST192.168.2.148.8.8.80xdd8aStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:36.187644005 CEST192.168.2.148.8.8.80xdd8aStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:36.384691000 CEST192.168.2.148.8.8.80xdd8aStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:36.600141048 CEST192.168.2.148.8.8.80xdd8aStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:36.827614069 CEST192.168.2.148.8.8.80xdd8aStandard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:47.040591955 CEST192.168.2.148.8.8.80x7131Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:47.238810062 CEST192.168.2.148.8.8.80x7131Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:47.465373039 CEST192.168.2.148.8.8.80x7131Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:47.654547930 CEST192.168.2.148.8.8.80x7131Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:47.851057053 CEST192.168.2.148.8.8.80x7131Standard query (0)cnc.condi.cloudA (IP address)IN (0x0001)false
    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
    Apr 18, 2024 07:59:46.948549986 CEST8.8.8.8192.168.2.140xf6faServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 07:59:47.131932974 CEST8.8.8.8192.168.2.140xf6faServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 07:59:47.334244967 CEST8.8.8.8192.168.2.140xf6faServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 07:59:47.517951965 CEST8.8.8.8192.168.2.140xf6faServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 07:59:47.701625109 CEST8.8.8.8192.168.2.140xf6faServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 07:59:51.898200989 CEST8.8.8.8192.168.2.140x468aServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 07:59:52.081671000 CEST8.8.8.8192.168.2.140x468aServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 07:59:52.265723944 CEST8.8.8.8192.168.2.140x468aServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 07:59:52.450360060 CEST8.8.8.8192.168.2.140x468aServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 07:59:52.633991003 CEST8.8.8.8192.168.2.140x468aServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 07:59:55.817697048 CEST8.8.8.8192.168.2.140x2ff2Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 07:59:56.019841909 CEST8.8.8.8192.168.2.140x2ff2Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 07:59:56.203500032 CEST8.8.8.8192.168.2.140x2ff2Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 07:59:56.386876106 CEST8.8.8.8192.168.2.140x2ff2Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 07:59:56.570341110 CEST8.8.8.8192.168.2.140x2ff2Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:02.754101038 CEST8.8.8.8192.168.2.140xcaa8Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:02.937650919 CEST8.8.8.8192.168.2.140xcaa8Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:03.121373892 CEST8.8.8.8192.168.2.140xcaa8Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:03.308938026 CEST8.8.8.8192.168.2.140xcaa8Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:03.542287111 CEST8.8.8.8192.168.2.140xcaa8Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:09.726397991 CEST8.8.8.8192.168.2.140xa12eServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:09.942184925 CEST8.8.8.8192.168.2.140xa12eServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:10.155698061 CEST8.8.8.8192.168.2.140xa12eServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:10.339857101 CEST8.8.8.8192.168.2.140xa12eServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:10.524296999 CEST8.8.8.8192.168.2.140xa12eServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:14.721690893 CEST8.8.8.8192.168.2.140x23a1Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:14.906235933 CEST8.8.8.8192.168.2.140x23a1Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:15.132921934 CEST8.8.8.8192.168.2.140x23a1Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:15.336913109 CEST8.8.8.8192.168.2.140x23a1Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:15.540225983 CEST8.8.8.8192.168.2.140x23a1Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:24.724495888 CEST8.8.8.8192.168.2.140x660bServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:24.921787024 CEST8.8.8.8192.168.2.140x660bServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:25.119848967 CEST8.8.8.8192.168.2.140x660bServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:25.316850901 CEST8.8.8.8192.168.2.140x660bServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:25.513696909 CEST8.8.8.8192.168.2.140x660bServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:28.710575104 CEST8.8.8.8192.168.2.140xea97Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:28.893897057 CEST8.8.8.8192.168.2.140xea97Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:29.090543032 CEST8.8.8.8192.168.2.140xea97Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:29.273555040 CEST8.8.8.8192.168.2.140xea97Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:29.470681906 CEST8.8.8.8192.168.2.140xea97Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:36.673547029 CEST8.8.8.8192.168.2.140x69f3Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:36.905941963 CEST8.8.8.8192.168.2.140x69f3Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:37.132483959 CEST8.8.8.8192.168.2.140x69f3Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:37.316299915 CEST8.8.8.8192.168.2.140x69f3Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:37.500693083 CEST8.8.8.8192.168.2.140x69f3Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:45.698384047 CEST8.8.8.8192.168.2.140x6c89Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:45.901597023 CEST8.8.8.8192.168.2.140x6c89Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:46.087308884 CEST8.8.8.8192.168.2.140x6c89Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:46.283981085 CEST8.8.8.8192.168.2.140x6c89Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:46.468306065 CEST8.8.8.8192.168.2.140x6c89Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:47.684854984 CEST8.8.8.8192.168.2.140xba21Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:47.868275881 CEST8.8.8.8192.168.2.140xba21Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:48.094039917 CEST8.8.8.8192.168.2.140xba21Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:48.278177977 CEST8.8.8.8192.168.2.140xba21Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:48.460906029 CEST8.8.8.8192.168.2.140xba21Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:52.644948006 CEST8.8.8.8192.168.2.140x57a7Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:52.829624891 CEST8.8.8.8192.168.2.140x57a7Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:53.026540995 CEST8.8.8.8192.168.2.140x57a7Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:53.242419958 CEST8.8.8.8192.168.2.140x57a7Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:53.426841021 CEST8.8.8.8192.168.2.140x57a7Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:59.622844934 CEST8.8.8.8192.168.2.140x674fServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:00:59.835685968 CEST8.8.8.8192.168.2.140x674fServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:00.061758995 CEST8.8.8.8192.168.2.140x674fServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:00.245811939 CEST8.8.8.8192.168.2.140x674fServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:00.429737091 CEST8.8.8.8192.168.2.140x674fServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:10.629762888 CEST8.8.8.8192.168.2.140xf09fServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:10.813534975 CEST8.8.8.8192.168.2.140xf09fServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:10.997620106 CEST8.8.8.8192.168.2.140xf09fServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:11.195067883 CEST8.8.8.8192.168.2.140xf09fServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:11.379558086 CEST8.8.8.8192.168.2.140xf09fServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:15.564397097 CEST8.8.8.8192.168.2.140x5db4Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:15.762249947 CEST8.8.8.8192.168.2.140x5db4Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:15.946124077 CEST8.8.8.8192.168.2.140x5db4Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:16.143855095 CEST8.8.8.8192.168.2.140x5db4Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:16.375581026 CEST8.8.8.8192.168.2.140x5db4Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:20.560750008 CEST8.8.8.8192.168.2.140x879fServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:20.774063110 CEST8.8.8.8192.168.2.140x879fServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:20.958498955 CEST8.8.8.8192.168.2.140x879fServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:21.142911911 CEST8.8.8.8192.168.2.140x879fServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:22.034096956 CEST8.8.8.8192.168.2.140x879fServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:29.225467920 CEST8.8.8.8192.168.2.140xe204Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:29.428054094 CEST8.8.8.8192.168.2.140xe204Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:29.619388103 CEST8.8.8.8192.168.2.140xe204Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:29.836000919 CEST8.8.8.8192.168.2.140xe204Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:30.039355993 CEST8.8.8.8192.168.2.140xe204Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:33.224353075 CEST8.8.8.8192.168.2.140x2917Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:33.421010017 CEST8.8.8.8192.168.2.140x2917Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:33.604779959 CEST8.8.8.8192.168.2.140x2917Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:33.788877010 CEST8.8.8.8192.168.2.140x2917Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:33.972978115 CEST8.8.8.8192.168.2.140x2917Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:36.187423944 CEST8.8.8.8192.168.2.140xdd8aServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:36.384558916 CEST8.8.8.8192.168.2.140xdd8aServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:36.599905014 CEST8.8.8.8192.168.2.140xdd8aServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:36.827447891 CEST8.8.8.8192.168.2.140xdd8aServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:37.040780067 CEST8.8.8.8192.168.2.140xdd8aServer failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:47.238677979 CEST8.8.8.8192.168.2.140x7131Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:47.465261936 CEST8.8.8.8192.168.2.140x7131Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:47.654369116 CEST8.8.8.8192.168.2.140x7131Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:47.850879908 CEST8.8.8.8192.168.2.140x7131Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false
    Apr 18, 2024 08:01:48.034682989 CEST8.8.8.8192.168.2.140x7131Server failure (2)cnc.condi.cloudnonenoneA (IP address)IN (0x0001)false

    System Behavior

    Start time (UTC):05:59:46
    Start date (UTC):18/04/2024
    Path:/tmp/NnDBvZKtdN.elf
    Arguments:/tmp/NnDBvZKtdN.elf
    File size:62316 bytes
    MD5 hash:8622bebd8e2cbc2b5771884826a0afe5

    Start time (UTC):05:59:46
    Start date (UTC):18/04/2024
    Path:/tmp/NnDBvZKtdN.elf
    Arguments:-
    File size:62316 bytes
    MD5 hash:8622bebd8e2cbc2b5771884826a0afe5

    Start time (UTC):05:59:46
    Start date (UTC):18/04/2024
    Path:/tmp/NnDBvZKtdN.elf
    Arguments:-
    File size:62316 bytes
    MD5 hash:8622bebd8e2cbc2b5771884826a0afe5