Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
9aDl048Kv4

Overview

General Information

Sample Name:9aDl048Kv4
Analysis ID:679617
MD5:a6d59f5e0ba33c23089b0e8e5f33dc82
SHA1:e54874d4f97c4e80610ea3bb298eb9d912d30f65
SHA256:04dac155bac0715d824c9f56aacd4148615bec0d761e7854da27f0fdeb827f95
Tags:32elfmipsmirai
Infos:

Detection

Mirai
Score:76
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Yara detected Mirai
Multi AV Scanner detection for submitted file
Uses known network protocols on non-standard ports
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might not execute correctly on this machine.
All HTTP servers contacted by the sample do not answer. The sample is likely an old dropper which does no longer work.
Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures.
Joe Sandbox Version:35.0.0 Citrine
Analysis ID:679617
Start date and time: 06/08/202206:33:442022-08-06 06:33:44 +02:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 5m 41s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:9aDl048Kv4
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal76.troj.lin@0/0@54/0
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100
Command:/tmp/9aDl048Kv4
PID:6230
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Connected To CNC
Standard Error:
  • system is lnxubuntu20
  • 9aDl048Kv4 (PID: 6230, Parent: 6125, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/9aDl048Kv4
  • cleanup
SourceRuleDescriptionAuthorStrings
9aDl048Kv4JoeSecurity_Mirai_8Yara detected MiraiJoe Security
    SourceRuleDescriptionAuthorStrings
    dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security
      SourceRuleDescriptionAuthorStrings
      6243.1.00007f96e8400000.00007f96e841b000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
        6330.1.00007f96e8400000.00007f96e841b000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          6230.1.00007f96e8400000.00007f96e841b000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
            No Snort rule has matched

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: 9aDl048Kv4Avira: detected
            Source: 9aDl048Kv4Virustotal: Detection: 55%Perma Link
            Source: 9aDl048Kv4Metadefender: Detection: 31%Perma Link
            Source: 9aDl048Kv4ReversingLabs: Detection: 69%

            Networking

            barindex
            Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58628
            Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58632
            Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58638
            Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58644
            Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58652
            Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58656
            Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58658
            Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58660
            Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58662
            Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58664
            Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
            Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
            Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
            Source: global trafficTCP traffic: 192.168.2.23:53436 -> 46.23.109.40:1312
            Source: global trafficTCP traffic: 192.168.2.23:52298 -> 218.212.106.223:7547
            Source: /tmp/9aDl048Kv4 (PID: 6230)Socket: 127.0.0.1::1312
            Source: /tmp/9aDl048Kv4 (PID: 6242)Socket: 0.0.0.0::0
            Source: /tmp/9aDl048Kv4 (PID: 6242)Socket: 0.0.0.0::23
            Source: /tmp/9aDl048Kv4 (PID: 6242)Socket: 0.0.0.0::53413
            Source: /tmp/9aDl048Kv4 (PID: 6242)Socket: 0.0.0.0::80
            Source: /tmp/9aDl048Kv4 (PID: 6242)Socket: 0.0.0.0::52869
            Source: /tmp/9aDl048Kv4 (PID: 6242)Socket: 0.0.0.0::37215
            Source: unknownDNS traffic detected: queries for: arcticboatz.cz
            Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
            Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
            Source: unknownTCP traffic detected without corresponding DNS query: 222.217.156.56
            Source: unknownTCP traffic detected without corresponding DNS query: 245.20.167.18
            Source: unknownTCP traffic detected without corresponding DNS query: 162.239.246.112
            Source: unknownTCP traffic detected without corresponding DNS query: 98.138.227.65
            Source: unknownTCP traffic detected without corresponding DNS query: 87.206.111.62
            Source: unknownTCP traffic detected without corresponding DNS query: 78.112.121.17
            Source: unknownTCP traffic detected without corresponding DNS query: 223.157.163.154
            Source: unknownTCP traffic detected without corresponding DNS query: 219.131.214.147
            Source: unknownTCP traffic detected without corresponding DNS query: 117.79.105.79
            Source: unknownTCP traffic detected without corresponding DNS query: 59.202.7.169
            Source: unknownTCP traffic detected without corresponding DNS query: 136.54.248.181
            Source: unknownTCP traffic detected without corresponding DNS query: 142.158.32.123
            Source: unknownTCP traffic detected without corresponding DNS query: 197.186.44.15
            Source: unknownTCP traffic detected without corresponding DNS query: 135.180.200.4
            Source: unknownTCP traffic detected without corresponding DNS query: 12.84.166.159
            Source: unknownTCP traffic detected without corresponding DNS query: 196.76.68.26
            Source: unknownTCP traffic detected without corresponding DNS query: 161.62.105.28
            Source: unknownTCP traffic detected without corresponding DNS query: 14.119.197.64
            Source: unknownTCP traffic detected without corresponding DNS query: 66.142.20.96
            Source: unknownTCP traffic detected without corresponding DNS query: 36.123.152.125
            Source: unknownTCP traffic detected without corresponding DNS query: 19.101.78.36
            Source: unknownTCP traffic detected without corresponding DNS query: 105.124.49.201
            Source: unknownTCP traffic detected without corresponding DNS query: 59.89.176.50
            Source: unknownTCP traffic detected without corresponding DNS query: 165.3.182.140
            Source: unknownTCP traffic detected without corresponding DNS query: 97.227.225.137
            Source: unknownTCP traffic detected without corresponding DNS query: 63.168.45.177
            Source: unknownTCP traffic detected without corresponding DNS query: 154.33.231.225
            Source: unknownTCP traffic detected without corresponding DNS query: 41.235.228.41
            Source: unknownTCP traffic detected without corresponding DNS query: 213.102.46.105
            Source: unknownTCP traffic detected without corresponding DNS query: 217.241.206.214
            Source: unknownTCP traffic detected without corresponding DNS query: 159.135.126.178
            Source: unknownTCP traffic detected without corresponding DNS query: 208.28.95.189
            Source: unknownTCP traffic detected without corresponding DNS query: 116.151.139.183
            Source: unknownTCP traffic detected without corresponding DNS query: 172.252.85.196
            Source: unknownTCP traffic detected without corresponding DNS query: 32.106.160.166
            Source: unknownTCP traffic detected without corresponding DNS query: 92.224.116.20
            Source: unknownTCP traffic detected without corresponding DNS query: 157.75.162.126
            Source: unknownTCP traffic detected without corresponding DNS query: 184.221.156.118
            Source: unknownTCP traffic detected without corresponding DNS query: 188.242.194.107
            Source: unknownTCP traffic detected without corresponding DNS query: 200.117.135.242
            Source: unknownTCP traffic detected without corresponding DNS query: 191.120.198.243
            Source: unknownTCP traffic detected without corresponding DNS query: 221.55.155.170
            Source: unknownTCP traffic detected without corresponding DNS query: 141.54.35.99
            Source: unknownTCP traffic detected without corresponding DNS query: 149.123.92.26
            Source: unknownTCP traffic detected without corresponding DNS query: 74.240.94.234
            Source: unknownTCP traffic detected without corresponding DNS query: 196.222.24.38
            Source: unknownTCP traffic detected without corresponding DNS query: 243.188.199.249
            Source: unknownTCP traffic detected without corresponding DNS query: 13.79.185.74
            Source: unknownTCP traffic detected without corresponding DNS query: 207.227.127.113
            Source: ELF static info symbol of initial sample.symtab present: no
            Source: /tmp/9aDl048Kv4 (PID: 6242)SIGKILL sent: pid: 936, result: successful
            Source: Initial sampleString containing 'busybox' found: /bin/busybox AK1K2
            Source: Initial sampleString containing 'busybox' found: /bin/busybox cp /bin/busybox retrieve && >retrieve && /bin/busybox chmod 777 retrieve && /bin/busybox cp /bin/busybox .t && >.t && /bin/busybox chmod 777 .t
            Source: Initial sampleString containing 'busybox' found: /bin/busybox echo -en '%s' %s %s && /bin/busybox echo -en '\x45\x43\x48\x4f\x44\x4f\x4e\x45'
            Source: Initial sampleString containing 'busybox' found: >%st && cd %s && >retrieve; >.t/bin/busybox cp /bin/busybox retrieve && >retrieve && /bin/busybox chmod 777 retrieve && /bin/busybox cp /bin/busybox .t && >.t && /bin/busybox chmod 777 .t
            Source: Initial sampleString containing 'busybox' found: >>>/bin/busybox echo -en '%s' %s %s && /bin/busybox echo -en '\x45\x43\x48\x4f\x44\x4f\x4e\x45'
            Source: classification engineClassification label: mal76.troj.lin@0/0@54/0
            Source: /tmp/9aDl048Kv4 (PID: 6242)File opened: /proc/491/fd
            Source: /tmp/9aDl048Kv4 (PID: 6242)File opened: /proc/793/fd
            Source: /tmp/9aDl048Kv4 (PID: 6242)File opened: /proc/772/fd
            Source: /tmp/9aDl048Kv4 (PID: 6242)File opened: /proc/796/fd
            Source: /tmp/9aDl048Kv4 (PID: 6242)File opened: /proc/774/fd
            Source: /tmp/9aDl048Kv4 (PID: 6242)File opened: /proc/797/fd
            Source: /tmp/9aDl048Kv4 (PID: 6242)File opened: /proc/777/fd
            Source: /tmp/9aDl048Kv4 (PID: 6242)File opened: /proc/799/fd
            Source: /tmp/9aDl048Kv4 (PID: 6242)File opened: /proc/658/fd
            Source: /tmp/9aDl048Kv4 (PID: 6242)File opened: /proc/912/fd
            Source: /tmp/9aDl048Kv4 (PID: 6242)File opened: /proc/759/fd
            Source: /tmp/9aDl048Kv4 (PID: 6242)File opened: /proc/936/fd
            Source: /tmp/9aDl048Kv4 (PID: 6242)File opened: /proc/918/fd
            Source: /tmp/9aDl048Kv4 (PID: 6242)File opened: /proc/1/fd
            Source: /tmp/9aDl048Kv4 (PID: 6242)File opened: /proc/761/fd
            Source: /tmp/9aDl048Kv4 (PID: 6242)File opened: /proc/785/fd
            Source: /tmp/9aDl048Kv4 (PID: 6242)File opened: /proc/884/fd
            Source: /tmp/9aDl048Kv4 (PID: 6242)File opened: /proc/720/fd
            Source: /tmp/9aDl048Kv4 (PID: 6242)File opened: /proc/721/fd
            Source: /tmp/9aDl048Kv4 (PID: 6242)File opened: /proc/788/fd
            Source: /tmp/9aDl048Kv4 (PID: 6242)File opened: /proc/789/fd
            Source: /tmp/9aDl048Kv4 (PID: 6242)File opened: /proc/800/fd
            Source: /tmp/9aDl048Kv4 (PID: 6242)File opened: /proc/801/fd
            Source: /tmp/9aDl048Kv4 (PID: 6242)File opened: /proc/847/fd
            Source: /tmp/9aDl048Kv4 (PID: 6242)File opened: /proc/904/fd

            Hooking and other Techniques for Hiding and Protection

            barindex
            Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58628
            Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58632
            Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58638
            Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58644
            Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58652
            Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58656
            Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58658
            Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58660
            Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58662
            Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58664
            Source: /tmp/9aDl048Kv4 (PID: 6230)Queries kernel information via 'uname':
            Source: 9aDl048Kv4, 6230.1.0000556b34b2d000.0000556b34bb4000.rw-.sdmp, 9aDl048Kv4, 6330.1.0000556b34b2d000.0000556b34bb4000.rw-.sdmp, 9aDl048Kv4, 6243.1.0000556b34b2d000.0000556b34bb4000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
            Source: 9aDl048Kv4, 6230.1.0000556b34b2d000.0000556b34bb4000.rw-.sdmp, 9aDl048Kv4, 6330.1.0000556b34b2d000.0000556b34bb4000.rw-.sdmp, 9aDl048Kv4, 6243.1.0000556b34b2d000.0000556b34bb4000.rw-.sdmpBinary or memory string: 4kU!/etc/qemu-binfmt/mips
            Source: 9aDl048Kv4, 6230.1.00007fff215f0000.00007fff21611000.rw-.sdmp, 9aDl048Kv4, 6330.1.00007fff215f0000.00007fff21611000.rw-.sdmp, 9aDl048Kv4, 6243.1.00007fff215f0000.00007fff21611000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
            Source: 9aDl048Kv4, 6230.1.00007fff215f0000.00007fff21611000.rw-.sdmp, 9aDl048Kv4, 6330.1.00007fff215f0000.00007fff21611000.rw-.sdmp, 9aDl048Kv4, 6243.1.00007fff215f0000.00007fff21611000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/9aDl048Kv4SUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/9aDl048Kv4

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: dump.pcap, type: PCAP
            Source: Yara matchFile source: 9aDl048Kv4, type: SAMPLE
            Source: Yara matchFile source: 6243.1.00007f96e8400000.00007f96e841b000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6330.1.00007f96e8400000.00007f96e841b000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6230.1.00007f96e8400000.00007f96e841b000.r-x.sdmp, type: MEMORY

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: dump.pcap, type: PCAP
            Source: Yara matchFile source: 9aDl048Kv4, type: SAMPLE
            Source: Yara matchFile source: 6243.1.00007f96e8400000.00007f96e841b000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6330.1.00007f96e8400000.00007f96e841b000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6230.1.00007f96e8400000.00007f96e841b000.r-x.sdmp, type: MEMORY
            Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
            Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume Access1
            OS Credential Dumping
            11
            Security Software Discovery
            Remote ServicesData from Local SystemExfiltration Over Other Network Medium1
            Encrypted Channel
            Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
            Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth11
            Non-Standard Port
            Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
            Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration1
            Non-Application Layer Protocol
            Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
            Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer2
            Application Layer Protocol
            SIM Card SwapCarrier Billing Fraud
            No configs have been found
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Number of created Files
            • Is malicious
            • Internet
            behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 679617 Sample: 9aDl048Kv4 Startdate: 06/08/2022 Architecture: LINUX Score: 76 25 arcticboatz.cz 2->25 27 45.214.228.50 ZAIN-ZAMBIAZM Zambia 2->27 29 99 other IPs or domains 2->29 31 Antivirus / Scanner detection for submitted sample 2->31 33 Multi AV Scanner detection for submitted file 2->33 35 Yara detected Mirai 2->35 37 Uses known network protocols on non-standard ports 2->37 9 9aDl048Kv4 2->9         started        signatures3 process4 process5 11 9aDl048Kv4 9->11         started        13 9aDl048Kv4 9->13         started        15 9aDl048Kv4 9->15         started        17 9aDl048Kv4 9->17         started        process6 19 9aDl048Kv4 11->19         started        21 9aDl048Kv4 11->21         started        process7 23 9aDl048Kv4 19->23         started       
            SourceDetectionScannerLabelLink
            9aDl048Kv456%VirustotalBrowse
            9aDl048Kv431%MetadefenderBrowse
            9aDl048Kv469%ReversingLabsLinux.Trojan.Mirai
            9aDl048Kv4100%AviraLINUX/Mirai.ckhvs
            No Antivirus matches
            SourceDetectionScannerLabelLink
            arcticboatz.cz12%VirustotalBrowse
            No Antivirus matches
            NameIPActiveMaliciousAntivirus DetectionReputation
            arcticboatz.cz
            46.23.109.40
            truetrueunknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            112.38.81.126
            unknownChina
            24444CMNET-V4SHANDONG-AS-APShandongMobileCommunicationCompanyfalse
            209.188.192.80
            unknownUnited States
            2152CSUNET-NWUSfalse
            31.119.143.132
            unknownUnited Kingdom
            12576EELtdGBfalse
            168.142.106.78
            unknownSouth Africa
            3741ISZAfalse
            241.238.198.119
            unknownReserved
            unknownunknownfalse
            71.207.101.131
            unknownUnited States
            7922COMCAST-7922USfalse
            243.94.91.52
            unknownReserved
            unknownunknownfalse
            82.134.138.59
            unknownNetherlands
            8542BKK-DIGITEK-AS8542NorwayNOfalse
            103.207.37.116
            unknownViet Nam
            45899VNPT-AS-VNVNPTCorpVNfalse
            167.94.84.200
            unknownUnited States
            20278NEXEONUSfalse
            71.234.44.99
            unknownUnited States
            7922COMCAST-7922USfalse
            20.136.114.213
            unknownUnited States
            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
            92.173.69.212
            unknownFrance
            3215FranceTelecom-OrangeFRfalse
            31.251.56.59
            unknownGermany
            3320DTAGInternetserviceprovideroperationsDEfalse
            1.232.219.196
            unknownKorea Republic of
            9318SKB-ASSKBroadbandCoLtdKRfalse
            8.85.206.249
            unknownUnited States
            3356LEVEL3USfalse
            14.215.188.237
            unknownChina
            58466CT-GUANGZHOU-IDCCHINANETGuangdongprovincenetworkCNfalse
            143.26.217.182
            unknownUnited States
            264008LANCAMANTOANISERVICOSDEINFORMATICALTDA-MEBRfalse
            69.71.53.125
            unknownUnited States
            12025IMDC-AS12025USfalse
            133.42.124.105
            unknownJapan24248ASN-WADAI-UWakayamaUniversityJPfalse
            161.247.27.70
            unknownUnited States
            26539GIANT-FOOD-INCUSfalse
            4.224.225.38
            unknownUnited States
            3356LEVEL3USfalse
            99.32.231.102
            unknownUnited States
            7018ATT-INTERNET4USfalse
            178.192.103.30
            unknownSwitzerland
            3303SWISSCOMSwisscomSwitzerlandLtdCHfalse
            32.131.98.93
            unknownUnited States
            2686ATGS-MMD-ASUSfalse
            41.115.224.79
            unknownSouth Africa
            16637MTNNS-ASZAfalse
            45.214.228.50
            unknownZambia
            37287ZAIN-ZAMBIAZMfalse
            246.188.239.90
            unknownReserved
            unknownunknownfalse
            241.58.255.17
            unknownReserved
            unknownunknownfalse
            123.169.33.124
            unknownChina
            4809CHINATELECOM-CORE-WAN-CN2ChinaTelecomNextGenerationCarrfalse
            206.46.248.32
            unknownUnited States
            7021VRIS-7021USfalse
            40.97.188.119
            unknownUnited States
            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
            253.118.91.171
            unknownReserved
            unknownunknownfalse
            247.195.117.119
            unknownReserved
            unknownunknownfalse
            43.250.74.242
            unknownChina
            40676AS40676USfalse
            253.63.64.212
            unknownReserved
            unknownunknownfalse
            103.220.236.234
            unknownIndia
            139490ASPTNPL-AS-INAsptNetworksPvtLtdINfalse
            123.31.89.9
            unknownViet Nam
            45899VNPT-AS-VNVNPTCorpVNfalse
            166.148.219.208
            unknownUnited States
            22394CELLCOUSfalse
            181.154.150.72
            unknownColombia
            26611COMCELSACOfalse
            59.128.228.32
            unknownJapan2516KDDIKDDICORPORATIONJPfalse
            168.235.188.124
            unknownUnited States
            22925ALLIED-TELECOMUSfalse
            217.98.115.142
            unknownPoland
            5617TPNETPLfalse
            2.254.55.207
            unknownSweden
            3301TELIANET-SWEDENTeliaCompanySEfalse
            208.197.249.2
            unknownUnited States
            7029WINDSTREAMUSfalse
            211.252.213.234
            unknownKorea Republic of
            4766KIXS-AS-KRKoreaTelecomKRfalse
            80.41.144.0
            unknownUnited Kingdom
            9105TISCALI-UKTalkTalkCommunicationsLimitedGBfalse
            13.213.186.117
            unknownUnited States
            16509AMAZON-02USfalse
            174.99.178.10
            unknownUnited States
            10796TWC-10796-MIDWESTUSfalse
            96.132.30.42
            unknownUnited States
            7922COMCAST-7922USfalse
            174.228.87.35
            unknownUnited States
            22394CELLCOUSfalse
            206.139.220.116
            unknownUnited States
            701UUNETUSfalse
            180.222.63.58
            unknownJapan18371NCABLE-APNeighbourhoodCableAUfalse
            201.53.53.71
            unknownBrazil
            28573CLAROSABRfalse
            190.32.220.66
            unknownPanama
            11556CableWirelessPanamaPAfalse
            9.193.186.225
            unknownUnited States
            3356LEVEL3USfalse
            240.115.82.109
            unknownReserved
            unknownunknownfalse
            105.22.200.55
            unknownMauritius
            37100SEACOM-ASMUfalse
            150.115.207.2
            unknownChina
            2516KDDIKDDICORPORATIONJPfalse
            32.217.248.222
            unknownUnited States
            46690SNET-FCCUSfalse
            247.116.205.32
            unknownReserved
            unknownunknownfalse
            81.98.166.242
            unknownUnited Kingdom
            5089NTLGBfalse
            165.96.21.17
            unknownJapan37053RSAWEB-ASZAfalse
            122.41.44.128
            unknownKorea Republic of
            17858POWERVIS-AS-KRLGPOWERCOMMKRfalse
            248.211.248.7
            unknownReserved
            unknownunknownfalse
            248.175.187.185
            unknownReserved
            unknownunknownfalse
            216.4.100.227
            unknownUnited States
            393577SCCNETUSfalse
            219.130.114.139
            unknownChina
            4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
            8.196.29.161
            unknownUnited States
            3356LEVEL3USfalse
            17.36.150.157
            unknownUnited States
            714APPLE-ENGINEERINGUSfalse
            114.41.153.116
            unknownTaiwan; Republic of China (ROC)
            3462HINETDataCommunicationBusinessGroupTWfalse
            247.209.22.244
            unknownReserved
            unknownunknownfalse
            194.61.190.0
            unknownUnited Kingdom
            24775AS24775GBfalse
            148.11.87.103
            unknownUnited States
            3946739408USfalse
            196.40.197.88
            unknownNigeria
            36974AFNET-ASCIfalse
            99.123.148.139
            unknownUnited States
            7018ATT-INTERNET4USfalse
            204.66.36.171
            unknownUnited States
            1761TDIR-CAPNETUSfalse
            187.126.17.235
            unknownBrazil
            7738TelemarNorteLesteSABRfalse
            73.217.152.6
            unknownUnited States
            7922COMCAST-7922USfalse
            197.183.150.216
            unknownKenya
            33771SAFARICOM-LIMITEDKEfalse
            19.104.141.57
            unknownUnited States
            3MIT-GATEWAYSUSfalse
            182.85.190.52
            unknownChina
            4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
            172.159.109.57
            unknownUnited States
            7018ATT-INTERNET4USfalse
            145.19.236.45
            unknownNetherlands
            1103SURFNET-NLSURFnetTheNetherlandsNLfalse
            91.52.17.228
            unknownGermany
            3320DTAGInternetserviceprovideroperationsDEfalse
            119.47.34.76
            unknownJapan7679QTNETQTnetIncJPfalse
            12.77.56.175
            unknownUnited States
            7018ATT-INTERNET4USfalse
            183.238.72.237
            unknownChina
            56040CMNET-GUANGDONG-APChinaMobilecommunicationscorporationfalse
            19.113.192.29
            unknownUnited States
            3MIT-GATEWAYSUSfalse
            114.183.221.23
            unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
            217.227.178.81
            unknownGermany
            3320DTAGInternetserviceprovideroperationsDEfalse
            191.210.231.186
            unknownBrazil
            26599TELEFONICABRASILSABRfalse
            163.123.126.190
            unknownUnited States
            1767ILIGHT-NETUSfalse
            98.31.236.200
            unknownUnited States
            10796TWC-10796-MIDWESTUSfalse
            121.246.90.149
            unknownIndia
            17908TCISLTataCommunicationsINfalse
            122.213.81.165
            unknownJapan17506UCOMARTERIANetworksCorporationJPfalse
            175.172.190.121
            unknownChina
            4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
            175.37.77.244
            unknownAustralia
            4804MPX-ASMicroplexPTYLTDAUfalse
            222.209.131.130
            unknownChina
            4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
            213.197.169.187
            unknownLithuania
            15440BALTNETACustomersASLTfalse
            No context
            No context
            No context
            No context
            No context
            No created / dropped files found
            File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
            Entropy (8bit):5.624887608307235
            TrID:
            • ELF Executable and Linkable format (generic) (4004/1) 100.00%
            File name:9aDl048Kv4
            File size:114356
            MD5:a6d59f5e0ba33c23089b0e8e5f33dc82
            SHA1:e54874d4f97c4e80610ea3bb298eb9d912d30f65
            SHA256:04dac155bac0715d824c9f56aacd4148615bec0d761e7854da27f0fdeb827f95
            SHA512:da0817d6f3b65997e197a9991938180e7a88e3b8ae89a835684a238fabf438c71f60316833377c24f354ed224bf699049397ad8a0c72ab454a305c7a80605530
            SSDEEP:1536:8RTc+b0cmOw9tepIZ2axAzVQs842JnFhKeFuOg6HmG1eMEXSJYWsz0c2:2TRbnIyzVQs8XtFnFuOg6HmGWX8tsz0f
            TLSH:DAB3C71E3E218F7EF7ACC23847B74A21975923D527F0D185D16CE9015EA038E646FBA8
            File Content Preview:.ELF.....................@.`...4.........4. ...(.............@...@...........................E...E..... ..8.........dt.Q............................<...'.6....!'.......................<...'.6....!... ....'9... ......................<...'.6h...!........'9.

            ELF header

            Class:ELF32
            Data:2's complement, big endian
            Version:1 (current)
            Machine:MIPS R3000
            Version Number:0x1
            Type:EXEC (Executable file)
            OS/ABI:UNIX - System V
            ABI Version:0
            Entry Point Address:0x400260
            Flags:0x1007
            ELF Header Size:52
            Program Header Offset:52
            Program Header Size:32
            Number of Program Headers:3
            Section Header Offset:113796
            Section Header Size:40
            Number of Section Headers:14
            Header String Table Index:13
            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
            NULL0x00x00x00x00x0000
            .initPROGBITS0x4000940x940x8c0x00x6AX004
            .textPROGBITS0x4001200x1200x18a600x00x6AX0016
            .finiPROGBITS0x418b800x18b800x5c0x00x6AX004
            .rodataPROGBITS0x418be00x18be00x22c00x00x2A0016
            .ctorsPROGBITS0x45b0000x1b0000x80x00x3WA004
            .dtorsPROGBITS0x45b0080x1b0080x80x00x3WA004
            .data.rel.roPROGBITS0x45b0140x1b0140x80x00x3WA004
            .dataPROGBITS0x45b0200x1b0200x7400x00x3WA0016
            .gotPROGBITS0x45b7600x1b7600x4c00x40x10000003WAp0016
            .sbssNOBITS0x45bc200x1bc200x240x00x10000003WAp004
            .bssNOBITS0x45bc500x1bc200x2c400x00x3WA0016
            .mdebug.abi32PROGBITS0x9360x1bc200x00x00x0001
            .shstrtabSTRTAB0x00x1bc200x640x00x0001
            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
            LOAD0x00x4000000x4000000x1aea00x1aea05.64070x5R E0x10000.init .text .fini .rodata
            LOAD0x1b0000x45b0000x45b0000xc200x38904.79090x6RW 0x10000.ctors .dtors .data.rel.ro .data .got .sbss .bss
            GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
            TimestampSource PortDest PortSource IPDest IP
            Aug 6, 2022 06:34:30.732768059 CEST42836443192.168.2.2391.189.91.43
            Aug 6, 2022 06:34:30.975199938 CEST584923192.168.2.23222.217.156.56
            Aug 6, 2022 06:34:30.975253105 CEST584923192.168.2.23245.20.167.18
            Aug 6, 2022 06:34:30.975307941 CEST584923192.168.2.23162.239.246.112
            Aug 6, 2022 06:34:30.975322008 CEST584923192.168.2.2398.138.227.65
            Aug 6, 2022 06:34:30.975321054 CEST584923192.168.2.2387.206.111.62
            Aug 6, 2022 06:34:30.975327969 CEST584923192.168.2.2378.112.121.17
            Aug 6, 2022 06:34:30.975369930 CEST584923192.168.2.23223.157.163.154
            Aug 6, 2022 06:34:30.975394011 CEST584923192.168.2.23219.131.214.147
            Aug 6, 2022 06:34:30.975398064 CEST584923192.168.2.23117.79.105.79
            Aug 6, 2022 06:34:30.975411892 CEST584923192.168.2.2359.202.7.169
            Aug 6, 2022 06:34:30.975419044 CEST584923192.168.2.23136.54.248.181
            Aug 6, 2022 06:34:30.975445986 CEST584923192.168.2.23142.158.32.123
            Aug 6, 2022 06:34:30.975445032 CEST584923192.168.2.23197.186.44.15
            Aug 6, 2022 06:34:30.975450993 CEST584923192.168.2.23135.180.200.4
            Aug 6, 2022 06:34:30.975464106 CEST584923192.168.2.23205.210.128.208
            Aug 6, 2022 06:34:30.975483894 CEST584923192.168.2.2312.84.166.159
            Aug 6, 2022 06:34:30.975490093 CEST584923192.168.2.23196.76.68.26
            Aug 6, 2022 06:34:30.975490093 CEST584923192.168.2.23161.62.105.28
            Aug 6, 2022 06:34:30.975497007 CEST584923192.168.2.2314.119.197.64
            Aug 6, 2022 06:34:30.975505114 CEST584923192.168.2.2366.142.20.96
            Aug 6, 2022 06:34:30.975519896 CEST584923192.168.2.2336.123.152.125
            Aug 6, 2022 06:34:30.975526094 CEST584923192.168.2.2319.101.78.36
            Aug 6, 2022 06:34:30.975527048 CEST584923192.168.2.23105.124.49.201
            Aug 6, 2022 06:34:30.975537062 CEST584923192.168.2.2359.89.176.50
            Aug 6, 2022 06:34:30.975570917 CEST584923192.168.2.23193.110.11.2
            Aug 6, 2022 06:34:30.975605965 CEST584923192.168.2.23165.3.182.140
            Aug 6, 2022 06:34:30.975605965 CEST584923192.168.2.2397.227.225.137
            Aug 6, 2022 06:34:30.975620031 CEST584923192.168.2.2363.168.45.177
            Aug 6, 2022 06:34:30.975632906 CEST584923192.168.2.23154.33.231.225
            Aug 6, 2022 06:34:30.975636959 CEST584923192.168.2.2341.235.228.41
            Aug 6, 2022 06:34:30.975647926 CEST584923192.168.2.23213.102.46.105
            Aug 6, 2022 06:34:30.975752115 CEST584923192.168.2.23217.241.206.214
            Aug 6, 2022 06:34:30.975765944 CEST584923192.168.2.23159.135.126.178
            Aug 6, 2022 06:34:30.976948023 CEST584923192.168.2.23208.28.95.189
            Aug 6, 2022 06:34:30.976999998 CEST584923192.168.2.23116.151.139.183
            Aug 6, 2022 06:34:30.977010965 CEST584923192.168.2.23172.252.85.196
            Aug 6, 2022 06:34:30.977010965 CEST584923192.168.2.2332.106.160.166
            Aug 6, 2022 06:34:30.977015018 CEST584923192.168.2.2392.224.116.20
            Aug 6, 2022 06:34:30.977021933 CEST584923192.168.2.23157.75.162.126
            Aug 6, 2022 06:34:30.977041006 CEST584923192.168.2.23184.221.156.118
            Aug 6, 2022 06:34:30.977044106 CEST584923192.168.2.23188.242.194.107
            Aug 6, 2022 06:34:30.977045059 CEST584923192.168.2.23200.117.135.242
            Aug 6, 2022 06:34:30.977045059 CEST584923192.168.2.23191.120.198.243
            Aug 6, 2022 06:34:30.977076054 CEST584923192.168.2.23221.55.155.170
            Aug 6, 2022 06:34:30.977087975 CEST584923192.168.2.23141.54.35.99
            Aug 6, 2022 06:34:30.977098942 CEST584923192.168.2.23149.123.92.26
            Aug 6, 2022 06:34:30.977099895 CEST584923192.168.2.2374.240.94.234
            Aug 6, 2022 06:34:30.977121115 CEST584923192.168.2.23196.222.24.38
            Aug 6, 2022 06:34:30.977128983 CEST584923192.168.2.23243.188.199.249
            Aug 6, 2022 06:34:30.977149963 CEST584923192.168.2.2313.79.185.74
            Aug 6, 2022 06:34:30.977190018 CEST584923192.168.2.23207.227.127.113
            Aug 6, 2022 06:34:30.977190971 CEST584923192.168.2.23208.194.124.185
            Aug 6, 2022 06:34:30.977233887 CEST584923192.168.2.2392.105.207.71
            Aug 6, 2022 06:34:30.977236986 CEST584923192.168.2.2313.219.250.37
            Aug 6, 2022 06:34:30.978032112 CEST584923192.168.2.23198.131.104.211
            Aug 6, 2022 06:34:30.978059053 CEST584923192.168.2.234.91.152.94
            Aug 6, 2022 06:34:30.978080988 CEST584923192.168.2.23144.49.228.199
            Aug 6, 2022 06:34:30.978095055 CEST584923192.168.2.2365.160.196.136
            Aug 6, 2022 06:34:30.978117943 CEST584923192.168.2.23162.165.151.181
            Aug 6, 2022 06:34:30.978132010 CEST584923192.168.2.23100.31.46.37
            Aug 6, 2022 06:34:30.978156090 CEST584923192.168.2.23194.179.159.251
            Aug 6, 2022 06:34:30.978174925 CEST584923192.168.2.23186.174.3.184
            Aug 6, 2022 06:34:30.979909897 CEST584923192.168.2.23100.48.102.100
            Aug 6, 2022 06:34:30.979963064 CEST584923192.168.2.23164.95.55.211
            Aug 6, 2022 06:34:30.979984999 CEST584923192.168.2.23190.141.20.236
            Aug 6, 2022 06:34:30.979999065 CEST584923192.168.2.2391.99.31.248
            Aug 6, 2022 06:34:30.980007887 CEST584923192.168.2.23166.215.124.31
            Aug 6, 2022 06:34:30.980011940 CEST584923192.168.2.2340.235.222.32
            Aug 6, 2022 06:34:30.980062962 CEST584923192.168.2.23107.242.94.224
            Aug 6, 2022 06:34:30.980063915 CEST584923192.168.2.23164.94.186.214
            Aug 6, 2022 06:34:30.980077982 CEST584923192.168.2.2393.230.242.184
            Aug 6, 2022 06:34:30.980089903 CEST584923192.168.2.23205.215.43.124
            Aug 6, 2022 06:34:30.980103970 CEST584923192.168.2.23122.5.145.238
            Aug 6, 2022 06:34:30.980107069 CEST584923192.168.2.23151.238.15.33
            Aug 6, 2022 06:34:30.980113983 CEST584923192.168.2.23115.165.49.164
            Aug 6, 2022 06:34:30.980134010 CEST584923192.168.2.23183.128.243.245
            Aug 6, 2022 06:34:30.980139017 CEST584923192.168.2.23102.222.10.110
            Aug 6, 2022 06:34:30.980144024 CEST584923192.168.2.2353.229.99.169
            Aug 6, 2022 06:34:30.980154037 CEST584923192.168.2.23113.123.72.62
            Aug 6, 2022 06:34:30.980161905 CEST584923192.168.2.23142.211.179.14
            Aug 6, 2022 06:34:30.980160952 CEST584923192.168.2.23252.221.157.25
            Aug 6, 2022 06:34:30.980166912 CEST584923192.168.2.2379.150.239.82
            Aug 6, 2022 06:34:30.980169058 CEST584923192.168.2.2319.202.111.62
            Aug 6, 2022 06:34:30.980191946 CEST584923192.168.2.2377.187.117.133
            Aug 6, 2022 06:34:30.980197906 CEST584923192.168.2.23242.90.158.165
            Aug 6, 2022 06:34:30.980200052 CEST584923192.168.2.23118.68.92.211
            Aug 6, 2022 06:34:30.980210066 CEST584923192.168.2.23161.22.183.23
            Aug 6, 2022 06:34:30.980211973 CEST584923192.168.2.23103.127.90.238
            Aug 6, 2022 06:34:30.980221987 CEST584923192.168.2.2383.22.11.82
            Aug 6, 2022 06:34:30.980235100 CEST584923192.168.2.2395.30.92.234
            Aug 6, 2022 06:34:30.980247021 CEST584923192.168.2.23216.82.132.218
            Aug 6, 2022 06:34:30.980258942 CEST584923192.168.2.2353.89.87.102
            Aug 6, 2022 06:34:30.980259895 CEST584923192.168.2.239.111.132.78
            Aug 6, 2022 06:34:30.980267048 CEST584923192.168.2.2381.177.46.157
            Aug 6, 2022 06:34:30.980278969 CEST584923192.168.2.23250.55.66.62
            Aug 6, 2022 06:34:30.980279922 CEST584923192.168.2.23159.198.90.46
            Aug 6, 2022 06:34:30.980294943 CEST584923192.168.2.2394.38.181.153
            Aug 6, 2022 06:34:30.980314016 CEST584923192.168.2.23125.215.80.21
            Aug 6, 2022 06:34:30.980320930 CEST584923192.168.2.23197.168.61.231
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
            Aug 6, 2022 06:34:30.984601974 CEST192.168.2.238.8.8.80x4c95Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:34:33.042846918 CEST192.168.2.238.8.8.80xa3eeStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:34:38.091512918 CEST192.168.2.238.8.8.80x41aStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:34:43.161137104 CEST192.168.2.238.8.8.80xfa2fStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:34:50.209662914 CEST192.168.2.238.8.8.80x37e6Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:34:52.255748034 CEST192.168.2.238.8.8.80x5d33Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:35:02.321718931 CEST192.168.2.238.8.8.80xdfdeStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:35:08.369952917 CEST192.168.2.238.8.8.80xf05aStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:35:13.417853117 CEST192.168.2.238.8.8.80x5135Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:35:16.467514992 CEST192.168.2.238.8.8.80x2756Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:35:18.513750076 CEST192.168.2.238.8.8.80xdf13Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:35:22.562899113 CEST192.168.2.238.8.8.80x8306Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:35:23.613262892 CEST192.168.2.238.8.8.80xe356Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:35:31.661303043 CEST192.168.2.238.8.8.80x5cStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:35:36.709366083 CEST192.168.2.238.8.8.80xca89Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:35:42.755481005 CEST192.168.2.238.8.8.80x83e8Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:35:52.801347017 CEST192.168.2.238.8.8.80xc49Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:36:02.850513935 CEST192.168.2.238.8.8.80xa4e2Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:36:07.915524960 CEST192.168.2.238.8.8.80x5e02Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:36:13.966692924 CEST192.168.2.238.8.8.80xd380Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:36:21.015851974 CEST192.168.2.238.8.8.80x991dStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:36:26.064208984 CEST192.168.2.238.8.8.80x5735Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:36:34.109294891 CEST192.168.2.238.8.8.80xbdabStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:36:39.158842087 CEST192.168.2.238.8.8.80x9986Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:36:42.231399059 CEST192.168.2.238.8.8.80xa808Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:36:43.279979944 CEST192.168.2.238.8.8.80xbbb9Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:36:50.325704098 CEST192.168.2.238.8.8.80xa579Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:36:51.374264002 CEST192.168.2.238.8.8.80xc2b8Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:36:59.423377991 CEST192.168.2.238.8.8.80x3c6Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:37:01.480495930 CEST192.168.2.238.8.8.80xdf0eStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:37:02.529299021 CEST192.168.2.238.8.8.80x7f1dStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:37:07.579133034 CEST192.168.2.238.8.8.80xb33dStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:37:13.629314899 CEST192.168.2.238.8.8.80xc8bStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:37:15.677565098 CEST192.168.2.238.8.8.80x3cbStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:37:18.500262976 CEST192.168.2.238.8.8.80x4c95Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:37:20.548906088 CEST192.168.2.238.8.8.80xa3eeStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:37:24.725655079 CEST192.168.2.238.8.8.80x2e44Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:37:25.595376015 CEST192.168.2.238.8.8.80x41aStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:37:30.642967939 CEST192.168.2.238.8.8.80xfa2fStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:37:30.774873972 CEST192.168.2.238.8.8.80x8de6Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:37:32.823848963 CEST192.168.2.238.8.8.80x90a8Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:37:35.906585932 CEST192.168.2.238.8.8.80x8312Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:37:37.691096067 CEST192.168.2.238.8.8.80x37e6Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:37:39.741597891 CEST192.168.2.238.8.8.80x5d33Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:37:43.955291033 CEST192.168.2.238.8.8.80xb738Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:37:48.004853010 CEST192.168.2.238.8.8.80xfab1Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:37:48.789915085 CEST192.168.2.238.8.8.80xdfdeStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:37:53.053350925 CEST192.168.2.238.8.8.80xf4b0Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:37:54.849728107 CEST192.168.2.238.8.8.80xf05aStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:37:59.908838987 CEST192.168.2.238.8.8.80x5135Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:38:02.978688002 CEST192.168.2.238.8.8.80x2756Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:38:03.101815939 CEST192.168.2.238.8.8.80xd947Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:38:05.055260897 CEST192.168.2.238.8.8.80xdf13Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:38:05.150703907 CEST192.168.2.238.8.8.80x80Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
            Aug 6, 2022 06:34:31.012761116 CEST8.8.8.8192.168.2.230x4c95No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:34:33.062582970 CEST8.8.8.8192.168.2.230xa3eeNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:34:38.110887051 CEST8.8.8.8192.168.2.230x41aNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:34:43.178842068 CEST8.8.8.8192.168.2.230xfa2fNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:34:50.227161884 CEST8.8.8.8192.168.2.230x37e6No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:34:52.275523901 CEST8.8.8.8192.168.2.230x5d33No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:35:02.341381073 CEST8.8.8.8192.168.2.230xdfdeNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:35:08.389444113 CEST8.8.8.8192.168.2.230xf05aNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:35:13.437644005 CEST8.8.8.8192.168.2.230x5135No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:35:16.485018015 CEST8.8.8.8192.168.2.230x2756No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:35:18.533694029 CEST8.8.8.8192.168.2.230xdf13No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:35:22.580888987 CEST8.8.8.8192.168.2.230x8306No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:35:23.632677078 CEST8.8.8.8192.168.2.230xe356No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:35:31.678518057 CEST8.8.8.8192.168.2.230x5cNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:35:36.726804018 CEST8.8.8.8192.168.2.230xca89No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:35:42.772620916 CEST8.8.8.8192.168.2.230x83e8No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:35:52.820950031 CEST8.8.8.8192.168.2.230xc49No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:36:02.868339062 CEST8.8.8.8192.168.2.230xa4e2No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:36:07.935823917 CEST8.8.8.8192.168.2.230x5e02No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:36:13.986347914 CEST8.8.8.8192.168.2.230xd380No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:36:21.035554886 CEST8.8.8.8192.168.2.230x991dNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:36:26.081285954 CEST8.8.8.8192.168.2.230x5735No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:36:34.130255938 CEST8.8.8.8192.168.2.230xbdabNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:36:39.176071882 CEST8.8.8.8192.168.2.230x9986No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:36:42.251230955 CEST8.8.8.8192.168.2.230xa808No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:36:43.297199965 CEST8.8.8.8192.168.2.230xbbb9No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:36:50.345362902 CEST8.8.8.8192.168.2.230xa579No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:36:51.394253969 CEST8.8.8.8192.168.2.230xc2b8No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:36:59.451746941 CEST8.8.8.8192.168.2.230x3c6No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:37:01.499841928 CEST8.8.8.8192.168.2.230xdf0eNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:37:02.546760082 CEST8.8.8.8192.168.2.230x7f1dNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:37:07.599052906 CEST8.8.8.8192.168.2.230xb33dNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:37:13.648916006 CEST8.8.8.8192.168.2.230xc8bNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:37:15.697153091 CEST8.8.8.8192.168.2.230x3cbNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:37:18.517447948 CEST8.8.8.8192.168.2.230x4c95No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:37:20.566694021 CEST8.8.8.8192.168.2.230xa3eeNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:37:24.744548082 CEST8.8.8.8192.168.2.230x2e44No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:37:25.612651110 CEST8.8.8.8192.168.2.230x41aNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:37:30.661705971 CEST8.8.8.8192.168.2.230xfa2fNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:37:30.794035912 CEST8.8.8.8192.168.2.230x8de6No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:37:32.843652964 CEST8.8.8.8192.168.2.230x90a8No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:37:35.926378012 CEST8.8.8.8192.168.2.230x8312No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:37:37.710695028 CEST8.8.8.8192.168.2.230x37e6No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:37:39.760700941 CEST8.8.8.8192.168.2.230x5d33No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:37:43.974637032 CEST8.8.8.8192.168.2.230xb738No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:37:48.024336100 CEST8.8.8.8192.168.2.230xfab1No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:37:48.809528112 CEST8.8.8.8192.168.2.230xdfdeNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:37:53.073667049 CEST8.8.8.8192.168.2.230xf4b0No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:37:54.871546030 CEST8.8.8.8192.168.2.230xf05aNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:37:59.927725077 CEST8.8.8.8192.168.2.230x5135No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:38:03.026779890 CEST8.8.8.8192.168.2.230x2756No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:38:03.121298075 CEST8.8.8.8192.168.2.230xd947No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:38:05.074727058 CEST8.8.8.8192.168.2.230xdf13No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:38:05.167964935 CEST8.8.8.8192.168.2.230x80No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)

            System Behavior

            Start time:06:34:29
            Start date:06/08/2022
            Path:/tmp/9aDl048Kv4
            Arguments:/tmp/9aDl048Kv4
            File size:5777432 bytes
            MD5 hash:0083f1f0e77be34ad27f849842bbb00c
            Start time:06:34:29
            Start date:06/08/2022
            Path:/tmp/9aDl048Kv4
            Arguments:n/a
            File size:5777432 bytes
            MD5 hash:0083f1f0e77be34ad27f849842bbb00c
            Start time:06:34:29
            Start date:06/08/2022
            Path:/tmp/9aDl048Kv4
            Arguments:n/a
            File size:5777432 bytes
            MD5 hash:0083f1f0e77be34ad27f849842bbb00c
            Start time:06:34:29
            Start date:06/08/2022
            Path:/tmp/9aDl048Kv4
            Arguments:n/a
            File size:5777432 bytes
            MD5 hash:0083f1f0e77be34ad27f849842bbb00c
            Start time:06:34:29
            Start date:06/08/2022
            Path:/tmp/9aDl048Kv4
            Arguments:n/a
            File size:5777432 bytes
            MD5 hash:0083f1f0e77be34ad27f849842bbb00c
            Start time:06:34:29
            Start date:06/08/2022
            Path:/tmp/9aDl048Kv4
            Arguments:n/a
            File size:5777432 bytes
            MD5 hash:0083f1f0e77be34ad27f849842bbb00c
            Start time:06:37:17
            Start date:06/08/2022
            Path:/tmp/9aDl048Kv4
            Arguments:n/a
            File size:5777432 bytes
            MD5 hash:0083f1f0e77be34ad27f849842bbb00c
            Start time:06:34:29
            Start date:06/08/2022
            Path:/tmp/9aDl048Kv4
            Arguments:n/a
            File size:5777432 bytes
            MD5 hash:0083f1f0e77be34ad27f849842bbb00c