It seems i forgot to cater for the quota applied to free "play" user in ClickHouse in my previous query... In fact, the threat actor did a lot more... this should give a better list of actions that was performed - Clearly showed he was testing his payload:
https://play.clickhouse.com/play?user=play#c2VsZWN0ICogZnJvb...