Edit tour
Linux
Analysis Report
JVL2bXW1ch.elf
Overview
General Information
Sample name: | JVL2bXW1ch.elfrenamed because original name is a hash value |
Original sample name: | 766d13e52ec239528db092c98036cf9e.elf |
Analysis ID: | 1532258 |
MD5: | 766d13e52ec239528db092c98036cf9e |
SHA1: | a4440805279305960c7ce6fada0cab758b21e9fd |
SHA256: | 1485c22eb03f1e8e50b2ba4d6a5fdfd22cb4214b585e04929e670c4bfdeda864 |
Tags: | 32armelfmirai |
Infos: |
Detection
Mirai, Moobot
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Detected Mirai
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Mirai
Yara detected Moobot
Connects to many ports of the same IP (likely port scanning)
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1532258 |
Start date and time: | 2024-10-12 23:00:08 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 40s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | JVL2bXW1ch.elfrenamed because original name is a hash value |
Original Sample Name: | 766d13e52ec239528db092c98036cf9e.elf |
Detection: | MAL |
Classification: | mal100.troj.evad.linELF@0/0@19/0 |
Command: | /tmp/JVL2bXW1ch.elf |
PID: | 5467 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | done. |
Standard Error: |
- system is lnxubuntu20
- JVL2bXW1ch.elf New Fork (PID: 5469, Parent: 5467)
- JVL2bXW1ch.elf New Fork (PID: 5471, Parent: 5469)
- JVL2bXW1ch.elf New Fork (PID: 5473, Parent: 5469)
- JVL2bXW1ch.elf New Fork (PID: 5475, Parent: 5473)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Mirai | Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world. | No Attribution |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
MooBot | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Moobot | Yara detected Moobot | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Moobot | Yara detected Moobot | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
|
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-12T23:01:08.454710+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44712 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:01:14.140908+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44714 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:01:25.806007+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44716 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:01:28.461864+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44718 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:01:32.120608+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44720 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:01:38.775362+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44722 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:01:46.432690+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44724 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:01:52.107698+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44726 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:02:03.798990+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44728 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:02:13.463765+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44730 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:02:18.121949+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44732 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:02:21.153657+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44734 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:02:28.821634+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44736 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:02:37.481453+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44738 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:02:44.138224+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44740 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:02:52.813085+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44742 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:03:01.472423+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44744 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:03:07.162485+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44746 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:03:09.849426+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44748 | 107.189.4.201 | 58431 | TCP |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | TCP traffic: |
Source: | TCP traffic: |
Source: | DNS traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | .symtab present: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | 1 File Deletion | 1 OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Non-Standard Port | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
68% | ReversingLabs | Linux.Trojan.Mirai | ||
64% | Virustotal | Browse | ||
100% | Avira | EXP/ELF.Mirai.Z.A |
⊘No Antivirus matches
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
2% | Virustotal | Browse |
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
update.byeux.com | 107.189.4.201 | true | true |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
107.189.4.201 | update.byeux.com | United States | 53667 | PONYNETUS | true |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
107.189.4.201 | Get hash | malicious | Mirai, Moobot | Browse | ||
Get hash | malicious | Mirai, Moobot | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
update.byeux.com | Get hash | malicious | Mirai, Moobot | Browse |
| |
Get hash | malicious | Mirai, Moobot | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
PONYNETUS | Get hash | malicious | RHADAMANTHYS | Browse |
| |
Get hash | malicious | RHADAMANTHYS | Browse |
| ||
Get hash | malicious | RHADAMANTHYS | Browse |
| ||
Get hash | malicious | RHADAMANTHYS | Browse |
| ||
Get hash | malicious | RHADAMANTHYS | Browse |
| ||
Get hash | malicious | DcRat | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 6.074228500499579 |
TrID: |
|
File name: | JVL2bXW1ch.elf |
File size: | 58'676 bytes |
MD5: | 766d13e52ec239528db092c98036cf9e |
SHA1: | a4440805279305960c7ce6fada0cab758b21e9fd |
SHA256: | 1485c22eb03f1e8e50b2ba4d6a5fdfd22cb4214b585e04929e670c4bfdeda864 |
SHA512: | ba0d91c83947af9abc6b26769a50db480204a1dde52f10478f88e7b1c9b12d9608ab373c03a8f82d995e5a5c323bc753467935efcbea80e6bcc0c3e95d434bdd |
SSDEEP: | 1536:bxlKAMJTgLd2og1nKJyAL1KWoPWPpDGmf9awven5:bxunu35/oGpim4Gen5 |
TLSH: | 1E434A51F8819623C6D1127BF66E428D3B2213E8E2DBB307AD225F20378686B0D77F55 |
File Content Preview: | .ELF...a..........(.........4...........4. ...(.....................................................d...8%..........Q.td..................................-...L."....1..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 58276 |
Section Header Size: | 40 |
Number of Section Headers: | 10 |
Header String Table Index: | 9 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x8094 | 0x94 | 0x18 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x80b0 | 0xb0 | 0xc4a0 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x14550 | 0xc550 | 0x14 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x14564 | 0xc564 | 0x197c | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ctors | PROGBITS | 0x1e000 | 0xe000 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x1e008 | 0xe008 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x1e014 | 0xe014 | 0x350 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x1e364 | 0xe364 | 0x21d4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.shstrtab | STRTAB | 0x0 | 0xe364 | 0x3e | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8000 | 0x8000 | 0xdee0 | 0xdee0 | 6.1327 | 0x5 | R E | 0x8000 | .init .text .fini .rodata | |
LOAD | 0xe000 | 0x1e000 | 0x1e000 | 0x364 | 0x2538 | 2.6296 | 0x6 | RW | 0x8000 | .ctors .dtors .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-12T23:01:08.454710+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44712 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:01:14.140908+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44714 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:01:25.806007+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44716 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:01:28.461864+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44718 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:01:32.120608+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44720 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:01:38.775362+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44722 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:01:46.432690+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44724 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:01:52.107698+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44726 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:02:03.798990+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44728 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:02:13.463765+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44730 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:02:18.121949+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44732 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:02:21.153657+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44734 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:02:28.821634+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44736 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:02:37.481453+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44738 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:02:44.138224+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44740 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:02:52.813085+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44742 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:03:01.472423+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44744 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:03:07.162485+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44746 | 107.189.4.201 | 58431 | TCP |
2024-10-12T23:03:09.849426+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44748 | 107.189.4.201 | 58431 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 12, 2024 23:01:08.447690964 CEST | 44712 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:08.452610016 CEST | 58431 | 44712 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:08.452656031 CEST | 44712 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:08.454710007 CEST | 44712 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:08.459562063 CEST | 58431 | 44712 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:10.105041981 CEST | 58431 | 44712 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:10.109415054 CEST | 44712 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:10.113548040 CEST | 44712 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:10.118298054 CEST | 58431 | 44712 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:14.135159016 CEST | 44714 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:14.139976978 CEST | 58431 | 44714 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:14.140049934 CEST | 44714 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:14.140908003 CEST | 44714 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:14.145735979 CEST | 58431 | 44714 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:15.789098978 CEST | 58431 | 44714 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:15.789335012 CEST | 44714 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:15.794235945 CEST | 58431 | 44714 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:25.800002098 CEST | 44716 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:25.804984093 CEST | 58431 | 44716 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:25.805064917 CEST | 44716 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:25.806006908 CEST | 44716 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:25.810749054 CEST | 58431 | 44716 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:27.445257902 CEST | 58431 | 44716 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:27.445817947 CEST | 44716 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:27.451219082 CEST | 58431 | 44716 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:28.456240892 CEST | 44718 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:28.461159945 CEST | 58431 | 44718 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:28.461226940 CEST | 44718 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:28.461863995 CEST | 44718 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:28.466670990 CEST | 58431 | 44718 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:30.103655100 CEST | 58431 | 44718 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:30.104132891 CEST | 44718 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:30.109416008 CEST | 58431 | 44718 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:32.114455938 CEST | 44720 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:32.119402885 CEST | 58431 | 44720 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:32.119474888 CEST | 44720 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:32.120608091 CEST | 44720 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:32.126816988 CEST | 58431 | 44720 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:33.758184910 CEST | 58431 | 44720 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:33.758470058 CEST | 44720 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:33.763340950 CEST | 58431 | 44720 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:38.769268036 CEST | 44722 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:38.774169922 CEST | 58431 | 44722 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:38.774318933 CEST | 44722 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:38.775362015 CEST | 44722 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:38.780186892 CEST | 58431 | 44722 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:40.415930986 CEST | 58431 | 44722 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:40.416122913 CEST | 44722 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:40.421401024 CEST | 58431 | 44722 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:46.426551104 CEST | 44724 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:46.431372881 CEST | 58431 | 44724 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:46.431442976 CEST | 44724 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:46.432689905 CEST | 44724 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:46.437477112 CEST | 58431 | 44724 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:48.090709925 CEST | 58431 | 44724 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:48.091078997 CEST | 44724 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:48.095938921 CEST | 58431 | 44724 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:52.101453066 CEST | 44726 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:52.106307030 CEST | 58431 | 44726 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:52.106452942 CEST | 44726 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:52.107697964 CEST | 44726 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:52.112622976 CEST | 58431 | 44726 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:53.778215885 CEST | 58431 | 44726 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:01:53.778866053 CEST | 44726 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:01:53.783833027 CEST | 58431 | 44726 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:03.793040991 CEST | 44728 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:03.797918081 CEST | 58431 | 44728 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:03.797972918 CEST | 44728 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:03.798990011 CEST | 44728 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:03.803783894 CEST | 58431 | 44728 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:05.446997881 CEST | 58431 | 44728 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:05.447571993 CEST | 44728 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:05.452474117 CEST | 58431 | 44728 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:13.457941055 CEST | 44730 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:13.462892056 CEST | 58431 | 44730 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:13.462954044 CEST | 44730 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:13.463764906 CEST | 44730 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:13.468574047 CEST | 58431 | 44730 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:15.103998899 CEST | 58431 | 44730 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:15.104396105 CEST | 44730 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:15.109221935 CEST | 58431 | 44730 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:18.115715027 CEST | 44732 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:18.120553970 CEST | 58431 | 44732 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:18.120606899 CEST | 44732 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:18.121948957 CEST | 44732 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:18.125833988 CEST | 58431 | 44732 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:18.125916004 CEST | 44732 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:18.126792908 CEST | 58431 | 44732 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:18.130785942 CEST | 58431 | 44732 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:21.146373987 CEST | 44734 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:21.151942968 CEST | 58431 | 44734 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:21.152081966 CEST | 44734 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:21.153656960 CEST | 44734 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:21.158562899 CEST | 58431 | 44734 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:22.800190926 CEST | 58431 | 44734 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:22.800548077 CEST | 44734 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:22.805517912 CEST | 58431 | 44734 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:28.814258099 CEST | 44736 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:28.819869041 CEST | 58431 | 44736 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:28.819964886 CEST | 44736 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:28.821634054 CEST | 44736 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:28.826641083 CEST | 58431 | 44736 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:30.462995052 CEST | 58431 | 44736 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:30.463323116 CEST | 44736 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:30.468303919 CEST | 58431 | 44736 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:37.474868059 CEST | 44738 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:37.479696989 CEST | 58431 | 44738 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:37.479799986 CEST | 44738 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:37.481452942 CEST | 44738 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:37.486296892 CEST | 58431 | 44738 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:39.119107962 CEST | 58431 | 44738 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:39.119673967 CEST | 44738 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:39.124742031 CEST | 58431 | 44738 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:44.132165909 CEST | 44740 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:44.137006044 CEST | 58431 | 44740 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:44.137098074 CEST | 44740 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:44.138223886 CEST | 44740 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:44.143045902 CEST | 58431 | 44740 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:45.794951916 CEST | 58431 | 44740 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:45.795341969 CEST | 44740 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:45.800470114 CEST | 58431 | 44740 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:52.807261944 CEST | 44742 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:52.812088013 CEST | 58431 | 44742 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:52.812148094 CEST | 44742 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:52.813085079 CEST | 44742 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:52.817981958 CEST | 58431 | 44742 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:54.447340965 CEST | 58431 | 44742 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:02:54.447901011 CEST | 44742 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:02:54.453588963 CEST | 58431 | 44742 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:03:01.464776039 CEST | 44744 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:03:01.470344067 CEST | 58431 | 44744 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:03:01.470608950 CEST | 44744 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:03:01.472423077 CEST | 44744 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:03:01.477705002 CEST | 58431 | 44744 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:03:03.140695095 CEST | 58431 | 44744 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:03:03.141071081 CEST | 44744 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:03:03.146414042 CEST | 58431 | 44744 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:03:07.155505896 CEST | 44746 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:03:07.160496950 CEST | 58431 | 44746 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:03:07.160732985 CEST | 44746 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:03:07.162484884 CEST | 44746 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:03:07.167663097 CEST | 58431 | 44746 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:03:08.824372053 CEST | 58431 | 44746 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:03:08.825145006 CEST | 44746 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:03:08.830498934 CEST | 58431 | 44746 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:03:09.842142105 CEST | 44748 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:03:09.847496986 CEST | 58431 | 44748 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:03:09.847609043 CEST | 44748 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:03:09.849426031 CEST | 44748 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:03:09.854407072 CEST | 58431 | 44748 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:03:11.530927896 CEST | 58431 | 44748 | 107.189.4.201 | 192.168.2.13 |
Oct 12, 2024 23:03:11.531831980 CEST | 44748 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 12, 2024 23:03:11.537348032 CEST | 58431 | 44748 | 107.189.4.201 | 192.168.2.13 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 12, 2024 23:01:08.287813902 CEST | 58237 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 12, 2024 23:01:08.446027040 CEST | 53 | 58237 | 8.8.8.8 | 192.168.2.13 |
Oct 12, 2024 23:01:14.127722025 CEST | 51602 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 12, 2024 23:01:14.134630919 CEST | 53 | 51602 | 8.8.8.8 | 192.168.2.13 |
Oct 12, 2024 23:01:25.792181969 CEST | 50086 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 12, 2024 23:01:25.799350977 CEST | 53 | 50086 | 8.8.8.8 | 192.168.2.13 |
Oct 12, 2024 23:01:28.448400021 CEST | 56568 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 12, 2024 23:01:28.455816984 CEST | 53 | 56568 | 8.8.8.8 | 192.168.2.13 |
Oct 12, 2024 23:01:32.107034922 CEST | 50440 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 12, 2024 23:01:32.113754988 CEST | 53 | 50440 | 8.8.8.8 | 192.168.2.13 |
Oct 12, 2024 23:01:38.760715008 CEST | 42632 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 12, 2024 23:01:38.768155098 CEST | 53 | 42632 | 8.8.8.8 | 192.168.2.13 |
Oct 12, 2024 23:01:46.419697046 CEST | 49028 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 12, 2024 23:01:46.425765038 CEST | 53 | 49028 | 8.8.8.8 | 192.168.2.13 |
Oct 12, 2024 23:01:52.093771935 CEST | 52799 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 12, 2024 23:01:52.100806952 CEST | 53 | 52799 | 8.8.8.8 | 192.168.2.13 |
Oct 12, 2024 23:02:03.784280062 CEST | 53833 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 12, 2024 23:02:03.791680098 CEST | 53 | 53833 | 8.8.8.8 | 192.168.2.13 |
Oct 12, 2024 23:02:13.450175047 CEST | 52300 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 12, 2024 23:02:13.457483053 CEST | 53 | 52300 | 8.8.8.8 | 192.168.2.13 |
Oct 12, 2024 23:02:18.107960939 CEST | 53892 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 12, 2024 23:02:18.115024090 CEST | 53 | 53892 | 8.8.8.8 | 192.168.2.13 |
Oct 12, 2024 23:02:21.129661083 CEST | 54541 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 12, 2024 23:02:21.145186901 CEST | 53 | 54541 | 8.8.8.8 | 192.168.2.13 |
Oct 12, 2024 23:02:28.805218935 CEST | 41450 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 12, 2024 23:02:28.813235998 CEST | 53 | 41450 | 8.8.8.8 | 192.168.2.13 |
Oct 12, 2024 23:02:37.467117071 CEST | 51267 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 12, 2024 23:02:37.474037886 CEST | 53 | 51267 | 8.8.8.8 | 192.168.2.13 |
Oct 12, 2024 23:02:44.123907089 CEST | 35936 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 12, 2024 23:02:44.131458044 CEST | 53 | 35936 | 8.8.8.8 | 192.168.2.13 |
Oct 12, 2024 23:02:52.799885035 CEST | 39977 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 12, 2024 23:02:52.806592941 CEST | 53 | 39977 | 8.8.8.8 | 192.168.2.13 |
Oct 12, 2024 23:03:01.454943895 CEST | 54969 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 12, 2024 23:03:01.462950945 CEST | 53 | 54969 | 8.8.8.8 | 192.168.2.13 |
Oct 12, 2024 23:03:07.146104097 CEST | 48146 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 12, 2024 23:03:07.153480053 CEST | 53 | 48146 | 8.8.8.8 | 192.168.2.13 |
Oct 12, 2024 23:03:09.832556963 CEST | 49374 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 12, 2024 23:03:09.840336084 CEST | 53 | 49374 | 8.8.8.8 | 192.168.2.13 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 12, 2024 23:01:08.287813902 CEST | 192.168.2.13 | 8.8.8.8 | 0xb048 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 23:01:14.127722025 CEST | 192.168.2.13 | 8.8.8.8 | 0x214f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 23:01:25.792181969 CEST | 192.168.2.13 | 8.8.8.8 | 0xe00 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 23:01:28.448400021 CEST | 192.168.2.13 | 8.8.8.8 | 0xe7bc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 23:01:32.107034922 CEST | 192.168.2.13 | 8.8.8.8 | 0x1b04 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 23:01:38.760715008 CEST | 192.168.2.13 | 8.8.8.8 | 0x57d1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 23:01:46.419697046 CEST | 192.168.2.13 | 8.8.8.8 | 0x9a66 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 23:01:52.093771935 CEST | 192.168.2.13 | 8.8.8.8 | 0x18ce | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 23:02:03.784280062 CEST | 192.168.2.13 | 8.8.8.8 | 0x2818 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 23:02:13.450175047 CEST | 192.168.2.13 | 8.8.8.8 | 0x4eb0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 23:02:18.107960939 CEST | 192.168.2.13 | 8.8.8.8 | 0xe95e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 23:02:21.129661083 CEST | 192.168.2.13 | 8.8.8.8 | 0x2949 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 23:02:28.805218935 CEST | 192.168.2.13 | 8.8.8.8 | 0xbb3d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 23:02:37.467117071 CEST | 192.168.2.13 | 8.8.8.8 | 0xd845 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 23:02:44.123907089 CEST | 192.168.2.13 | 8.8.8.8 | 0x7d91 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 23:02:52.799885035 CEST | 192.168.2.13 | 8.8.8.8 | 0xb504 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 23:03:01.454943895 CEST | 192.168.2.13 | 8.8.8.8 | 0x1d1d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 23:03:07.146104097 CEST | 192.168.2.13 | 8.8.8.8 | 0x17d3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 23:03:09.832556963 CEST | 192.168.2.13 | 8.8.8.8 | 0x1237 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 12, 2024 23:01:08.446027040 CEST | 8.8.8.8 | 192.168.2.13 | 0xb048 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 23:01:14.134630919 CEST | 8.8.8.8 | 192.168.2.13 | 0x214f | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 23:01:25.799350977 CEST | 8.8.8.8 | 192.168.2.13 | 0xe00 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 23:01:28.455816984 CEST | 8.8.8.8 | 192.168.2.13 | 0xe7bc | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 23:01:32.113754988 CEST | 8.8.8.8 | 192.168.2.13 | 0x1b04 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 23:01:38.768155098 CEST | 8.8.8.8 | 192.168.2.13 | 0x57d1 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 23:01:46.425765038 CEST | 8.8.8.8 | 192.168.2.13 | 0x9a66 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 23:01:52.100806952 CEST | 8.8.8.8 | 192.168.2.13 | 0x18ce | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 23:02:03.791680098 CEST | 8.8.8.8 | 192.168.2.13 | 0x2818 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 23:02:13.457483053 CEST | 8.8.8.8 | 192.168.2.13 | 0x4eb0 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 23:02:18.115024090 CEST | 8.8.8.8 | 192.168.2.13 | 0xe95e | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 23:02:21.145186901 CEST | 8.8.8.8 | 192.168.2.13 | 0x2949 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 23:02:28.813235998 CEST | 8.8.8.8 | 192.168.2.13 | 0xbb3d | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 23:02:37.474037886 CEST | 8.8.8.8 | 192.168.2.13 | 0xd845 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 23:02:44.131458044 CEST | 8.8.8.8 | 192.168.2.13 | 0x7d91 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 23:02:52.806592941 CEST | 8.8.8.8 | 192.168.2.13 | 0xb504 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 23:03:01.462950945 CEST | 8.8.8.8 | 192.168.2.13 | 0x1d1d | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 23:03:07.153480053 CEST | 8.8.8.8 | 192.168.2.13 | 0x17d3 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 23:03:09.840336084 CEST | 8.8.8.8 | 192.168.2.13 | 0x1237 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 21:01:07 |
Start date (UTC): | 12/10/2024 |
Path: | /tmp/JVL2bXW1ch.elf |
Arguments: | /tmp/JVL2bXW1ch.elf |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 21:01:07 |
Start date (UTC): | 12/10/2024 |
Path: | /tmp/JVL2bXW1ch.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 21:01:07 |
Start date (UTC): | 12/10/2024 |
Path: | /tmp/JVL2bXW1ch.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 21:01:07 |
Start date (UTC): | 12/10/2024 |
Path: | /tmp/JVL2bXW1ch.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 21:01:07 |
Start date (UTC): | 12/10/2024 |
Path: | /tmp/JVL2bXW1ch.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |