Edit tour
Linux
Analysis Report
mpsl.elf
Overview
General Information
Sample name: | mpsl.elf |
Analysis ID: | 1538769 |
MD5: | eaf4f92882209af2ac633f3755b92284 |
SHA1: | fe20895c65e750dd1fc0dd45445720ba952576a4 |
SHA256: | ec5afbd33022308ae46716f3226b32620982da469fb81120939aeee2b386e857 |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Mirai, Moobot
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Detected Mirai
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Mirai
Yara detected Moobot
Connects to many ports of the same IP (likely port scanning)
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1538769 |
Start date and time: | 2024-10-21 18:46:07 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 39s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | mpsl.elf |
Detection: | MAL |
Classification: | mal100.troj.evad.linELF@0/0@24/0 |
- VT rate limit hit for: mpsl.elf
Command: | /tmp/mpsl.elf |
PID: | 6243 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | done. |
Standard Error: |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Mirai | Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world. | No Attribution |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
MooBot | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Moobot | Yara detected Moobot | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Moobot | Yara detected Moobot | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
JoeSecurity_Moobot | Yara detected Moobot | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Click to see the 1 entries |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-21T18:46:56.685755+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 60532 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:02.114474+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 60534 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:03.570774+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 60536 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:08.044068+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 60538 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:13.596698+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 60540 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:21.028675+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 60542 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:24.459662+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 60544 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:28.892181+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 60546 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:37.348328+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 60548 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:47.784153+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 60550 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:54.217105+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 60552 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:56.788475+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 60554 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:59.220557+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 60556 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:04.652976+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 60558 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:09.110620+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 60560 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:11.540482+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 60562 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:21.972963+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 60564 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:27.403718+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 60566 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:31.842157+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 60568 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:37.390600+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 60570 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:39.824204+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 60572 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:45.269697+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 60574 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:51.699905+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 60576 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:49:00.134037+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 60578 | 107.189.4.201 | 58431 | TCP |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | TCP traffic: |
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | .symtab present: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | 1 File Deletion | 1 OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 2 Application Layer Protocol | Traffic Duplication | Data Destruction |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
63% | ReversingLabs | Linux.Backdoor.Mirai | ||
100% | Avira | EXP/ELF.Mirai.Z.A |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
update.byeux.com | 107.189.4.201 | true | true | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
107.189.4.201 | update.byeux.com | United States | 53667 | PONYNETUS | true | |
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
91.189.91.43 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
107.189.4.201 | Get hash | malicious | Mirai, Moobot | Browse | ||
Get hash | malicious | Mirai, Moobot | Browse | |||
Get hash | malicious | Mirai, Moobot | Browse | |||
109.202.202.202 | Get hash | malicious | Unknown | Browse |
| |
91.189.91.43 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | |||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | |||
91.189.91.42 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
update.byeux.com | Get hash | malicious | Mirai, Moobot | Browse |
| |
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CANONICAL-ASGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
CANONICAL-ASGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
INIT7CH | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
PONYNETUS | Get hash | malicious | Gafgyt, Mirai | Browse |
| |
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 5.490969198434503 |
TrID: |
|
File name: | mpsl.elf |
File size: | 72'288 bytes |
MD5: | eaf4f92882209af2ac633f3755b92284 |
SHA1: | fe20895c65e750dd1fc0dd45445720ba952576a4 |
SHA256: | ec5afbd33022308ae46716f3226b32620982da469fb81120939aeee2b386e857 |
SHA512: | 563db38902b0c2226900c2e4d2080ceabcaaa882b11cb201735fe8f57f0406c2d3571129d7ed194461bea50e56b5fca3d9c592b1d554deb9dee9242acf2f33ac |
SSDEEP: | 768:Leh4txgcRLNurDjdg8eBroeaESQJ2w6uXatZXEPXitU5EiegY0xh1wntIF:Leh0KPUro1EfNEZXEZEinY0mnt |
TLSH: | EA63D716FB650FB7DC6BCD3306A81B013ACC558A22E97B363534D828F65B24B59E3C64 |
File Content Preview: | .ELF....................`.@.4...X.......4. ...(...............@...@...........................E...E..... *..........Q.td...............................<...'!......'.......................<...'!... .........9'.. ........................<...'!.............9 |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 71768 |
Section Header Size: | 40 |
Number of Section Headers: | 13 |
Header String Table Index: | 12 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x400094 | 0x94 | 0x8c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x400120 | 0x120 | 0xf250 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x40f370 | 0xf370 | 0x5c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x40f3d0 | 0xf3d0 | 0x1ae0 | 0x0 | 0x2 | A | 0 | 0 | 16 |
.ctors | PROGBITS | 0x451000 | 0x11000 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x451008 | 0x11008 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x451020 | 0x11020 | 0x3a0 | 0x0 | 0x3 | WA | 0 | 0 | 16 |
.got | PROGBITS | 0x4513c0 | 0x113c0 | 0x440 | 0x4 | 0x10000003 | WAp | 0 | 0 | 16 |
.sbss | NOBITS | 0x451800 | 0x11800 | 0x1c | 0x0 | 0x10000003 | WAp | 0 | 0 | 4 |
.bss | NOBITS | 0x451820 | 0x11800 | 0x2200 | 0x0 | 0x3 | WA | 0 | 0 | 16 |
.mdebug.abi32 | PROGBITS | 0x912 | 0x11800 | 0x0 | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0x11800 | 0x57 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x400000 | 0x400000 | 0x10eb0 | 0x10eb0 | 5.5464 | 0x5 | R E | 0x10000 | .init .text .fini .rodata | |
LOAD | 0x11000 | 0x451000 | 0x451000 | 0x800 | 0x2a20 | 3.6735 | 0x6 | RW | 0x10000 | .ctors .dtors .data .got .sbss .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-21T18:46:56.685755+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.23 | 60532 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:02.114474+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.23 | 60534 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:03.570774+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.23 | 60536 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:08.044068+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.23 | 60538 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:13.596698+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.23 | 60540 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:21.028675+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.23 | 60542 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:24.459662+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.23 | 60544 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:28.892181+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.23 | 60546 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:37.348328+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.23 | 60548 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:47.784153+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.23 | 60550 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:54.217105+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.23 | 60552 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:56.788475+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.23 | 60554 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:59.220557+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.23 | 60556 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:04.652976+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.23 | 60558 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:09.110620+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.23 | 60560 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:11.540482+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.23 | 60562 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:21.972963+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.23 | 60564 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:27.403718+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.23 | 60566 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:31.842157+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.23 | 60568 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:37.390600+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.23 | 60570 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:39.824204+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.23 | 60572 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:45.269697+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.23 | 60574 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:51.699905+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.23 | 60576 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:49:00.134037+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.23 | 60578 | 107.189.4.201 | 58431 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 21, 2024 18:46:56.676738024 CEST | 60532 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:46:56.682744980 CEST | 58431 | 60532 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:46:56.682826042 CEST | 60532 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:46:56.685755014 CEST | 60532 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:46:56.691221952 CEST | 58431 | 60532 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:46:57.097203016 CEST | 58431 | 60532 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:46:57.097598076 CEST | 60532 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:46:57.103079081 CEST | 58431 | 60532 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:46:59.629048109 CEST | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Oct 21, 2024 18:47:00.653006077 CEST | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Oct 21, 2024 18:47:02.108202934 CEST | 60534 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:02.113604069 CEST | 58431 | 60534 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:02.113681078 CEST | 60534 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:02.114474058 CEST | 60534 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:02.119853020 CEST | 58431 | 60534 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:02.553823948 CEST | 58431 | 60534 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:02.554045916 CEST | 60534 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:02.559773922 CEST | 58431 | 60534 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:03.564557076 CEST | 60536 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:03.569972992 CEST | 58431 | 60536 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:03.570049047 CEST | 60536 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:03.570774078 CEST | 60536 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:03.576155901 CEST | 58431 | 60536 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:03.989176035 CEST | 58431 | 60536 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:03.989382982 CEST | 60536 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:03.994859934 CEST | 58431 | 60536 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:08.015471935 CEST | 60538 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:08.020862103 CEST | 58431 | 60538 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:08.020936966 CEST | 60538 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:08.044068098 CEST | 60538 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:08.049499989 CEST | 58431 | 60538 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:08.579482079 CEST | 58431 | 60538 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:08.579777956 CEST | 60538 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:08.579818964 CEST | 60538 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:08.585491896 CEST | 58431 | 60538 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:13.590354919 CEST | 60540 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:13.595761061 CEST | 58431 | 60540 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:13.595877886 CEST | 60540 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:13.596698046 CEST | 60540 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:13.602065086 CEST | 58431 | 60540 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:14.012062073 CEST | 58431 | 60540 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:14.012574911 CEST | 60540 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:14.018018007 CEST | 58431 | 60540 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:14.986913919 CEST | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Oct 21, 2024 18:47:21.022263050 CEST | 60542 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:21.027764082 CEST | 58431 | 60542 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:21.027883053 CEST | 60542 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:21.028675079 CEST | 60542 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:21.034054995 CEST | 58431 | 60542 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:21.442603111 CEST | 58431 | 60542 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:21.442802906 CEST | 60542 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:21.449992895 CEST | 58431 | 60542 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:24.453512907 CEST | 60544 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:24.458952904 CEST | 58431 | 60544 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:24.459028959 CEST | 60544 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:24.459661961 CEST | 60544 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:24.465082884 CEST | 58431 | 60544 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:24.875291109 CEST | 58431 | 60544 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:24.875585079 CEST | 60544 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:24.881091118 CEST | 58431 | 60544 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:25.225562096 CEST | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Oct 21, 2024 18:47:28.885857105 CEST | 60546 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:28.891310930 CEST | 58431 | 60546 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:28.891407013 CEST | 60546 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:28.892180920 CEST | 60546 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:28.897572994 CEST | 58431 | 60546 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:29.325067997 CEST | 58431 | 60546 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:29.325505018 CEST | 60546 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:29.331027985 CEST | 58431 | 60546 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:31.368643045 CEST | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Oct 21, 2024 18:47:37.340001106 CEST | 60548 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:37.345506907 CEST | 58431 | 60548 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:37.345612049 CEST | 60548 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:37.348328114 CEST | 60548 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:37.353737116 CEST | 58431 | 60548 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:37.762137890 CEST | 58431 | 60548 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:37.762329102 CEST | 60548 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:37.768950939 CEST | 58431 | 60548 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:47.775950909 CEST | 60550 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:47.781549931 CEST | 58431 | 60550 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:47.781639099 CEST | 60550 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:47.784152985 CEST | 60550 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:47.789891958 CEST | 58431 | 60550 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:48.199471951 CEST | 58431 | 60550 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:48.199784994 CEST | 60550 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:48.205236912 CEST | 58431 | 60550 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:54.210556984 CEST | 60552 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:54.216222048 CEST | 58431 | 60552 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:54.216283083 CEST | 60552 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:54.217104912 CEST | 60552 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:54.222413063 CEST | 58431 | 60552 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:54.770087957 CEST | 58431 | 60552 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:54.770473003 CEST | 60552 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:54.780241013 CEST | 58431 | 60552 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:55.941169024 CEST | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Oct 21, 2024 18:47:56.781819105 CEST | 60554 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:56.787240982 CEST | 58431 | 60554 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:56.787327051 CEST | 60554 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:56.788475037 CEST | 60554 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:56.793756962 CEST | 58431 | 60554 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:57.202419043 CEST | 58431 | 60554 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:57.202645063 CEST | 60554 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:57.208197117 CEST | 58431 | 60554 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:59.213988066 CEST | 60556 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:59.219369888 CEST | 58431 | 60556 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:59.219440937 CEST | 60556 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:59.220556974 CEST | 60556 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:59.225851059 CEST | 58431 | 60556 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:59.633209944 CEST | 58431 | 60556 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:47:59.633367062 CEST | 60556 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:47:59.638691902 CEST | 58431 | 60556 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:04.645349979 CEST | 60558 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:04.652015924 CEST | 58431 | 60558 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:04.652092934 CEST | 60558 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:04.652976036 CEST | 60558 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:04.658704996 CEST | 58431 | 60558 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:05.089251995 CEST | 58431 | 60558 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:05.089484930 CEST | 60558 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:05.095956087 CEST | 58431 | 60558 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:09.102019072 CEST | 60560 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:09.109606981 CEST | 58431 | 60560 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:09.109659910 CEST | 60560 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:09.110620022 CEST | 60560 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:09.115938902 CEST | 58431 | 60560 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:09.522998095 CEST | 58431 | 60560 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:09.523299932 CEST | 60560 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:09.523299932 CEST | 60560 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:09.528875113 CEST | 58431 | 60560 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:11.534019947 CEST | 60562 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:11.539391994 CEST | 58431 | 60562 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:11.539478064 CEST | 60562 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:11.540482044 CEST | 60562 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:11.545846939 CEST | 58431 | 60562 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:11.953789949 CEST | 58431 | 60562 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:11.956685066 CEST | 60562 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:11.956685066 CEST | 60562 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:11.962415934 CEST | 58431 | 60562 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:16.418406010 CEST | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Oct 21, 2024 18:48:21.966458082 CEST | 60564 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:21.971805096 CEST | 58431 | 60564 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:21.971975088 CEST | 60564 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:21.972963095 CEST | 60564 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:21.978486061 CEST | 58431 | 60564 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:22.385345936 CEST | 58431 | 60564 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:22.385679007 CEST | 60564 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:22.391058922 CEST | 58431 | 60564 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:27.396887064 CEST | 60566 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:27.402400970 CEST | 58431 | 60566 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:27.402502060 CEST | 60566 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:27.403717995 CEST | 60566 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:27.409158945 CEST | 58431 | 60566 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:27.823889017 CEST | 58431 | 60566 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:27.824323893 CEST | 60566 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:27.829790115 CEST | 58431 | 60566 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:31.835683107 CEST | 60568 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:31.841135025 CEST | 58431 | 60568 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:31.841212988 CEST | 60568 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:31.842156887 CEST | 60568 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:31.847598076 CEST | 58431 | 60568 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:32.256174088 CEST | 58431 | 60568 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:32.256639957 CEST | 60568 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:32.262217999 CEST | 58431 | 60568 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:37.384186983 CEST | 60570 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:37.389626980 CEST | 58431 | 60570 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:37.389717102 CEST | 60570 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:37.390599966 CEST | 60570 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:37.395992994 CEST | 58431 | 60570 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:37.803685904 CEST | 58431 | 60570 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:37.804162979 CEST | 60570 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:37.809624910 CEST | 58431 | 60570 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:39.816957951 CEST | 60572 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:39.822633028 CEST | 58431 | 60572 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:39.822734118 CEST | 60572 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:39.824203968 CEST | 60572 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:39.829682112 CEST | 58431 | 60572 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:40.252480984 CEST | 58431 | 60572 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:40.252922058 CEST | 60572 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:40.258316994 CEST | 58431 | 60572 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:45.263468981 CEST | 60574 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:45.268805027 CEST | 58431 | 60574 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:45.268883944 CEST | 60574 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:45.269696951 CEST | 60574 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:45.274945021 CEST | 58431 | 60574 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:45.682894945 CEST | 58431 | 60574 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:45.683357954 CEST | 60574 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:45.688721895 CEST | 58431 | 60574 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:51.693605900 CEST | 60576 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:51.699029922 CEST | 58431 | 60576 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:51.699093103 CEST | 60576 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:51.699904919 CEST | 60576 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:51.705425978 CEST | 58431 | 60576 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:52.115467072 CEST | 58431 | 60576 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:48:52.115628004 CEST | 60576 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:48:52.121115923 CEST | 58431 | 60576 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:49:00.127127886 CEST | 60578 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:49:00.132596970 CEST | 58431 | 60578 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:49:00.132661104 CEST | 60578 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:49:00.134037018 CEST | 60578 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:49:00.139400959 CEST | 58431 | 60578 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:49:00.546240091 CEST | 58431 | 60578 | 107.189.4.201 | 192.168.2.23 |
Oct 21, 2024 18:49:00.546617031 CEST | 60578 | 58431 | 192.168.2.23 | 107.189.4.201 |
Oct 21, 2024 18:49:00.553819895 CEST | 58431 | 60578 | 107.189.4.201 | 192.168.2.23 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 21, 2024 18:46:56.665713072 CEST | 45826 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 21, 2024 18:46:56.675388098 CEST | 53 | 45826 | 8.8.8.8 | 192.168.2.23 |
Oct 21, 2024 18:47:02.099356890 CEST | 37904 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 21, 2024 18:47:02.107680082 CEST | 53 | 37904 | 8.8.8.8 | 192.168.2.23 |
Oct 21, 2024 18:47:03.556425095 CEST | 32939 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 21, 2024 18:47:03.563976049 CEST | 53 | 32939 | 8.8.8.8 | 192.168.2.23 |
Oct 21, 2024 18:47:08.000377893 CEST | 56132 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 21, 2024 18:47:08.008980989 CEST | 53 | 56132 | 8.8.8.8 | 192.168.2.23 |
Oct 21, 2024 18:47:13.581804037 CEST | 57670 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 21, 2024 18:47:13.589972019 CEST | 53 | 57670 | 8.8.8.8 | 192.168.2.23 |
Oct 21, 2024 18:47:21.014208078 CEST | 44146 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 21, 2024 18:47:21.021806955 CEST | 53 | 44146 | 8.8.8.8 | 192.168.2.23 |
Oct 21, 2024 18:47:24.445038080 CEST | 37847 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 21, 2024 18:47:24.453138113 CEST | 53 | 37847 | 8.8.8.8 | 192.168.2.23 |
Oct 21, 2024 18:47:28.877041101 CEST | 35537 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 21, 2024 18:47:28.885396957 CEST | 53 | 35537 | 8.8.8.8 | 192.168.2.23 |
Oct 21, 2024 18:47:37.329623938 CEST | 41482 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 21, 2024 18:47:37.337913990 CEST | 53 | 41482 | 8.8.8.8 | 192.168.2.23 |
Oct 21, 2024 18:47:47.765227079 CEST | 35339 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 21, 2024 18:47:47.774179935 CEST | 53 | 35339 | 8.8.8.8 | 192.168.2.23 |
Oct 21, 2024 18:47:54.201797009 CEST | 60232 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 21, 2024 18:47:54.210047007 CEST | 53 | 60232 | 8.8.8.8 | 192.168.2.23 |
Oct 21, 2024 18:47:56.773128986 CEST | 33287 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 21, 2024 18:47:56.781193972 CEST | 53 | 33287 | 8.8.8.8 | 192.168.2.23 |
Oct 21, 2024 18:47:59.205399036 CEST | 58670 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 21, 2024 18:47:59.213465929 CEST | 53 | 58670 | 8.8.8.8 | 192.168.2.23 |
Oct 21, 2024 18:48:04.635566950 CEST | 44597 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 21, 2024 18:48:04.644793034 CEST | 53 | 44597 | 8.8.8.8 | 192.168.2.23 |
Oct 21, 2024 18:48:09.092149973 CEST | 32997 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 21, 2024 18:48:09.101484060 CEST | 53 | 32997 | 8.8.8.8 | 192.168.2.23 |
Oct 21, 2024 18:48:11.525926113 CEST | 43213 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 21, 2024 18:48:11.533380032 CEST | 53 | 43213 | 8.8.8.8 | 192.168.2.23 |
Oct 21, 2024 18:48:21.957993984 CEST | 41938 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 21, 2024 18:48:21.965934992 CEST | 53 | 41938 | 8.8.8.8 | 192.168.2.23 |
Oct 21, 2024 18:48:27.388463974 CEST | 36432 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 21, 2024 18:48:27.396083117 CEST | 53 | 36432 | 8.8.8.8 | 192.168.2.23 |
Oct 21, 2024 18:48:31.827047110 CEST | 41830 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 21, 2024 18:48:31.835066080 CEST | 53 | 41830 | 8.8.8.8 | 192.168.2.23 |
Oct 21, 2024 18:48:37.259110928 CEST | 53610 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 21, 2024 18:48:37.382463932 CEST | 53 | 53610 | 8.8.8.8 | 192.168.2.23 |
Oct 21, 2024 18:48:39.807550907 CEST | 43154 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 21, 2024 18:48:39.816059113 CEST | 53 | 43154 | 8.8.8.8 | 192.168.2.23 |
Oct 21, 2024 18:48:45.255021095 CEST | 41303 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 21, 2024 18:48:45.262969017 CEST | 53 | 41303 | 8.8.8.8 | 192.168.2.23 |
Oct 21, 2024 18:48:51.685933113 CEST | 54154 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 21, 2024 18:48:51.693088055 CEST | 53 | 54154 | 8.8.8.8 | 192.168.2.23 |
Oct 21, 2024 18:49:00.118402958 CEST | 57018 | 53 | 192.168.2.23 | 8.8.8.8 |
Oct 21, 2024 18:49:00.126121044 CEST | 53 | 57018 | 8.8.8.8 | 192.168.2.23 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 21, 2024 18:46:56.665713072 CEST | 192.168.2.23 | 8.8.8.8 | 0x42e2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:02.099356890 CEST | 192.168.2.23 | 8.8.8.8 | 0x55e8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:03.556425095 CEST | 192.168.2.23 | 8.8.8.8 | 0x95b8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:08.000377893 CEST | 192.168.2.23 | 8.8.8.8 | 0x3f1f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:13.581804037 CEST | 192.168.2.23 | 8.8.8.8 | 0x3360 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:21.014208078 CEST | 192.168.2.23 | 8.8.8.8 | 0xabd3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:24.445038080 CEST | 192.168.2.23 | 8.8.8.8 | 0xf6c0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:28.877041101 CEST | 192.168.2.23 | 8.8.8.8 | 0x573c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:37.329623938 CEST | 192.168.2.23 | 8.8.8.8 | 0xde19 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:47.765227079 CEST | 192.168.2.23 | 8.8.8.8 | 0x7359 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:54.201797009 CEST | 192.168.2.23 | 8.8.8.8 | 0x4692 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:56.773128986 CEST | 192.168.2.23 | 8.8.8.8 | 0x4861 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:59.205399036 CEST | 192.168.2.23 | 8.8.8.8 | 0x3974 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:04.635566950 CEST | 192.168.2.23 | 8.8.8.8 | 0x6df5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:09.092149973 CEST | 192.168.2.23 | 8.8.8.8 | 0x381 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:11.525926113 CEST | 192.168.2.23 | 8.8.8.8 | 0xe80d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:21.957993984 CEST | 192.168.2.23 | 8.8.8.8 | 0x7210 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:27.388463974 CEST | 192.168.2.23 | 8.8.8.8 | 0xa18d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:31.827047110 CEST | 192.168.2.23 | 8.8.8.8 | 0xf423 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:37.259110928 CEST | 192.168.2.23 | 8.8.8.8 | 0xe9e4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:39.807550907 CEST | 192.168.2.23 | 8.8.8.8 | 0xf9cd | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:45.255021095 CEST | 192.168.2.23 | 8.8.8.8 | 0x94fc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:51.685933113 CEST | 192.168.2.23 | 8.8.8.8 | 0x869d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:49:00.118402958 CEST | 192.168.2.23 | 8.8.8.8 | 0x4d06 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 21, 2024 18:46:56.675388098 CEST | 8.8.8.8 | 192.168.2.23 | 0x42e2 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:02.107680082 CEST | 8.8.8.8 | 192.168.2.23 | 0x55e8 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:03.563976049 CEST | 8.8.8.8 | 192.168.2.23 | 0x95b8 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:08.008980989 CEST | 8.8.8.8 | 192.168.2.23 | 0x3f1f | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:13.589972019 CEST | 8.8.8.8 | 192.168.2.23 | 0x3360 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:21.021806955 CEST | 8.8.8.8 | 192.168.2.23 | 0xabd3 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:24.453138113 CEST | 8.8.8.8 | 192.168.2.23 | 0xf6c0 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:28.885396957 CEST | 8.8.8.8 | 192.168.2.23 | 0x573c | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:37.337913990 CEST | 8.8.8.8 | 192.168.2.23 | 0xde19 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:47.774179935 CEST | 8.8.8.8 | 192.168.2.23 | 0x7359 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:54.210047007 CEST | 8.8.8.8 | 192.168.2.23 | 0x4692 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:56.781193972 CEST | 8.8.8.8 | 192.168.2.23 | 0x4861 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:59.213465929 CEST | 8.8.8.8 | 192.168.2.23 | 0x3974 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:04.644793034 CEST | 8.8.8.8 | 192.168.2.23 | 0x6df5 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:09.101484060 CEST | 8.8.8.8 | 192.168.2.23 | 0x381 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:11.533380032 CEST | 8.8.8.8 | 192.168.2.23 | 0xe80d | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:21.965934992 CEST | 8.8.8.8 | 192.168.2.23 | 0x7210 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:27.396083117 CEST | 8.8.8.8 | 192.168.2.23 | 0xa18d | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:31.835066080 CEST | 8.8.8.8 | 192.168.2.23 | 0xf423 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:37.382463932 CEST | 8.8.8.8 | 192.168.2.23 | 0xe9e4 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:39.816059113 CEST | 8.8.8.8 | 192.168.2.23 | 0xf9cd | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:45.262969017 CEST | 8.8.8.8 | 192.168.2.23 | 0x94fc | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:51.693088055 CEST | 8.8.8.8 | 192.168.2.23 | 0x869d | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:49:00.126121044 CEST | 8.8.8.8 | 192.168.2.23 | 0x4d06 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 16:46:55 |
Start date (UTC): | 21/10/2024 |
Path: | /tmp/mpsl.elf |
Arguments: | /tmp/mpsl.elf |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 16:46:55 |
Start date (UTC): | 21/10/2024 |
Path: | /tmp/mpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 16:46:55 |
Start date (UTC): | 21/10/2024 |
Path: | /tmp/mpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 16:46:55 |
Start date (UTC): | 21/10/2024 |
Path: | /tmp/mpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 16:46:55 |
Start date (UTC): | 21/10/2024 |
Path: | /tmp/mpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |