Edit tour
Linux
Analysis Report
x86.elf
Overview
General Information
Sample name: | x86.elf |
Analysis ID: | 1538770 |
MD5: | a51270cb597ae42f4cb7bea59f2f6434 |
SHA1: | 2cf91d41bd27575b5c119f7626a991f3e098f3e0 |
SHA256: | 24cdebe89f0cd9e4f7ee3ce8cb36106ac09a45d9d7fa591e330940df329fcf06 |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Mirai, Moobot
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Detected Mirai
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Mirai
Yara detected Moobot
Connects to many ports of the same IP (likely port scanning)
Machine Learning detection for sample
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Yara signature match
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1538770 |
Start date and time: | 2024-10-21 18:46:09 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 25s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | x86.elf |
Detection: | MAL |
Classification: | mal100.troj.evad.linELF@0/0@17/0 |
- VT rate limit hit for: x86.elf
Command: | /tmp/x86.elf |
PID: | 5452 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | done. |
Standard Error: |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Mirai | Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world. | No Attribution |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
MooBot | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Moobot | Yara detected Moobot | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
Linux_Trojan_Mirai_b14f4c5d | unknown | unknown |
| |
Linux_Trojan_Mirai_88de437f | unknown | unknown |
| |
Click to see the 3 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Moobot | Yara detected Moobot | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
Linux_Trojan_Mirai_b14f4c5d | unknown | unknown |
| |
Linux_Trojan_Mirai_88de437f | unknown | unknown |
| |
Click to see the 5 entries |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-21T18:46:59.331447+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44702 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:05.762562+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44704 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:15.195078+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44706 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:24.774981+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44708 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:34.208270+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44710 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:43.639835+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44712 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:49.075916+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44714 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:56.504635+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44716 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:01.935587+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44718 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:07.370624+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44720 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:15.805745+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44722 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:24.236247+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44724 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:25.669952+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44726 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:29.104628+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44728 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:39.533894+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44730 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:47.115144+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44732 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:55.547188+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.13 | 44734 | 107.189.4.201 | 58431 | TCP |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Source: | Joe Sandbox ML: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | TCP traffic: |
Source: | TCP traffic: |
Source: | DNS traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | .symtab present: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | 1 File Deletion | 1 OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Non-Standard Port | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
71% | ReversingLabs | Linux.Backdoor.Mirai | ||
100% | Avira | EXP/ELF.Mirai.Z.A | ||
100% | Joe Sandbox ML |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
update.byeux.com | 107.189.4.201 | true | true | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
107.189.4.201 | update.byeux.com | United States | 53667 | PONYNETUS | true |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
107.189.4.201 | Get hash | malicious | Mirai, Moobot | Browse | ||
Get hash | malicious | Mirai, Moobot | Browse | |||
Get hash | malicious | Mirai, Moobot | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
update.byeux.com | Get hash | malicious | Mirai, Moobot | Browse |
| |
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
PONYNETUS | Get hash | malicious | Gafgyt, Mirai | Browse |
| |
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 6.515353152602667 |
TrID: |
|
File name: | x86.elf |
File size: | 47'504 bytes |
MD5: | a51270cb597ae42f4cb7bea59f2f6434 |
SHA1: | 2cf91d41bd27575b5c119f7626a991f3e098f3e0 |
SHA256: | 24cdebe89f0cd9e4f7ee3ce8cb36106ac09a45d9d7fa591e330940df329fcf06 |
SHA512: | 98970519b61ed83de6ec776ea0d94d525d3b8007718f34e6e5ff023a78f16a21dde3fcf50f9530e2184e80d86b019624f92d708a39fb25a67ea73721b4724853 |
SSDEEP: | 768:qmQx/v4HJrZWwRMQ8Llgjmh/l0QLY3psPkcb6cIYjF43ba8cmSTsCYzI6u:BQx/v4HJrZWgMQ8LllD0Q05Eb6cVj+3d |
TLSH: | 24235AC4F143D5F5E85709782177BB375A32F1E52229E653C3A4DA32BC92602B926ECC |
File Content Preview: | .ELF....................d...4...........4. ...(.....................<...<...............@...@E..@E.......(..........Q.td............................U..S............h....C...[]...$.............U......=.G...t..5....dE.....dE......u........t....h<5.......... |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 47104 |
Section Header Size: | 40 |
Number of Section Headers: | 10 |
Header String Table Index: | 9 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x8048094 | 0x94 | 0x1c | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.text | PROGBITS | 0x80480b0 | 0xb0 | 0x9866 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x8051916 | 0x9916 | 0x17 | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.rodata | PROGBITS | 0x8051940 | 0x9940 | 0x1bfc | 0x0 | 0x2 | A | 0 | 0 | 32 |
.ctors | PROGBITS | 0x8054540 | 0xb540 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x8054548 | 0xb548 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x8054560 | 0xb560 | 0x260 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.bss | NOBITS | 0x80547c0 | 0xb7c0 | 0x2580 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.shstrtab | STRTAB | 0x0 | 0xb7c0 | 0x3e | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8048000 | 0x8048000 | 0xb53c | 0xb53c | 6.5594 | 0x5 | R E | 0x1000 | .init .text .fini .rodata | |
LOAD | 0xb540 | 0x8054540 | 0x8054540 | 0x280 | 0x2800 | 3.3911 | 0x6 | RW | 0x1000 | .ctors .dtors .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x4 |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-21T18:46:59.331447+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44702 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:05.762562+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44704 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:15.195078+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44706 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:24.774981+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44708 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:34.208270+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44710 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:43.639835+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44712 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:49.075916+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44714 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:56.504635+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44716 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:01.935587+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44718 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:07.370624+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44720 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:15.805745+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44722 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:24.236247+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44724 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:25.669952+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44726 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:29.104628+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44728 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:39.533894+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44730 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:47.115144+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44732 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:55.547188+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.13 | 44734 | 107.189.4.201 | 58431 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 21, 2024 18:46:59.325376987 CEST | 44702 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:46:59.331350088 CEST | 58431 | 44702 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:46:59.331408978 CEST | 44702 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:46:59.331446886 CEST | 44702 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:46:59.336898088 CEST | 58431 | 44702 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:46:59.747279882 CEST | 58431 | 44702 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:46:59.747390032 CEST | 44702 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:46:59.754566908 CEST | 58431 | 44702 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:47:05.756979942 CEST | 44704 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:47:05.762487888 CEST | 58431 | 44704 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:47:05.762543917 CEST | 44704 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:47:05.762562037 CEST | 44704 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:47:05.767914057 CEST | 58431 | 44704 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:47:06.179568052 CEST | 58431 | 44704 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:47:06.179754972 CEST | 44704 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:47:06.185906887 CEST | 58431 | 44704 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:47:15.189443111 CEST | 44706 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:47:15.194981098 CEST | 58431 | 44706 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:47:15.195060015 CEST | 44706 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:47:15.195077896 CEST | 44706 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:47:15.201592922 CEST | 58431 | 44706 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:47:15.609827995 CEST | 58431 | 44706 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:47:15.609946012 CEST | 44706 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:47:15.616679907 CEST | 58431 | 44706 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:47:24.769478083 CEST | 44708 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:47:24.774879932 CEST | 58431 | 44708 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:47:24.774941921 CEST | 44708 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:47:24.774981022 CEST | 44708 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:47:24.780544043 CEST | 58431 | 44708 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:47:25.192048073 CEST | 58431 | 44708 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:47:25.192256927 CEST | 44708 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:47:25.198793888 CEST | 58431 | 44708 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:47:34.202755928 CEST | 44710 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:47:34.208200932 CEST | 58431 | 44710 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:47:34.208270073 CEST | 44710 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:47:34.208270073 CEST | 44710 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:47:34.213700056 CEST | 58431 | 44710 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:47:34.623647928 CEST | 58431 | 44710 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:47:34.623867989 CEST | 44710 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:47:34.629255056 CEST | 58431 | 44710 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:47:43.634052992 CEST | 44712 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:47:43.639725924 CEST | 58431 | 44712 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:47:43.639811039 CEST | 44712 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:47:43.639834881 CEST | 44712 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:47:43.647183895 CEST | 58431 | 44712 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:47:44.058964014 CEST | 58431 | 44712 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:47:44.059691906 CEST | 44712 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:47:44.065491915 CEST | 58431 | 44712 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:47:49.070456982 CEST | 44714 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:47:49.075788021 CEST | 58431 | 44714 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:47:49.075844049 CEST | 44714 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:47:49.075916052 CEST | 44714 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:47:49.081321955 CEST | 58431 | 44714 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:47:49.489538908 CEST | 58431 | 44714 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:47:49.489710093 CEST | 44714 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:47:49.495028973 CEST | 58431 | 44714 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:47:56.499172926 CEST | 44716 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:47:56.504539967 CEST | 58431 | 44716 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:47:56.504621983 CEST | 44716 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:47:56.504635096 CEST | 44716 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:47:56.510024071 CEST | 58431 | 44716 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:47:56.920581102 CEST | 58431 | 44716 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:47:56.920836926 CEST | 44716 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:47:56.926211119 CEST | 58431 | 44716 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:01.930176020 CEST | 44718 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:01.935504913 CEST | 58431 | 44718 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:01.935570002 CEST | 44718 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:01.935586929 CEST | 44718 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:01.940992117 CEST | 58431 | 44718 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:02.350924969 CEST | 58431 | 44718 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:02.351180077 CEST | 44718 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:02.356535912 CEST | 58431 | 44718 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:07.364948988 CEST | 44720 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:07.370517969 CEST | 58431 | 44720 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:07.370624065 CEST | 44720 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:07.370624065 CEST | 44720 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:07.376132965 CEST | 58431 | 44720 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:07.790007114 CEST | 58431 | 44720 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:07.790441990 CEST | 44720 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:07.796375990 CEST | 58431 | 44720 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:15.800183058 CEST | 44722 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:15.805655956 CEST | 58431 | 44722 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:15.805727959 CEST | 44722 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:15.805744886 CEST | 44722 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:15.811134100 CEST | 58431 | 44722 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:16.221798897 CEST | 58431 | 44722 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:16.222048044 CEST | 44722 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:16.227523088 CEST | 58431 | 44722 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:24.230771065 CEST | 44724 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:24.236145020 CEST | 58431 | 44724 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:24.236215115 CEST | 44724 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:24.236247063 CEST | 44724 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:24.241552114 CEST | 58431 | 44724 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:24.652844906 CEST | 58431 | 44724 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:24.653136015 CEST | 44724 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:24.658684015 CEST | 58431 | 44724 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:25.664448023 CEST | 44726 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:25.669796944 CEST | 58431 | 44726 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:25.669872999 CEST | 44726 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:25.669951916 CEST | 44726 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:25.675236940 CEST | 58431 | 44726 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:26.088143110 CEST | 58431 | 44726 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:26.088654041 CEST | 44726 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:26.094249964 CEST | 58431 | 44726 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:29.098598003 CEST | 44728 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:29.104471922 CEST | 58431 | 44728 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:29.104592085 CEST | 44728 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:29.104628086 CEST | 44728 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:29.110295057 CEST | 58431 | 44728 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:29.518661022 CEST | 58431 | 44728 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:29.518938065 CEST | 44728 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:29.524527073 CEST | 58431 | 44728 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:39.528249979 CEST | 44730 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:39.533699036 CEST | 58431 | 44730 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:39.533814907 CEST | 44730 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:39.533894062 CEST | 44730 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:39.539261103 CEST | 58431 | 44730 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:39.948939085 CEST | 58431 | 44730 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:39.949148893 CEST | 44730 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:39.954555035 CEST | 58431 | 44730 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:47.109235048 CEST | 44732 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:47.114937067 CEST | 58431 | 44732 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:47.115072012 CEST | 44732 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:47.115144014 CEST | 44732 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:47.120598078 CEST | 58431 | 44732 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:47.531281948 CEST | 58431 | 44732 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:47.531415939 CEST | 44732 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:47.536780119 CEST | 58431 | 44732 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:55.541376114 CEST | 44734 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:55.547066927 CEST | 58431 | 44734 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:55.547147036 CEST | 44734 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:55.547188044 CEST | 44734 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:55.553172112 CEST | 58431 | 44734 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:55.962455034 CEST | 58431 | 44734 | 107.189.4.201 | 192.168.2.13 |
Oct 21, 2024 18:48:55.962646961 CEST | 44734 | 58431 | 192.168.2.13 | 107.189.4.201 |
Oct 21, 2024 18:48:55.968054056 CEST | 58431 | 44734 | 107.189.4.201 | 192.168.2.13 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 21, 2024 18:46:59.315532923 CEST | 46457 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 21, 2024 18:46:59.325253963 CEST | 53 | 46457 | 8.8.8.8 | 192.168.2.13 |
Oct 21, 2024 18:47:05.749105930 CEST | 41099 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 21, 2024 18:47:05.756860018 CEST | 53 | 41099 | 8.8.8.8 | 192.168.2.13 |
Oct 21, 2024 18:47:15.180990934 CEST | 49622 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 21, 2024 18:47:15.189307928 CEST | 53 | 49622 | 8.8.8.8 | 192.168.2.13 |
Oct 21, 2024 18:47:24.611279011 CEST | 57414 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 21, 2024 18:47:24.769328117 CEST | 53 | 57414 | 8.8.8.8 | 192.168.2.13 |
Oct 21, 2024 18:47:34.193811893 CEST | 41087 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 21, 2024 18:47:34.202649117 CEST | 53 | 41087 | 8.8.8.8 | 192.168.2.13 |
Oct 21, 2024 18:47:43.625487089 CEST | 40208 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 21, 2024 18:47:43.633817911 CEST | 53 | 40208 | 8.8.8.8 | 192.168.2.13 |
Oct 21, 2024 18:47:49.062283039 CEST | 51697 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 21, 2024 18:47:49.070327044 CEST | 53 | 51697 | 8.8.8.8 | 192.168.2.13 |
Oct 21, 2024 18:47:56.491159916 CEST | 45233 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 21, 2024 18:47:56.499037981 CEST | 53 | 45233 | 8.8.8.8 | 192.168.2.13 |
Oct 21, 2024 18:48:01.922209978 CEST | 56199 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 21, 2024 18:48:01.930025101 CEST | 53 | 56199 | 8.8.8.8 | 192.168.2.13 |
Oct 21, 2024 18:48:07.352684975 CEST | 50374 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 21, 2024 18:48:07.364348888 CEST | 53 | 50374 | 8.8.8.8 | 192.168.2.13 |
Oct 21, 2024 18:48:15.792056084 CEST | 47404 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 21, 2024 18:48:15.799968004 CEST | 53 | 47404 | 8.8.8.8 | 192.168.2.13 |
Oct 21, 2024 18:48:24.223299026 CEST | 40547 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 21, 2024 18:48:24.230541945 CEST | 53 | 40547 | 8.8.8.8 | 192.168.2.13 |
Oct 21, 2024 18:48:25.654392958 CEST | 43412 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 21, 2024 18:48:25.664289951 CEST | 53 | 43412 | 8.8.8.8 | 192.168.2.13 |
Oct 21, 2024 18:48:29.090467930 CEST | 43583 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 21, 2024 18:48:29.098448038 CEST | 53 | 43583 | 8.8.8.8 | 192.168.2.13 |
Oct 21, 2024 18:48:39.520365000 CEST | 35389 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 21, 2024 18:48:39.527983904 CEST | 53 | 35389 | 8.8.8.8 | 192.168.2.13 |
Oct 21, 2024 18:48:46.950469971 CEST | 46677 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 21, 2024 18:48:47.109000921 CEST | 53 | 46677 | 8.8.8.8 | 192.168.2.13 |
Oct 21, 2024 18:48:55.532656908 CEST | 57774 | 53 | 192.168.2.13 | 8.8.8.8 |
Oct 21, 2024 18:48:55.541291952 CEST | 53 | 57774 | 8.8.8.8 | 192.168.2.13 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 21, 2024 18:46:59.315532923 CEST | 192.168.2.13 | 8.8.8.8 | 0x4483 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:05.749105930 CEST | 192.168.2.13 | 8.8.8.8 | 0x1189 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:15.180990934 CEST | 192.168.2.13 | 8.8.8.8 | 0x7ac0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:24.611279011 CEST | 192.168.2.13 | 8.8.8.8 | 0x397b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:34.193811893 CEST | 192.168.2.13 | 8.8.8.8 | 0xd094 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:43.625487089 CEST | 192.168.2.13 | 8.8.8.8 | 0x5c68 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:49.062283039 CEST | 192.168.2.13 | 8.8.8.8 | 0xfc1a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:56.491159916 CEST | 192.168.2.13 | 8.8.8.8 | 0xbf2b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:01.922209978 CEST | 192.168.2.13 | 8.8.8.8 | 0xc32 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:07.352684975 CEST | 192.168.2.13 | 8.8.8.8 | 0x1bd1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:15.792056084 CEST | 192.168.2.13 | 8.8.8.8 | 0x1292 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:24.223299026 CEST | 192.168.2.13 | 8.8.8.8 | 0x38a4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:25.654392958 CEST | 192.168.2.13 | 8.8.8.8 | 0x90c5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:29.090467930 CEST | 192.168.2.13 | 8.8.8.8 | 0x96ba | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:39.520365000 CEST | 192.168.2.13 | 8.8.8.8 | 0x1628 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:46.950469971 CEST | 192.168.2.13 | 8.8.8.8 | 0x158e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:55.532656908 CEST | 192.168.2.13 | 8.8.8.8 | 0xa0f3 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 21, 2024 18:46:59.325253963 CEST | 8.8.8.8 | 192.168.2.13 | 0x4483 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:05.756860018 CEST | 8.8.8.8 | 192.168.2.13 | 0x1189 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:15.189307928 CEST | 8.8.8.8 | 192.168.2.13 | 0x7ac0 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:24.769328117 CEST | 8.8.8.8 | 192.168.2.13 | 0x397b | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:34.202649117 CEST | 8.8.8.8 | 192.168.2.13 | 0xd094 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:43.633817911 CEST | 8.8.8.8 | 192.168.2.13 | 0x5c68 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:49.070327044 CEST | 8.8.8.8 | 192.168.2.13 | 0xfc1a | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:56.499037981 CEST | 8.8.8.8 | 192.168.2.13 | 0xbf2b | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:01.930025101 CEST | 8.8.8.8 | 192.168.2.13 | 0xc32 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:07.364348888 CEST | 8.8.8.8 | 192.168.2.13 | 0x1bd1 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:15.799968004 CEST | 8.8.8.8 | 192.168.2.13 | 0x1292 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:24.230541945 CEST | 8.8.8.8 | 192.168.2.13 | 0x38a4 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:25.664289951 CEST | 8.8.8.8 | 192.168.2.13 | 0x90c5 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:29.098448038 CEST | 8.8.8.8 | 192.168.2.13 | 0x96ba | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:39.527983904 CEST | 8.8.8.8 | 192.168.2.13 | 0x1628 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:47.109000921 CEST | 8.8.8.8 | 192.168.2.13 | 0x158e | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:55.541291952 CEST | 8.8.8.8 | 192.168.2.13 | 0xa0f3 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 16:46:58 |
Start date (UTC): | 21/10/2024 |
Path: | /tmp/x86.elf |
Arguments: | /tmp/x86.elf |
File size: | 47504 bytes |
MD5 hash: | a51270cb597ae42f4cb7bea59f2f6434 |
Start time (UTC): | 16:46:58 |
Start date (UTC): | 21/10/2024 |
Path: | /tmp/x86.elf |
Arguments: | - |
File size: | 47504 bytes |
MD5 hash: | a51270cb597ae42f4cb7bea59f2f6434 |
Start time (UTC): | 16:46:58 |
Start date (UTC): | 21/10/2024 |
Path: | /tmp/x86.elf |
Arguments: | - |
File size: | 47504 bytes |
MD5 hash: | a51270cb597ae42f4cb7bea59f2f6434 |
Start time (UTC): | 16:46:58 |
Start date (UTC): | 21/10/2024 |
Path: | /tmp/x86.elf |
Arguments: | - |
File size: | 47504 bytes |
MD5 hash: | a51270cb597ae42f4cb7bea59f2f6434 |
Start time (UTC): | 16:46:58 |
Start date (UTC): | 21/10/2024 |
Path: | /tmp/x86.elf |
Arguments: | - |
File size: | 47504 bytes |
MD5 hash: | a51270cb597ae42f4cb7bea59f2f6434 |