Edit tour
Linux
Analysis Report
x86_64.elf
Overview
General Information
Detection
Mirai, Moobot
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Detected Mirai
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Mirai
Yara detected Moobot
Connects to many ports of the same IP (likely port scanning)
Machine Learning detection for sample
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Yara signature match
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1538771 |
Start date and time: | 2024-10-21 18:46:12 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 24s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | x86_64.elf |
Detection: | MAL |
Classification: | mal100.troj.evad.linELF@0/0@25/0 |
- VT rate limit hit for: x86_64.elf
Command: | /tmp/x86_64.elf |
PID: | 5489 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | done. |
Standard Error: |
- system is lnxubuntu20
- x86_64.elf New Fork (PID: 5490, Parent: 5489)
- x86_64.elf New Fork (PID: 5491, Parent: 5490)
- x86_64.elf New Fork (PID: 5492, Parent: 5490)
- x86_64.elf New Fork (PID: 5493, Parent: 5492)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Mirai | Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world. | No Attribution |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
MooBot | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Moobot | Yara detected Moobot | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
Linux_Trojan_Gafgyt_9e9530a7 | unknown | unknown |
| |
Linux_Trojan_Gafgyt_807911a2 | unknown | unknown |
| |
Click to see the 9 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Moobot | Yara detected Moobot | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
Linux_Trojan_Gafgyt_9e9530a7 | unknown | unknown |
| |
Linux_Trojan_Gafgyt_807911a2 | unknown | unknown |
| |
Click to see the 11 entries |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-21T18:47:04.360219+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 37662 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:11.793334+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 37664 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:13.437473+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 37666 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:14.873132+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 37668 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:18.308645+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 37670 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:23.741702+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 37672 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:27.199437+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 37674 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:30.617842+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 37676 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:39.050395+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 37678 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:45.484564+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 37680 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:49.932820+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 37682 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:55.363102+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 37684 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:03.794743+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 37686 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:11.230889+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 37688 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:20.669718+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 37690 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:28.106099+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 37692 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:30.545317+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 37694 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:39.097659+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 37696 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:48.529050+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 37698 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:51.962017+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 37700 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:53.396244+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 37702 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:56.835865+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 37704 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:58.273047+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 37706 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:49:04.709969+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 37708 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:49:07.141242+0200 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 37710 | 107.189.4.201 | 58431 | TCP |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Source: | Joe Sandbox ML: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | TCP traffic: |
Source: | TCP traffic: |
Source: | DNS traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | .symtab present: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | 1 File Deletion | 1 OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Non-Standard Port | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
76% | ReversingLabs | Linux.Backdoor.Mirai | ||
100% | Avira | EXP/ELF.Mirai.Z.A | ||
100% | Joe Sandbox ML |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
update.byeux.com | 107.189.4.201 | true | true | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
107.189.4.201 | update.byeux.com | United States | 53667 | PONYNETUS | true |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
107.189.4.201 | Get hash | malicious | Mirai, Moobot | Browse | ||
Get hash | malicious | Mirai, Moobot | Browse | |||
Get hash | malicious | Mirai, Moobot | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
update.byeux.com | Get hash | malicious | Mirai, Moobot | Browse |
| |
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
PONYNETUS | Get hash | malicious | Gafgyt, Mirai | Browse |
| |
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 6.13452947468174 |
TrID: |
|
File name: | x86_64.elf |
File size: | 55'104 bytes |
MD5: | c7b297469d29bc62692d2423d7b377e9 |
SHA1: | 07d49bbadd74bd5f9e528d1b16552a3fdb7b91c7 |
SHA256: | a290d831c056125688b9ac4270cc22ef260efae780d6d1397ae51c926f0463eb |
SHA512: | 800422e27f04982d333bc520213bc5dd797b62f0983a8aa113aae686c2821356d8961b06d412d80aa3493ea4f87da41245a203f05c337226e6f6e5982ab79025 |
SSDEEP: | 1536:B8AiP6h4wh2tIF9ts/6PJSdZD4+a60mWHMXpOACYf:BZiSh4wh26/ts/6huJLa60dGpOACYf |
TLSH: | 4B331917B58180FDC4AAC1744B6BBA3E9D3370ED133DB3A977E4EB222996E614D58C40 |
File Content Preview: | .ELF..............>.......@.....@...................@.8...@.......................@.......@.....0.......0.................................P.......P.............(...............Q.td....................................................H...._........H........ |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 64 |
Program Header Offset: | 64 |
Program Header Size: | 56 |
Number of Program Headers: | 3 |
Section Header Offset: | 54464 |
Section Header Size: | 64 |
Number of Section Headers: | 10 |
Header String Table Index: | 9 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x4000e8 | 0xe8 | 0x13 | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.text | PROGBITS | 0x400100 | 0x100 | 0xa8d6 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x40a9d6 | 0xa9d6 | 0xe | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.rodata | PROGBITS | 0x40aa00 | 0xaa00 | 0x1f30 | 0x0 | 0x2 | A | 0 | 0 | 32 |
.ctors | PROGBITS | 0x50d000 | 0xd000 | 0x10 | 0x0 | 0x3 | WA | 0 | 0 | 8 |
.dtors | PROGBITS | 0x50d010 | 0xd010 | 0x10 | 0x0 | 0x3 | WA | 0 | 0 | 8 |
.data | PROGBITS | 0x50d040 | 0xd040 | 0x440 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.bss | NOBITS | 0x50d480 | 0xd480 | 0x29a8 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.shstrtab | STRTAB | 0x0 | 0xd480 | 0x3e | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x400000 | 0x400000 | 0xc930 | 0xc930 | 6.3540 | 0x5 | R E | 0x100000 | .init .text .fini .rodata | |
LOAD | 0xd000 | 0x50d000 | 0x50d000 | 0x480 | 0x2e28 | 2.1322 | 0x6 | RW | 0x100000 | .ctors .dtors .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x8 |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-21T18:47:04.360219+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 37662 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:11.793334+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 37664 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:13.437473+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 37666 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:14.873132+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 37668 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:18.308645+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 37670 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:23.741702+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 37672 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:27.199437+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 37674 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:30.617842+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 37676 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:39.050395+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 37678 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:45.484564+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 37680 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:49.932820+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 37682 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:47:55.363102+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 37684 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:03.794743+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 37686 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:11.230889+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 37688 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:20.669718+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 37690 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:28.106099+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 37692 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:30.545317+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 37694 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:39.097659+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 37696 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:48.529050+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 37698 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:51.962017+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 37700 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:53.396244+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 37702 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:56.835865+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 37704 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:48:58.273047+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 37706 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:49:04.709969+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 37708 | 107.189.4.201 | 58431 | TCP |
2024-10-21T18:49:07.141242+0200 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 37710 | 107.189.4.201 | 58431 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 21, 2024 18:47:04.347996950 CEST | 37662 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:04.355528116 CEST | 58431 | 37662 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:04.355607986 CEST | 37662 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:04.360219002 CEST | 37662 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:04.365566015 CEST | 58431 | 37662 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:04.772844076 CEST | 58431 | 37662 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:04.772943974 CEST | 37662 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:04.778633118 CEST | 58431 | 37662 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:11.785005093 CEST | 37664 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:11.792660952 CEST | 58431 | 37664 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:11.792762041 CEST | 37664 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:11.793334007 CEST | 37664 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:11.801103115 CEST | 58431 | 37664 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:12.216372013 CEST | 58431 | 37664 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:12.216770887 CEST | 37664 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:12.222196102 CEST | 58431 | 37664 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:13.430962086 CEST | 37666 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:13.436923027 CEST | 58431 | 37666 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:13.436973095 CEST | 37666 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:13.437473059 CEST | 37666 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:13.442898989 CEST | 58431 | 37666 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:13.855510950 CEST | 58431 | 37666 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:13.855762959 CEST | 37666 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:13.861202002 CEST | 58431 | 37666 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:14.866919994 CEST | 37668 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:14.872520924 CEST | 58431 | 37668 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:14.872620106 CEST | 37668 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:14.873131990 CEST | 37668 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:14.878616095 CEST | 58431 | 37668 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:15.288722038 CEST | 58431 | 37668 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:15.288800955 CEST | 37668 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:15.295000076 CEST | 58431 | 37668 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:18.301033974 CEST | 37670 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:18.307774067 CEST | 58431 | 37670 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:18.307836056 CEST | 37670 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:18.308645010 CEST | 37670 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:18.315198898 CEST | 58431 | 37670 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:18.724301100 CEST | 58431 | 37670 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:18.724462986 CEST | 37670 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:18.729949951 CEST | 58431 | 37670 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:23.734649897 CEST | 37672 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:23.740101099 CEST | 58431 | 37672 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:23.740216970 CEST | 37672 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:23.741702080 CEST | 37672 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:23.747096062 CEST | 58431 | 37672 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:24.160397053 CEST | 58431 | 37672 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:24.160599947 CEST | 37672 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:24.166039944 CEST | 58431 | 37672 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:27.181647062 CEST | 37674 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:27.187148094 CEST | 58431 | 37674 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:27.187292099 CEST | 37674 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:27.199436903 CEST | 37674 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:27.204937935 CEST | 58431 | 37674 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:27.601461887 CEST | 58431 | 37674 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:27.601725101 CEST | 37674 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:27.607218027 CEST | 58431 | 37674 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:30.611690998 CEST | 37676 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:30.617089033 CEST | 58431 | 37676 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:30.617208004 CEST | 37676 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:30.617841959 CEST | 37676 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:30.623080969 CEST | 58431 | 37676 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:31.031858921 CEST | 58431 | 37676 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:31.032233000 CEST | 37676 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:31.038391113 CEST | 58431 | 37676 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:39.043031931 CEST | 37678 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:39.049566031 CEST | 58431 | 37678 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:39.049623013 CEST | 37678 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:39.050395012 CEST | 37678 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:39.056802988 CEST | 58431 | 37678 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:39.464375019 CEST | 58431 | 37678 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:39.464622021 CEST | 37678 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:39.470601082 CEST | 58431 | 37678 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:45.477488995 CEST | 37680 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:45.483338118 CEST | 58431 | 37680 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:45.483465910 CEST | 37680 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:45.484564066 CEST | 37680 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:45.489986897 CEST | 58431 | 37680 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:45.915723085 CEST | 58431 | 37680 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:45.916168928 CEST | 37680 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:45.921633005 CEST | 58431 | 37680 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:49.926475048 CEST | 37682 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:49.931813002 CEST | 58431 | 37682 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:49.931905031 CEST | 37682 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:49.932820082 CEST | 37682 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:49.938143969 CEST | 58431 | 37682 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:50.346693039 CEST | 58431 | 37682 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:50.347018957 CEST | 37682 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:50.352654934 CEST | 58431 | 37682 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:55.357000113 CEST | 37684 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:55.362415075 CEST | 58431 | 37684 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:55.362469912 CEST | 37684 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:55.363101959 CEST | 37684 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:55.368452072 CEST | 58431 | 37684 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:55.776278019 CEST | 58431 | 37684 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:47:55.776727915 CEST | 37684 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:47:55.782075882 CEST | 58431 | 37684 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:03.787496090 CEST | 37686 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:03.793627024 CEST | 58431 | 37686 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:03.793735981 CEST | 37686 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:03.794743061 CEST | 37686 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:03.800240993 CEST | 58431 | 37686 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:04.212723017 CEST | 58431 | 37686 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:04.212949991 CEST | 37686 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:04.218426943 CEST | 58431 | 37686 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:11.224673986 CEST | 37688 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:11.230134964 CEST | 58431 | 37688 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:11.230196953 CEST | 37688 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:11.230889082 CEST | 37688 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:11.236326933 CEST | 58431 | 37688 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:11.646724939 CEST | 58431 | 37688 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:11.646851063 CEST | 37688 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:11.652456999 CEST | 58431 | 37688 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:20.660274029 CEST | 37690 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:20.668668032 CEST | 58431 | 37690 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:20.668792009 CEST | 37690 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:20.669718027 CEST | 37690 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:20.675225973 CEST | 58431 | 37690 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:21.085891962 CEST | 58431 | 37690 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:21.086216927 CEST | 37690 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:21.091557026 CEST | 58431 | 37690 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:28.097780943 CEST | 37692 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:28.104835033 CEST | 58431 | 37692 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:28.104893923 CEST | 37692 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:28.106098890 CEST | 37692 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:28.111588955 CEST | 58431 | 37692 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:28.523214102 CEST | 58431 | 37692 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:28.523561954 CEST | 37692 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:28.529289961 CEST | 58431 | 37692 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:30.536993027 CEST | 37694 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:30.544111013 CEST | 58431 | 37694 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:30.544177055 CEST | 37694 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:30.545316935 CEST | 37694 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:30.552767992 CEST | 58431 | 37694 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:30.961900949 CEST | 58431 | 37694 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:30.962182045 CEST | 37694 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:30.967998028 CEST | 58431 | 37694 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:39.090730906 CEST | 37696 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:39.096391916 CEST | 58431 | 37696 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:39.096465111 CEST | 37696 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:39.097659111 CEST | 37696 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:39.103306055 CEST | 58431 | 37696 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:39.510577917 CEST | 58431 | 37696 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:39.510957956 CEST | 37696 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:39.516468048 CEST | 58431 | 37696 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:48.521894932 CEST | 37698 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:48.528014898 CEST | 58431 | 37698 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:48.528094053 CEST | 37698 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:48.529050112 CEST | 37698 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:48.534380913 CEST | 58431 | 37698 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:48.942765951 CEST | 58431 | 37698 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:48.943059921 CEST | 37698 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:48.948427916 CEST | 58431 | 37698 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:51.955148935 CEST | 37700 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:51.960606098 CEST | 58431 | 37700 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:51.960733891 CEST | 37700 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:51.962017059 CEST | 37700 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:51.967427015 CEST | 58431 | 37700 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:52.377182961 CEST | 58431 | 37700 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:52.377641916 CEST | 37700 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:52.383605957 CEST | 58431 | 37700 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:53.389556885 CEST | 37702 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:53.395144939 CEST | 58431 | 37702 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:53.395232916 CEST | 37702 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:53.396244049 CEST | 37702 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:53.401856899 CEST | 58431 | 37702 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:53.814384937 CEST | 58431 | 37702 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:53.814627886 CEST | 37702 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:53.821445942 CEST | 58431 | 37702 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:56.827902079 CEST | 37704 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:56.834619999 CEST | 58431 | 37704 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:56.834724903 CEST | 37704 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:56.835865021 CEST | 37704 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:56.842120886 CEST | 58431 | 37704 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:57.255507946 CEST | 58431 | 37704 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:57.256069899 CEST | 37704 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:57.262490988 CEST | 58431 | 37704 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:58.266824961 CEST | 37706 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:58.272279024 CEST | 58431 | 37706 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:58.272362947 CEST | 37706 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:58.273046970 CEST | 37706 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:58.278403997 CEST | 58431 | 37706 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:58.691680908 CEST | 58431 | 37706 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:48:58.691858053 CEST | 37706 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:48:58.698657036 CEST | 58431 | 37706 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:49:04.703385115 CEST | 37708 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:49:04.708822966 CEST | 58431 | 37708 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:49:04.708945990 CEST | 37708 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:49:04.709969044 CEST | 37708 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:49:04.715351105 CEST | 58431 | 37708 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:49:05.122664928 CEST | 58431 | 37708 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:49:05.122926950 CEST | 37708 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:49:05.128303051 CEST | 58431 | 37708 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:49:07.134835958 CEST | 37710 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:49:07.140238047 CEST | 58431 | 37710 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:49:07.140372038 CEST | 37710 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:49:07.141242027 CEST | 37710 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:49:07.146516085 CEST | 58431 | 37710 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:49:07.555782080 CEST | 58431 | 37710 | 107.189.4.201 | 192.168.2.14 |
Oct 21, 2024 18:49:07.555905104 CEST | 37710 | 58431 | 192.168.2.14 | 107.189.4.201 |
Oct 21, 2024 18:49:07.561306000 CEST | 58431 | 37710 | 107.189.4.201 | 192.168.2.14 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 21, 2024 18:47:04.337990046 CEST | 44269 | 53 | 192.168.2.14 | 8.8.8.8 |
Oct 21, 2024 18:47:04.347050905 CEST | 53 | 44269 | 8.8.8.8 | 192.168.2.14 |
Oct 21, 2024 18:47:11.774347067 CEST | 43072 | 53 | 192.168.2.14 | 8.8.8.8 |
Oct 21, 2024 18:47:11.784454107 CEST | 53 | 43072 | 8.8.8.8 | 192.168.2.14 |
Oct 21, 2024 18:47:13.218734026 CEST | 41999 | 53 | 192.168.2.14 | 8.8.8.8 |
Oct 21, 2024 18:47:13.430387974 CEST | 53 | 41999 | 8.8.8.8 | 192.168.2.14 |
Oct 21, 2024 18:47:14.858477116 CEST | 56815 | 53 | 192.168.2.14 | 8.8.8.8 |
Oct 21, 2024 18:47:14.866364956 CEST | 53 | 56815 | 8.8.8.8 | 192.168.2.14 |
Oct 21, 2024 18:47:18.290730953 CEST | 35952 | 53 | 192.168.2.14 | 8.8.8.8 |
Oct 21, 2024 18:47:18.300499916 CEST | 53 | 35952 | 8.8.8.8 | 192.168.2.14 |
Oct 21, 2024 18:47:23.726589918 CEST | 47977 | 53 | 192.168.2.14 | 8.8.8.8 |
Oct 21, 2024 18:47:23.733978033 CEST | 53 | 47977 | 8.8.8.8 | 192.168.2.14 |
Oct 21, 2024 18:47:27.171207905 CEST | 51240 | 53 | 192.168.2.14 | 8.8.8.8 |
Oct 21, 2024 18:47:27.178611040 CEST | 53 | 51240 | 8.8.8.8 | 192.168.2.14 |
Oct 21, 2024 18:47:30.603653908 CEST | 55687 | 53 | 192.168.2.14 | 8.8.8.8 |
Oct 21, 2024 18:47:30.611285925 CEST | 53 | 55687 | 8.8.8.8 | 192.168.2.14 |
Oct 21, 2024 18:47:39.034801960 CEST | 41182 | 53 | 192.168.2.14 | 8.8.8.8 |
Oct 21, 2024 18:47:39.042567015 CEST | 53 | 41182 | 8.8.8.8 | 192.168.2.14 |
Oct 21, 2024 18:47:45.467354059 CEST | 39798 | 53 | 192.168.2.14 | 8.8.8.8 |
Oct 21, 2024 18:47:45.476759911 CEST | 53 | 39798 | 8.8.8.8 | 192.168.2.14 |
Oct 21, 2024 18:47:49.918323994 CEST | 52623 | 53 | 192.168.2.14 | 8.8.8.8 |
Oct 21, 2024 18:47:49.925772905 CEST | 53 | 52623 | 8.8.8.8 | 192.168.2.14 |
Oct 21, 2024 18:47:55.348773003 CEST | 43275 | 53 | 192.168.2.14 | 8.8.8.8 |
Oct 21, 2024 18:47:55.356595993 CEST | 53 | 43275 | 8.8.8.8 | 192.168.2.14 |
Oct 21, 2024 18:48:03.778595924 CEST | 44631 | 53 | 192.168.2.14 | 8.8.8.8 |
Oct 21, 2024 18:48:03.786804914 CEST | 53 | 44631 | 8.8.8.8 | 192.168.2.14 |
Oct 21, 2024 18:48:11.217314959 CEST | 34538 | 53 | 192.168.2.14 | 8.8.8.8 |
Oct 21, 2024 18:48:11.224280119 CEST | 53 | 34538 | 8.8.8.8 | 192.168.2.14 |
Oct 21, 2024 18:48:20.649082899 CEST | 38541 | 53 | 192.168.2.14 | 8.8.8.8 |
Oct 21, 2024 18:48:20.659655094 CEST | 53 | 38541 | 8.8.8.8 | 192.168.2.14 |
Oct 21, 2024 18:48:28.089411974 CEST | 57316 | 53 | 192.168.2.14 | 8.8.8.8 |
Oct 21, 2024 18:48:28.097253084 CEST | 53 | 57316 | 8.8.8.8 | 192.168.2.14 |
Oct 21, 2024 18:48:30.526423931 CEST | 36845 | 53 | 192.168.2.14 | 8.8.8.8 |
Oct 21, 2024 18:48:30.536199093 CEST | 53 | 36845 | 8.8.8.8 | 192.168.2.14 |
Oct 21, 2024 18:48:38.965153933 CEST | 40960 | 53 | 192.168.2.14 | 8.8.8.8 |
Oct 21, 2024 18:48:39.089667082 CEST | 53 | 40960 | 8.8.8.8 | 192.168.2.14 |
Oct 21, 2024 18:48:48.513185978 CEST | 52444 | 53 | 192.168.2.14 | 8.8.8.8 |
Oct 21, 2024 18:48:48.521327019 CEST | 53 | 52444 | 8.8.8.8 | 192.168.2.14 |
Oct 21, 2024 18:48:51.946275949 CEST | 56048 | 53 | 192.168.2.14 | 8.8.8.8 |
Oct 21, 2024 18:48:51.954360962 CEST | 53 | 56048 | 8.8.8.8 | 192.168.2.14 |
Oct 21, 2024 18:48:53.380623102 CEST | 37895 | 53 | 192.168.2.14 | 8.8.8.8 |
Oct 21, 2024 18:48:53.388928890 CEST | 53 | 37895 | 8.8.8.8 | 192.168.2.14 |
Oct 21, 2024 18:48:56.817687988 CEST | 33272 | 53 | 192.168.2.14 | 8.8.8.8 |
Oct 21, 2024 18:48:56.827258110 CEST | 53 | 33272 | 8.8.8.8 | 192.168.2.14 |
Oct 21, 2024 18:48:58.258464098 CEST | 40600 | 53 | 192.168.2.14 | 8.8.8.8 |
Oct 21, 2024 18:48:58.266382933 CEST | 53 | 40600 | 8.8.8.8 | 192.168.2.14 |
Oct 21, 2024 18:49:04.694426060 CEST | 60087 | 53 | 192.168.2.14 | 8.8.8.8 |
Oct 21, 2024 18:49:04.702728033 CEST | 53 | 60087 | 8.8.8.8 | 192.168.2.14 |
Oct 21, 2024 18:49:07.126101017 CEST | 55677 | 53 | 192.168.2.14 | 8.8.8.8 |
Oct 21, 2024 18:49:07.133949995 CEST | 53 | 55677 | 8.8.8.8 | 192.168.2.14 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 21, 2024 18:47:04.337990046 CEST | 192.168.2.14 | 8.8.8.8 | 0x5d7c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:11.774347067 CEST | 192.168.2.14 | 8.8.8.8 | 0x1386 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:13.218734026 CEST | 192.168.2.14 | 8.8.8.8 | 0x5c61 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:14.858477116 CEST | 192.168.2.14 | 8.8.8.8 | 0xc7d2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:18.290730953 CEST | 192.168.2.14 | 8.8.8.8 | 0x3c71 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:23.726589918 CEST | 192.168.2.14 | 8.8.8.8 | 0x495f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:27.171207905 CEST | 192.168.2.14 | 8.8.8.8 | 0x1cde | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:30.603653908 CEST | 192.168.2.14 | 8.8.8.8 | 0x6f39 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:39.034801960 CEST | 192.168.2.14 | 8.8.8.8 | 0xcd99 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:45.467354059 CEST | 192.168.2.14 | 8.8.8.8 | 0x6ac2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:49.918323994 CEST | 192.168.2.14 | 8.8.8.8 | 0xaee6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:47:55.348773003 CEST | 192.168.2.14 | 8.8.8.8 | 0xd96b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:03.778595924 CEST | 192.168.2.14 | 8.8.8.8 | 0xbc61 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:11.217314959 CEST | 192.168.2.14 | 8.8.8.8 | 0x6874 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:20.649082899 CEST | 192.168.2.14 | 8.8.8.8 | 0xb195 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:28.089411974 CEST | 192.168.2.14 | 8.8.8.8 | 0x24e1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:30.526423931 CEST | 192.168.2.14 | 8.8.8.8 | 0x21ef | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:38.965153933 CEST | 192.168.2.14 | 8.8.8.8 | 0x830c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:48.513185978 CEST | 192.168.2.14 | 8.8.8.8 | 0x2d55 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:51.946275949 CEST | 192.168.2.14 | 8.8.8.8 | 0xf6e6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:53.380623102 CEST | 192.168.2.14 | 8.8.8.8 | 0x3122 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:56.817687988 CEST | 192.168.2.14 | 8.8.8.8 | 0x1641 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:48:58.258464098 CEST | 192.168.2.14 | 8.8.8.8 | 0x1285 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:49:04.694426060 CEST | 192.168.2.14 | 8.8.8.8 | 0x7f4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 21, 2024 18:49:07.126101017 CEST | 192.168.2.14 | 8.8.8.8 | 0xc224 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 21, 2024 18:47:04.347050905 CEST | 8.8.8.8 | 192.168.2.14 | 0x5d7c | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:11.784454107 CEST | 8.8.8.8 | 192.168.2.14 | 0x1386 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:13.430387974 CEST | 8.8.8.8 | 192.168.2.14 | 0x5c61 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:14.866364956 CEST | 8.8.8.8 | 192.168.2.14 | 0xc7d2 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:18.300499916 CEST | 8.8.8.8 | 192.168.2.14 | 0x3c71 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:23.733978033 CEST | 8.8.8.8 | 192.168.2.14 | 0x495f | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:27.178611040 CEST | 8.8.8.8 | 192.168.2.14 | 0x1cde | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:30.611285925 CEST | 8.8.8.8 | 192.168.2.14 | 0x6f39 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:39.042567015 CEST | 8.8.8.8 | 192.168.2.14 | 0xcd99 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:45.476759911 CEST | 8.8.8.8 | 192.168.2.14 | 0x6ac2 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:49.925772905 CEST | 8.8.8.8 | 192.168.2.14 | 0xaee6 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:47:55.356595993 CEST | 8.8.8.8 | 192.168.2.14 | 0xd96b | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:03.786804914 CEST | 8.8.8.8 | 192.168.2.14 | 0xbc61 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:11.224280119 CEST | 8.8.8.8 | 192.168.2.14 | 0x6874 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:20.659655094 CEST | 8.8.8.8 | 192.168.2.14 | 0xb195 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:28.097253084 CEST | 8.8.8.8 | 192.168.2.14 | 0x24e1 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:30.536199093 CEST | 8.8.8.8 | 192.168.2.14 | 0x21ef | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:39.089667082 CEST | 8.8.8.8 | 192.168.2.14 | 0x830c | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:48.521327019 CEST | 8.8.8.8 | 192.168.2.14 | 0x2d55 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:51.954360962 CEST | 8.8.8.8 | 192.168.2.14 | 0xf6e6 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:53.388928890 CEST | 8.8.8.8 | 192.168.2.14 | 0x3122 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:56.827258110 CEST | 8.8.8.8 | 192.168.2.14 | 0x1641 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:48:58.266382933 CEST | 8.8.8.8 | 192.168.2.14 | 0x1285 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:49:04.702728033 CEST | 8.8.8.8 | 192.168.2.14 | 0x7f4 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false | ||
Oct 21, 2024 18:49:07.133949995 CEST | 8.8.8.8 | 192.168.2.14 | 0xc224 | No error (0) | 107.189.4.201 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 16:47:02 |
Start date (UTC): | 21/10/2024 |
Path: | /tmp/x86_64.elf |
Arguments: | /tmp/x86_64.elf |
File size: | 55104 bytes |
MD5 hash: | c7b297469d29bc62692d2423d7b377e9 |
Start time (UTC): | 16:47:03 |
Start date (UTC): | 21/10/2024 |
Path: | /tmp/x86_64.elf |
Arguments: | - |
File size: | 55104 bytes |
MD5 hash: | c7b297469d29bc62692d2423d7b377e9 |
Start time (UTC): | 16:47:03 |
Start date (UTC): | 21/10/2024 |
Path: | /tmp/x86_64.elf |
Arguments: | - |
File size: | 55104 bytes |
MD5 hash: | c7b297469d29bc62692d2423d7b377e9 |
Start time (UTC): | 16:47:03 |
Start date (UTC): | 21/10/2024 |
Path: | /tmp/x86_64.elf |
Arguments: | - |
File size: | 55104 bytes |
MD5 hash: | c7b297469d29bc62692d2423d7b377e9 |
Start time (UTC): | 16:47:03 |
Start date (UTC): | 21/10/2024 |
Path: | /tmp/x86_64.elf |
Arguments: | - |
File size: | 55104 bytes |
MD5 hash: | c7b297469d29bc62692d2423d7b377e9 |