Edit tour
Linux
Analysis Report
zerppc.elf
Overview
General Information
Detection
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Sends malformed DNS queries
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1543098 |
Start date and time: | 2024-10-27 08:57:13 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 34s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | zerppc.elf |
Detection: | MAL |
Classification: | mal56.troj.linELF@0/0@18/0 |
- VT rate limit hit for: yellowchink.pirate
Command: | /tmp/zerppc.elf |
PID: | 5462 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | The Peoples Bank of China. |
Standard Error: |
- system is lnxubuntu20
- zerppc.elf New Fork (PID: 5464, Parent: 5462)
- zerppc.elf New Fork (PID: 5466, Parent: 5464)
- cleanup
⊘No yara matches
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Networking |
---|
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | .symtab present: |
Source: | Classification label: |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | Direct Volume Access | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Non-Standard Port | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
39% | ReversingLabs | Linux.Trojan.Mirai | ||
43% | Virustotal | Browse |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
yellowchink.pirate | 45.156.86.24 | true | true | unknown | |
chinklabs.dyn | 185.150.24.67 | true | true | unknown | |
burnthe.libre | 45.156.86.24 | true | true | unknown | |
chinklabs.dyn. [malformed] | unknown | unknown | true | unknown | |
netfags.geek. [malformed] | unknown | unknown | true | unknown | |
burnthe.libre. [malformed] | unknown | unknown | true | unknown | |
yellowchink.pirate. [malformed] | unknown | unknown | true | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
185.150.24.67 | chinklabs.dyn | Netherlands | 44592 | SKYLINKNL | true | |
45.156.86.24 | yellowchink.pirate | Germany | 44592 | SKYLINKNL | true |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
185.150.24.67 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
burnthe.libre | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
yellowchink.pirate | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
SKYLINKNL | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
SKYLINKNL | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 6.217742381176895 |
TrID: |
|
File name: | zerppc.elf |
File size: | 46'296 bytes |
MD5: | dca795506df8d44ff8a9d45e85caf92b |
SHA1: | 1212e0e371e3ea71cc517f7ff644c9ff4362560e |
SHA256: | 6d86b401f77c1ffcc9d29d1b157f44b08611b84c4ea238b32d76c48eae4f62da |
SHA512: | 48173f7875e5dbf9333f0555bfc9839ee3703dbfb236e66ba353ef8b81850eeb38f32dca98a4c580ed4247b5c1602e45086b9a53c2331856f7b43b6dfaab0926 |
SSDEEP: | 768:UrpFtoekRioB66QTNC0SRhWELuIGSfZPsNDSYYc7qNnH:2FWTEX6QWRhWDShP0DSYB7unH |
TLSH: | 19234B43721C0A27C5A25774253F17F093FFADA025E4B688A40F9B5A8971F372486F9E |
File Content Preview: | .ELF...........................4.........4. ...(....................................................................dt.Q.............................!..|......$H...H..m...$8!. |...N.. .!..|.......?.............../...@..\?........+../...A..$8...})......N.. |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 45776 |
Section Header Size: | 40 |
Number of Section Headers: | 13 |
Header String Table Index: | 12 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x10000094 | 0x94 | 0x24 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x100000b8 | 0xb8 | 0xa6c4 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.fini | PROGBITS | 0x1000a77c | 0xa77c | 0x20 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x1000a79c | 0xa79c | 0x95c | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ctors | PROGBITS | 0x1001b0fc | 0xb0fc | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x1001b104 | 0xb104 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.jcr | PROGBITS | 0x1001b10c | 0xb10c | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x1001b110 | 0xb110 | 0x148 | 0x0 | 0x3 | WA | 0 | 0 | 8 |
.sdata | PROGBITS | 0x1001b258 | 0xb258 | 0x28 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.sbss | NOBITS | 0x1001b280 | 0xb280 | 0x5c | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x1001b2dc | 0xb280 | 0x10c | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.shstrtab | STRTAB | 0x0 | 0xb280 | 0x50 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x10000000 | 0x10000000 | 0xb0f8 | 0xb0f8 | 6.2749 | 0x5 | R E | 0x10000 | .init .text .fini .rodata | |
LOAD | 0xb0fc | 0x1001b0fc | 0x1001b0fc | 0x184 | 0x2ec | 0.8988 | 0x6 | RW | 0x10000 | .ctors .dtors .jcr .data .sdata .sbss .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 27, 2024 08:58:03.487375021 CET | 33436 | 38241 | 192.168.2.13 | 185.150.24.67 |
Oct 27, 2024 08:58:03.492981911 CET | 38241 | 33436 | 185.150.24.67 | 192.168.2.13 |
Oct 27, 2024 08:58:03.493212938 CET | 33436 | 38241 | 192.168.2.13 | 185.150.24.67 |
Oct 27, 2024 08:58:03.506023884 CET | 33436 | 38241 | 192.168.2.13 | 185.150.24.67 |
Oct 27, 2024 08:58:03.511667967 CET | 38241 | 33436 | 185.150.24.67 | 192.168.2.13 |
Oct 27, 2024 08:58:03.511856079 CET | 33436 | 38241 | 192.168.2.13 | 185.150.24.67 |
Oct 27, 2024 08:58:03.517400980 CET | 38241 | 33436 | 185.150.24.67 | 192.168.2.13 |
Oct 27, 2024 08:58:04.275667906 CET | 38241 | 33436 | 185.150.24.67 | 192.168.2.13 |
Oct 27, 2024 08:58:04.276146889 CET | 33436 | 38241 | 192.168.2.13 | 185.150.24.67 |
Oct 27, 2024 08:58:04.282031059 CET | 38241 | 33436 | 185.150.24.67 | 192.168.2.13 |
Oct 27, 2024 08:58:05.289815903 CET | 33438 | 38241 | 192.168.2.13 | 185.150.24.67 |
Oct 27, 2024 08:58:05.295377970 CET | 38241 | 33438 | 185.150.24.67 | 192.168.2.13 |
Oct 27, 2024 08:58:05.295444012 CET | 33438 | 38241 | 192.168.2.13 | 185.150.24.67 |
Oct 27, 2024 08:58:05.296185017 CET | 33438 | 38241 | 192.168.2.13 | 185.150.24.67 |
Oct 27, 2024 08:58:05.301441908 CET | 38241 | 33438 | 185.150.24.67 | 192.168.2.13 |
Oct 27, 2024 08:58:05.301491976 CET | 33438 | 38241 | 192.168.2.13 | 185.150.24.67 |
Oct 27, 2024 08:58:05.306849957 CET | 38241 | 33438 | 185.150.24.67 | 192.168.2.13 |
Oct 27, 2024 08:58:05.895735979 CET | 38241 | 33438 | 185.150.24.67 | 192.168.2.13 |
Oct 27, 2024 08:58:05.896171093 CET | 33438 | 38241 | 192.168.2.13 | 185.150.24.67 |
Oct 27, 2024 08:58:05.901988029 CET | 38241 | 33438 | 185.150.24.67 | 192.168.2.13 |
Oct 27, 2024 08:58:06.910146952 CET | 33440 | 38241 | 192.168.2.13 | 185.150.24.67 |
Oct 27, 2024 08:58:06.916084051 CET | 38241 | 33440 | 185.150.24.67 | 192.168.2.13 |
Oct 27, 2024 08:58:06.916176081 CET | 33440 | 38241 | 192.168.2.13 | 185.150.24.67 |
Oct 27, 2024 08:58:06.917084932 CET | 33440 | 38241 | 192.168.2.13 | 185.150.24.67 |
Oct 27, 2024 08:58:06.922831059 CET | 38241 | 33440 | 185.150.24.67 | 192.168.2.13 |
Oct 27, 2024 08:58:06.922992945 CET | 33440 | 38241 | 192.168.2.13 | 185.150.24.67 |
Oct 27, 2024 08:58:06.928656101 CET | 38241 | 33440 | 185.150.24.67 | 192.168.2.13 |
Oct 27, 2024 08:58:07.504314899 CET | 38241 | 33440 | 185.150.24.67 | 192.168.2.13 |
Oct 27, 2024 08:58:07.504689932 CET | 33440 | 38241 | 192.168.2.13 | 185.150.24.67 |
Oct 27, 2024 08:58:07.510468960 CET | 38241 | 33440 | 185.150.24.67 | 192.168.2.13 |
Oct 27, 2024 08:58:08.523277998 CET | 49400 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:08.528814077 CET | 38241 | 49400 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:08.528871059 CET | 49400 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:08.530217886 CET | 49400 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:08.535504103 CET | 38241 | 49400 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:08.535559893 CET | 49400 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:08.540958881 CET | 38241 | 49400 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:18.540407896 CET | 49400 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:18.545696020 CET | 38241 | 49400 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:18.908116102 CET | 38241 | 49400 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:18.908360958 CET | 49400 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:18.913805962 CET | 38241 | 49400 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:19.940155983 CET | 49402 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:19.945480108 CET | 38241 | 49402 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:19.945599079 CET | 49402 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:19.946753025 CET | 49402 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:19.951170921 CET | 38241 | 49402 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:19.951288939 CET | 49402 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:19.952076912 CET | 38241 | 49402 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:19.956867933 CET | 38241 | 49402 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:20.966356039 CET | 49404 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:20.972070932 CET | 38241 | 49404 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:20.972330093 CET | 49404 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:20.973454952 CET | 49404 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:20.978754997 CET | 38241 | 49404 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:20.978816986 CET | 49404 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:20.984126091 CET | 38241 | 49404 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:31.791130066 CET | 38241 | 49404 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:31.791388035 CET | 49404 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:31.796966076 CET | 38241 | 49404 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:32.828563929 CET | 33448 | 38241 | 192.168.2.13 | 185.150.24.67 |
Oct 27, 2024 08:58:32.835189104 CET | 38241 | 33448 | 185.150.24.67 | 192.168.2.13 |
Oct 27, 2024 08:58:32.835275888 CET | 33448 | 38241 | 192.168.2.13 | 185.150.24.67 |
Oct 27, 2024 08:58:32.836328983 CET | 33448 | 38241 | 192.168.2.13 | 185.150.24.67 |
Oct 27, 2024 08:58:32.842963934 CET | 38241 | 33448 | 185.150.24.67 | 192.168.2.13 |
Oct 27, 2024 08:58:32.843024015 CET | 33448 | 38241 | 192.168.2.13 | 185.150.24.67 |
Oct 27, 2024 08:58:32.848917961 CET | 38241 | 33448 | 185.150.24.67 | 192.168.2.13 |
Oct 27, 2024 08:58:33.432430029 CET | 38241 | 33448 | 185.150.24.67 | 192.168.2.13 |
Oct 27, 2024 08:58:33.432663918 CET | 33448 | 38241 | 192.168.2.13 | 185.150.24.67 |
Oct 27, 2024 08:58:33.437984943 CET | 38241 | 33448 | 185.150.24.67 | 192.168.2.13 |
Oct 27, 2024 08:58:34.464654922 CET | 33450 | 38241 | 192.168.2.13 | 185.150.24.67 |
Oct 27, 2024 08:58:34.469948053 CET | 38241 | 33450 | 185.150.24.67 | 192.168.2.13 |
Oct 27, 2024 08:58:34.469990015 CET | 33450 | 38241 | 192.168.2.13 | 185.150.24.67 |
Oct 27, 2024 08:58:34.470756054 CET | 33450 | 38241 | 192.168.2.13 | 185.150.24.67 |
Oct 27, 2024 08:58:34.476011038 CET | 38241 | 33450 | 185.150.24.67 | 192.168.2.13 |
Oct 27, 2024 08:58:34.476066113 CET | 33450 | 38241 | 192.168.2.13 | 185.150.24.67 |
Oct 27, 2024 08:58:34.481430054 CET | 38241 | 33450 | 185.150.24.67 | 192.168.2.13 |
Oct 27, 2024 08:58:35.058887959 CET | 38241 | 33450 | 185.150.24.67 | 192.168.2.13 |
Oct 27, 2024 08:58:35.059062958 CET | 33450 | 38241 | 192.168.2.13 | 185.150.24.67 |
Oct 27, 2024 08:58:35.064425945 CET | 38241 | 33450 | 185.150.24.67 | 192.168.2.13 |
Oct 27, 2024 08:58:36.073278904 CET | 49410 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:36.079051971 CET | 38241 | 49410 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:36.079124928 CET | 49410 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:36.080343008 CET | 49410 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:36.084661961 CET | 38241 | 49410 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:36.084726095 CET | 49410 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:36.085566998 CET | 38241 | 49410 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:36.092138052 CET | 38241 | 49410 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:37.099772930 CET | 49412 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:37.105921030 CET | 38241 | 49412 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:37.105993986 CET | 49412 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:37.106914997 CET | 49412 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:37.112454891 CET | 38241 | 49412 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:37.112560987 CET | 49412 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:37.112724066 CET | 38241 | 49412 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:37.119359016 CET | 38241 | 49412 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:38.149538040 CET | 49414 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:38.154901981 CET | 38241 | 49414 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:38.154972076 CET | 49414 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:38.156421900 CET | 49414 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:38.161798000 CET | 38241 | 49414 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:38.161856890 CET | 49414 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:38.167203903 CET | 38241 | 49414 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:48.988919020 CET | 38241 | 49414 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:48.989198923 CET | 49414 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:48.994652033 CET | 38241 | 49414 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:50.003118038 CET | 49416 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:50.008450031 CET | 38241 | 49416 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:50.008584976 CET | 49416 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:50.009548903 CET | 49416 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:50.014970064 CET | 38241 | 49416 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:58:50.015111923 CET | 49416 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:58:50.020457029 CET | 38241 | 49416 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:59:00.846548080 CET | 38241 | 49416 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:59:00.846698046 CET | 49416 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:59:00.853811979 CET | 38241 | 49416 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:59:01.879578114 CET | 49418 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:59:01.884915113 CET | 38241 | 49418 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:59:01.885001898 CET | 49418 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:59:01.886126041 CET | 49418 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:59:01.891594887 CET | 38241 | 49418 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:59:01.891663074 CET | 49418 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:59:01.897073030 CET | 38241 | 49418 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:59:12.713751078 CET | 38241 | 49418 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:59:12.714024067 CET | 49418 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:59:12.719320059 CET | 38241 | 49418 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:59:13.734813929 CET | 49420 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:59:13.740230083 CET | 38241 | 49420 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:59:13.740300894 CET | 49420 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:59:13.741133928 CET | 49420 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:59:13.746817112 CET | 38241 | 49420 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:59:13.746922016 CET | 49420 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:59:13.752222061 CET | 38241 | 49420 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:59:24.648431063 CET | 38241 | 49420 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:59:24.648576021 CET | 49420 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:59:24.654088020 CET | 38241 | 49420 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:59:25.663589954 CET | 49422 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:59:25.668962955 CET | 38241 | 49422 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:59:25.669054031 CET | 49422 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:59:25.670047998 CET | 49422 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:59:25.675384998 CET | 38241 | 49422 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:59:25.675442934 CET | 49422 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:59:25.680809975 CET | 38241 | 49422 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:59:35.680258036 CET | 49422 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:59:35.685676098 CET | 38241 | 49422 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:59:36.048253059 CET | 38241 | 49422 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:59:36.048736095 CET | 49422 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:59:36.054058075 CET | 38241 | 49422 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:59:37.070190907 CET | 49424 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:59:37.075700998 CET | 38241 | 49424 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:59:37.075794935 CET | 49424 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:59:37.077317953 CET | 49424 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:59:37.082617998 CET | 38241 | 49424 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:59:37.082686901 CET | 49424 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:59:37.088217974 CET | 38241 | 49424 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:59:47.890459061 CET | 38241 | 49424 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:59:47.890786886 CET | 49424 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:59:47.896379948 CET | 38241 | 49424 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:59:48.908127069 CET | 49426 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:59:48.913664103 CET | 38241 | 49426 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:59:48.913789034 CET | 49426 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:59:48.915234089 CET | 49426 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:59:48.920620918 CET | 38241 | 49426 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:59:48.920829058 CET | 49426 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:59:48.926218033 CET | 38241 | 49426 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:59:59.747068882 CET | 38241 | 49426 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 08:59:59.747354031 CET | 49426 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 08:59:59.752747059 CET | 38241 | 49426 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 09:00:00.767774105 CET | 49428 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 09:00:00.773186922 CET | 38241 | 49428 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 09:00:00.773297071 CET | 49428 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 09:00:00.774115086 CET | 49428 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 09:00:00.779386997 CET | 38241 | 49428 | 45.156.86.24 | 192.168.2.13 |
Oct 27, 2024 09:00:00.779434919 CET | 49428 | 38241 | 192.168.2.13 | 45.156.86.24 |
Oct 27, 2024 09:00:00.784787893 CET | 38241 | 49428 | 45.156.86.24 | 192.168.2.13 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 27, 2024 08:58:03.465802908 CET | 34518 | 53 | 192.168.2.13 | 51.158.108.203 |
Oct 27, 2024 08:58:03.482372999 CET | 53 | 34518 | 51.158.108.203 | 192.168.2.13 |
Oct 27, 2024 08:58:05.278806925 CET | 59676 | 53 | 192.168.2.13 | 202.61.197.122 |
Oct 27, 2024 08:58:05.289331913 CET | 53 | 59676 | 202.61.197.122 | 192.168.2.13 |
Oct 27, 2024 08:58:06.898382902 CET | 51081 | 53 | 192.168.2.13 | 152.53.15.127 |
Oct 27, 2024 08:58:06.909492016 CET | 53 | 51081 | 152.53.15.127 | 192.168.2.13 |
Oct 27, 2024 08:58:08.506511927 CET | 44010 | 53 | 192.168.2.13 | 51.158.108.203 |
Oct 27, 2024 08:58:08.522433043 CET | 53 | 44010 | 51.158.108.203 | 192.168.2.13 |
Oct 27, 2024 08:58:19.911047935 CET | 60402 | 53 | 192.168.2.13 | 81.169.136.222 |
Oct 27, 2024 08:58:19.939189911 CET | 53 | 60402 | 81.169.136.222 | 192.168.2.13 |
Oct 27, 2024 08:58:20.954787970 CET | 45463 | 53 | 192.168.2.13 | 194.36.144.87 |
Oct 27, 2024 08:58:20.965321064 CET | 53 | 45463 | 194.36.144.87 | 192.168.2.13 |
Oct 27, 2024 08:58:32.794020891 CET | 49456 | 53 | 192.168.2.13 | 185.181.61.24 |
Oct 27, 2024 08:58:32.827630043 CET | 53 | 49456 | 185.181.61.24 | 192.168.2.13 |
Oct 27, 2024 08:58:34.435870886 CET | 43879 | 53 | 192.168.2.13 | 81.169.136.222 |
Oct 27, 2024 08:58:34.464160919 CET | 53 | 43879 | 81.169.136.222 | 192.168.2.13 |
Oct 27, 2024 08:58:36.061888933 CET | 38702 | 53 | 192.168.2.13 | 194.36.144.87 |
Oct 27, 2024 08:58:36.072698116 CET | 53 | 38702 | 194.36.144.87 | 192.168.2.13 |
Oct 27, 2024 08:58:37.087366104 CET | 39837 | 53 | 192.168.2.13 | 152.53.15.127 |
Oct 27, 2024 08:58:37.099116087 CET | 53 | 39837 | 152.53.15.127 | 192.168.2.13 |
Oct 27, 2024 08:58:38.115178108 CET | 59379 | 53 | 192.168.2.13 | 185.181.61.24 |
Oct 27, 2024 08:58:38.148529053 CET | 53 | 59379 | 185.181.61.24 | 192.168.2.13 |
Oct 27, 2024 08:58:49.991590023 CET | 39409 | 53 | 192.168.2.13 | 202.61.197.122 |
Oct 27, 2024 08:58:50.002639055 CET | 53 | 39409 | 202.61.197.122 | 192.168.2.13 |
Oct 27, 2024 08:59:01.849875927 CET | 59081 | 53 | 192.168.2.13 | 81.169.136.222 |
Oct 27, 2024 08:59:01.878751993 CET | 53 | 59081 | 81.169.136.222 | 192.168.2.13 |
Oct 27, 2024 08:59:13.717858076 CET | 51063 | 53 | 192.168.2.13 | 51.158.108.203 |
Oct 27, 2024 08:59:13.734034061 CET | 53 | 51063 | 51.158.108.203 | 192.168.2.13 |
Oct 27, 2024 08:59:25.652400970 CET | 40611 | 53 | 192.168.2.13 | 202.61.197.122 |
Oct 27, 2024 08:59:25.663000107 CET | 53 | 40611 | 202.61.197.122 | 192.168.2.13 |
Oct 27, 2024 08:59:37.052851915 CET | 56960 | 53 | 192.168.2.13 | 51.158.108.203 |
Oct 27, 2024 08:59:37.069034100 CET | 53 | 56960 | 51.158.108.203 | 192.168.2.13 |
Oct 27, 2024 08:59:48.896055937 CET | 41743 | 53 | 192.168.2.13 | 202.61.197.122 |
Oct 27, 2024 08:59:48.906852961 CET | 53 | 41743 | 202.61.197.122 | 192.168.2.13 |
Oct 27, 2024 09:00:00.750327110 CET | 56213 | 53 | 192.168.2.13 | 51.158.108.203 |
Oct 27, 2024 09:00:00.767127991 CET | 53 | 56213 | 51.158.108.203 | 192.168.2.13 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 27, 2024 08:58:03.465802908 CET | 192.168.2.13 | 51.158.108.203 | 0xa175 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 27, 2024 08:58:05.278806925 CET | 192.168.2.13 | 202.61.197.122 | 0x76d0 | Standard query (0) | 256 | 397 | false | |
Oct 27, 2024 08:58:06.898382902 CET | 192.168.2.13 | 152.53.15.127 | 0x2f6f | Standard query (0) | 256 | 398 | false | |
Oct 27, 2024 08:58:08.506511927 CET | 192.168.2.13 | 51.158.108.203 | 0xee81 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 27, 2024 08:58:19.911047935 CET | 192.168.2.13 | 81.169.136.222 | 0x32a0 | Standard query (0) | 256 | 411 | false | |
Oct 27, 2024 08:58:20.954787970 CET | 192.168.2.13 | 194.36.144.87 | 0xd221 | Standard query (0) | 256 | 412 | false | |
Oct 27, 2024 08:58:32.794020891 CET | 192.168.2.13 | 185.181.61.24 | 0xe8e0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 27, 2024 08:58:34.435870886 CET | 192.168.2.13 | 81.169.136.222 | 0xc402 | Standard query (0) | 256 | 426 | false | |
Oct 27, 2024 08:58:36.061888933 CET | 192.168.2.13 | 194.36.144.87 | 0x8286 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 27, 2024 08:58:37.087366104 CET | 192.168.2.13 | 152.53.15.127 | 0xd359 | Standard query (0) | 256 | 429 | false | |
Oct 27, 2024 08:58:38.115178108 CET | 192.168.2.13 | 185.181.61.24 | 0x4045 | Standard query (0) | 256 | 430 | false | |
Oct 27, 2024 08:58:49.991590023 CET | 192.168.2.13 | 202.61.197.122 | 0x91e0 | Standard query (0) | 256 | 442 | false | |
Oct 27, 2024 08:59:01.849875927 CET | 192.168.2.13 | 81.169.136.222 | 0xbb0d | Standard query (0) | 256 | 453 | false | |
Oct 27, 2024 08:59:13.717858076 CET | 192.168.2.13 | 51.158.108.203 | 0xf354 | Standard query (0) | 256 | 465 | false | |
Oct 27, 2024 08:59:25.652400970 CET | 192.168.2.13 | 202.61.197.122 | 0x802a | Standard query (0) | 256 | 477 | false | |
Oct 27, 2024 08:59:37.052851915 CET | 192.168.2.13 | 51.158.108.203 | 0x217e | Standard query (0) | 256 | 489 | false | |
Oct 27, 2024 08:59:48.896055937 CET | 192.168.2.13 | 202.61.197.122 | 0xb8ec | Standard query (0) | 256 | 500 | false | |
Oct 27, 2024 09:00:00.750327110 CET | 192.168.2.13 | 51.158.108.203 | 0x95ee | Standard query (0) | 256 | 256 | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 27, 2024 08:58:03.482372999 CET | 51.158.108.203 | 192.168.2.13 | 0xa175 | No error (0) | 185.150.24.67 | A (IP address) | IN (0x0001) | false | ||
Oct 27, 2024 08:58:06.909492016 CET | 152.53.15.127 | 192.168.2.13 | 0x2f6f | Format error (1) | none | none | 256 | 398 | false | |
Oct 27, 2024 08:58:08.522433043 CET | 51.158.108.203 | 192.168.2.13 | 0xee81 | No error (0) | 45.156.86.24 | A (IP address) | IN (0x0001) | false | ||
Oct 27, 2024 08:58:20.965321064 CET | 194.36.144.87 | 192.168.2.13 | 0xd221 | Format error (1) | none | none | 256 | 412 | false | |
Oct 27, 2024 08:58:32.827630043 CET | 185.181.61.24 | 192.168.2.13 | 0xe8e0 | No error (0) | 185.150.24.67 | A (IP address) | IN (0x0001) | false | ||
Oct 27, 2024 08:58:36.072698116 CET | 194.36.144.87 | 192.168.2.13 | 0x8286 | No error (0) | 45.156.86.24 | A (IP address) | IN (0x0001) | false | ||
Oct 27, 2024 08:58:37.099116087 CET | 152.53.15.127 | 192.168.2.13 | 0xd359 | Format error (1) | none | none | 256 | 429 | false | |
Oct 27, 2024 08:59:13.734034061 CET | 51.158.108.203 | 192.168.2.13 | 0xf354 | Format error (1) | none | none | 256 | 465 | false | |
Oct 27, 2024 08:59:37.069034100 CET | 51.158.108.203 | 192.168.2.13 | 0x217e | Format error (1) | none | none | 256 | 489 | false | |
Oct 27, 2024 09:00:00.767127991 CET | 51.158.108.203 | 192.168.2.13 | 0x95ee | Format error (1) | none | none | 256 | 256 | false |
System Behavior
Start time (UTC): | 07:58:02 |
Start date (UTC): | 27/10/2024 |
Path: | /tmp/zerppc.elf |
Arguments: | /tmp/zerppc.elf |
File size: | 5388968 bytes |
MD5 hash: | ae65271c943d3451b7f026d1fadccea6 |
Start time (UTC): | 07:58:02 |
Start date (UTC): | 27/10/2024 |
Path: | /tmp/zerppc.elf |
Arguments: | - |
File size: | 5388968 bytes |
MD5 hash: | ae65271c943d3451b7f026d1fadccea6 |
Start time (UTC): | 07:58:02 |
Start date (UTC): | 27/10/2024 |
Path: | /tmp/zerppc.elf |
Arguments: | - |
File size: | 5388968 bytes |
MD5 hash: | ae65271c943d3451b7f026d1fadccea6 |