Edit tour
Linux
Analysis Report
amd64.elf
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Multi AV Scanner detection for submitted file
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1543411 |
Start date and time: | 2024-10-27 20:18:03 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 40s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | amd64.elf |
Detection: | MAL |
Classification: | mal48.linELF@0/0@0/0 |
- Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: amd64.elf
Command: | /tmp/amd64.elf |
PID: | 6264 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | |
Standard Error: | 2024/10/27 14:19:14 Forking 2024/10/27 14:19:14 Connecting to 156.234.42.40:80 2024/10/27 14:19:17 Successfully connnected 156.234.42.40:80 |
⊘No yara matches
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | ReversingLabs: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | .symtab present: |
Source: | Classification label: |
Source: | Submission: |
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior |
Source: | Stderr: 2024/10/27 14:19:14 Forking2024/10/27 14:19:14 Connecting to 156.234.42.40:802024/10/27 14:19:17 Successfully connnected 156.234.42.40:80: |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | 1 File Deletion | OS Credential Dumping | 1 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
⊘No configs have been found
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
16% | ReversingLabs | Linux.Hacktool.RevhellMarte |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
⊘No contacted domains info
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
34.249.145.219 | unknown | United States | 16509 | AMAZON-02US | false | |
156.234.42.40 | unknown | Seychelles | 136800 | XIAOZHIYUN1-AS-APICIDCNETWORKUS | false | |
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
34.249.145.219 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
109.202.202.202 | Get hash | malicious | Unknown | Browse |
| |
91.189.91.42 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Chaos | Browse | |||
Get hash | malicious | Chaos | Browse | |||
Get hash | malicious | Chaos | Browse | |||
Get hash | malicious | Unknown | Browse |
⊘No context
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CANONICAL-ASGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Chaos | Browse |
| ||
Get hash | malicious | Chaos | Browse |
| ||
Get hash | malicious | Chaos | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
INIT7CH | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Chaos | Browse |
| ||
Get hash | malicious | Chaos | Browse |
| ||
Get hash | malicious | Chaos | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
XIAOZHIYUN1-AS-APICIDCNETWORKUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
AMAZON-02US | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Python Stealer, Exela Stealer | Browse |
| ||
Get hash | malicious | Stealc, Vidar | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 6.149775708920118 |
TrID: |
|
File name: | amd64.elf |
File size: | 8'876'184 bytes |
MD5: | 460bfe2f3c4ec8d67282cded7ce12215 |
SHA1: | 206da96eeae36e8133c9f459a21244693cf58b73 |
SHA256: | 6ee4ae55ebc3cc41ecc3a0f713ef44cd680320bb8ef9916cefc9f88b61ea7724 |
SHA512: | d89f32d4a2929d0000b8729f430abe4a4f131c934c16757b242a7a2ebdd5c178443f9d4616a2c3bcfd48679601404ab62ca7d5531e7fd9c4d661dbf099050380 |
SSDEEP: | 98304:2b6jIMC9bXHFx8SeFu8Y4ASgS5rEkCG78/mCW+:2L956SeQ4Ar9ki |
TLSH: | 3E963947ECA104E4C0ADD63085629262BFB27C895B3477D72B90B72C3FB6BD0AA75750 |
File Content Preview: | .ELF..............>.....@.F.....@...................@.8...@.............@.......@.@.....@.@.....P.......P.................................@.......@.....d.......d.................................@.......@......1<......1<......................@<......@|.... |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 64 |
Program Header Offset: | 64 |
Program Header Size: | 56 |
Number of Program Headers: | 6 |
Section Header Offset: | 400 |
Section Header Size: | 64 |
Number of Section Headers: | 14 |
Header String Table Index: | 13 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.text | PROGBITS | 0x401000 | 0x1000 | 0x3c2195 | 0x0 | 0x6 | AX | 0 | 0 | 32 |
.rodata | PROGBITS | 0x7c4000 | 0x3c4000 | 0x1dfa8e | 0x0 | 0x2 | A | 0 | 0 | 32 |
.typelink | PROGBITS | 0x9a3aa0 | 0x5a3aa0 | 0x3114 | 0x0 | 0x2 | A | 0 | 0 | 32 |
.itablink | PROGBITS | 0x9a6bc0 | 0x5a6bc0 | 0x1ef8 | 0x0 | 0x2 | A | 0 | 0 | 32 |
.gosymtab | PROGBITS | 0x9a8ab8 | 0x5a8ab8 | 0x0 | 0x0 | 0x2 | A | 0 | 0 | 1 |
.gopclntab | PROGBITS | 0x9a8ac0 | 0x5a8ac0 | 0x28c018 | 0x0 | 0x2 | A | 0 | 0 | 32 |
.go.buildinfo | PROGBITS | 0xc35000 | 0x835000 | 0x580 | 0x0 | 0x3 | WA | 0 | 0 | 16 |
.noptrdata | PROGBITS | 0xc35580 | 0x835580 | 0x30a42 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.data | PROGBITS | 0xc65fe0 | 0x865fe0 | 0x10bb0 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.bss | NOBITS | 0xc76ba0 | 0x876ba0 | 0x62750 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.noptrbss | NOBITS | 0xcd9300 | 0x8d9300 | 0xe470 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.note.go.buildid | NOTE | 0x400f9c | 0xf9c | 0x64 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.shstrtab | STRTAB | 0x0 | 0x877000 | 0x98 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
PHDR | 0x40 | 0x400040 | 0x400040 | 0x150 | 0x150 | 1.6922 | 0x4 | R | 0x1000 | ||
NOTE | 0xf9c | 0x400f9c | 0x400f9c | 0x64 | 0x64 | 5.2982 | 0x4 | R | 0x4 | .note.go.buildid | |
LOAD | 0x0 | 0x400000 | 0x400000 | 0x3c3195 | 0x3c3195 | 6.1355 | 0x5 | R E | 0x1000 | .text .note.go.buildid | |
LOAD | 0x3c4000 | 0x7c4000 | 0x7c4000 | 0x470ad8 | 0x470ad8 | 5.6090 | 0x4 | R | 0x1000 | .rodata .typelink .itablink .gosymtab .gopclntab | |
LOAD | 0x835000 | 0xc35000 | 0xc35000 | 0x41ba0 | 0xb2770 | 5.1365 | 0x6 | RW | 0x1000 | .go.buildinfo .noptrdata .data .bss .noptrbss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x8 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 27, 2024 20:19:15.979701996 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:19:15.985588074 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:15.985663891 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:19:15.986895084 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:19:15.992415905 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:16.570689917 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Oct 27, 2024 20:19:16.947041988 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:16.947298050 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:19:16.947329998 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:16.947401047 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:19:17.005073071 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:19:17.009911060 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:19:17.010440111 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:17.015388966 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:17.314460039 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:17.314632893 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:19:17.319303989 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:19:17.323739052 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:19:17.324985027 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:17.329458952 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:17.627741098 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:17.628057957 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:19:17.631789923 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:19:17.637244940 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:17.935740948 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:17.935950041 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:19:17.939918041 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:19:17.945765972 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:18.244457006 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:18.248362064 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:19:18.253936052 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:18.552531004 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:18.552735090 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:18.553949118 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:19:18.558787107 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:19:18.564136028 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:18.933782101 CET | 443 | 39256 | 34.249.145.219 | 192.168.2.23 |
Oct 27, 2024 20:19:18.934103966 CET | 39256 | 443 | 192.168.2.23 | 34.249.145.219 |
Oct 27, 2024 20:19:18.940601110 CET | 443 | 39256 | 34.249.145.219 | 192.168.2.23 |
Oct 27, 2024 20:19:23.863218069 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:23.866970062 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:19:23.872391939 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:29.170975924 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:29.176151037 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:19:29.181624889 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:34.480731964 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:34.489434004 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:19:34.495136023 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:35.768062115 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Oct 27, 2024 20:19:37.815826893 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Oct 27, 2024 20:19:39.795120955 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:39.801372051 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:19:39.807457924 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:45.111067057 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:45.115282059 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:19:45.120654106 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:50.419955969 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:50.425484896 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:19:50.432473898 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:55.732363939 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:19:55.738223076 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:19:55.743808985 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:20:01.044022083 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:20:01.051336050 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:20:01.056803942 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:20:06.355689049 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:20:06.362624884 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:20:06.375228882 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:20:11.673441887 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:20:11.681526899 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:20:11.692600965 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:20:16.992574930 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:20:17.000276089 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:20:17.012921095 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:20:18.770003080 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Oct 27, 2024 20:20:22.312519073 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:20:22.320111990 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:20:22.328388929 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:20:27.627552032 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:20:27.633295059 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:20:27.642999887 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:20:32.941436052 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:20:32.947277069 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:20:32.961118937 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:20:38.261164904 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:20:38.266890049 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:20:38.280046940 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:20:43.586815119 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:20:43.592984915 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:20:43.605634928 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:20:48.906358957 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:20:48.910468102 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:20:48.922522068 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:20:54.221957922 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:20:54.230865955 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:20:54.241355896 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:20:59.540066957 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:20:59.548432112 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:20:59.562292099 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:21:04.862875938 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:21:04.868472099 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:21:04.877113104 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:21:10.180104017 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:21:10.185981035 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:21:10.193984985 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:21:15.492564917 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:21:15.496541023 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:21:15.505809069 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:21:20.806989908 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:21:20.814822912 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:21:20.824500084 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:21:26.123961926 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:21:26.132249117 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:21:26.137777090 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:21:31.436824083 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:21:31.442310095 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:21:31.447700977 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:21:36.746355057 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:21:36.752669096 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:21:36.758184910 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:21:42.056375980 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:21:42.064810991 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:21:42.070233107 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:21:47.369466066 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:21:47.377810001 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:21:47.384403944 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:21:52.688469887 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:21:52.692603111 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:21:52.700001001 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:21:57.999087095 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:21:58.007428885 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:21:58.013149023 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:22:03.312458992 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:22:03.316643000 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:22:03.322031975 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:22:08.849164009 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:22:08.850135088 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:22:08.850172997 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:22:08.853240967 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:22:08.858731985 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:22:14.157617092 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:22:14.157855034 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:22:14.163192034 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:22:14.168476105 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:22:19.467905998 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:22:19.468214989 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:22:19.474610090 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:22:19.480129957 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:22:24.779839993 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:22:24.789163113 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:22:24.794692039 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:22:30.179282904 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:22:30.188332081 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:22:30.193707943 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:22:35.493220091 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:22:35.500065088 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:22:35.505774021 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:22:40.805279970 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:22:40.814157963 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:22:40.821182966 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:22:46.120927095 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:22:46.128353119 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:22:46.133924007 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:22:51.433274031 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Oct 27, 2024 20:22:51.442158937 CET | 47284 | 80 | 192.168.2.23 | 156.234.42.40 |
Oct 27, 2024 20:22:51.447596073 CET | 80 | 47284 | 156.234.42.40 | 192.168.2.23 |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.23 | 47284 | 156.234.42.40 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 27, 2024 20:19:15.986895084 CET | 47 | OUT | |
Oct 27, 2024 20:19:16.947041988 CET | 33 | IN | |
Oct 27, 2024 20:19:16.947329998 CET | 732 | IN | |
Oct 27, 2024 20:19:17.005073071 CET | 1132 | OUT | |
Oct 27, 2024 20:19:17.009911060 CET | 60 | OUT | |
Oct 27, 2024 20:19:17.314460039 CET | 480 | IN | |
Oct 27, 2024 20:19:17.319303989 CET | 28 | OUT | |
Oct 27, 2024 20:19:17.323739052 CET | 64 | OUT | |
Oct 27, 2024 20:19:17.627741098 CET | 64 | IN | |
Oct 27, 2024 20:19:17.631789923 CET | 96 | OUT |
System Behavior
Start time (UTC): | 19:19:14 |
Start date (UTC): | 27/10/2024 |
Path: | /tmp/amd64.elf |
Arguments: | /tmp/amd64.elf |
File size: | 8876184 bytes |
MD5 hash: | 460bfe2f3c4ec8d67282cded7ce12215 |
Start time (UTC): | 19:19:14 |
Start date (UTC): | 27/10/2024 |
Path: | /tmp/amd64.elf |
Arguments: | - |
File size: | 8876184 bytes |
MD5 hash: | 460bfe2f3c4ec8d67282cded7ce12215 |
Start time (UTC): | 19:19:14 |
Start date (UTC): | 27/10/2024 |
Path: | /proc/self/exe |
Arguments: | /proc/self/exe |
File size: | 8876184 bytes |
MD5 hash: | 460bfe2f3c4ec8d67282cded7ce12215 |
Start time (UTC): | 19:19:17 |
Start date (UTC): | 27/10/2024 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 19:19:17 |
Start date (UTC): | 27/10/2024 |
Path: | /usr/bin/rm |
Arguments: | rm -f /tmp/tmp.81eTWBWmI7 /tmp/tmp.o9DTYjt50x /tmp/tmp.si5gMoxVnA |
File size: | 72056 bytes |
MD5 hash: | aa2b5496fdbfd88e38791ab81f90b95b |
Start time (UTC): | 19:19:17 |
Start date (UTC): | 27/10/2024 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 19:19:17 |
Start date (UTC): | 27/10/2024 |
Path: | /usr/bin/rm |
Arguments: | rm -f /tmp/tmp.81eTWBWmI7 /tmp/tmp.o9DTYjt50x /tmp/tmp.si5gMoxVnA |
File size: | 72056 bytes |
MD5 hash: | aa2b5496fdbfd88e38791ab81f90b95b |