Edit tour
Linux
Analysis Report
harm4.elf
Overview
General Information
Sample name: | harm4.elf |
Analysis ID: | 1546612 |
MD5: | b388c33234287df8e67decee3801d046 |
SHA1: | 9807602b862a086c0a3ad3042faf88203a322d4d |
SHA256: | 8f925cc077f79f07ad70dbfc9478a1f72a3134f711edebac505914d76dd5af6e |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Mirai
Score: | 80 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Yara detected Mirai
Connects to many ports of the same IP (likely port scanning)
Sample reads /proc/mounts (often used for finding a writable filesystem)
Detected TCP or UDP traffic on non-standard ports
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1546612 |
Start date and time: | 2024-11-01 08:47:09 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 47s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | harm4.elf |
Detection: | MAL |
Classification: | mal80.troj.linELF@0/0@24/0 |
- VT rate limit hit for: harm4.elf
Command: | /tmp/harm4.elf |
PID: | 5490 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | you are now apart of hail cock botnet |
Standard Error: |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Mirai | Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Mirai_6 | Yara detected Mirai | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Mirai_6 | Yara detected Mirai | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
JoeSecurity_Mirai_6 | Yara detected Mirai | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
JoeSecurity_Mirai_6 | Yara detected Mirai | Joe Security | ||
Click to see the 4 entries |
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Networking |
---|
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: |
Source: | .symtab present: |
Source: | Classification label: |
Persistence and Installation Behavior |
---|
Source: | File: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | Direct Volume Access | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Non-Standard Port | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | 1 File and Directory Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
53% | ReversingLabs | Linux.Trojan.Mirai | ||
100% | Avira | EXP/ELF.Mirai.W |
⊘No Antivirus matches
⊘No Antivirus matches
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
daisy.ubuntu.com | 162.213.35.25 | true | false | unknown | |
kingstonwikkerink.dyn | 213.182.204.57 | true | false | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | unknown | |||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
217.28.130.41 | unknown | United Kingdom | 15839 | COBWEB-NETGB | false | |
213.182.204.57 | kingstonwikkerink.dyn | Latvia | 9009 | M247GB | false | |
91.149.218.232 | unknown | Poland | 198401 | GECKONET-ASPL | false | |
31.13.248.89 | unknown | Bulgaria | 34224 | NETERRA-ASBG | true | |
91.149.238.18 | unknown | Poland | 41952 | MARTON-ASPL | true | |
81.29.149.178 | unknown | Switzerland | 39616 | COMUNICA_IT_SERVICESCH | true |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
217.28.130.41 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
213.182.204.57 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
91.149.218.232 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
91.149.238.18 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
31.13.248.89 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
daisy.ubuntu.com | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
kingstonwikkerink.dyn | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
M247GB | Get hash | malicious | AsyncRAT | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AsyncRAT, DcRat | Browse |
| ||
Get hash | malicious | Remcos, GuLoader | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
GECKONET-ASPL | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
COBWEB-NETGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 6.163249847045424 |
TrID: |
|
File name: | harm4.elf |
File size: | 94'288 bytes |
MD5: | b388c33234287df8e67decee3801d046 |
SHA1: | 9807602b862a086c0a3ad3042faf88203a322d4d |
SHA256: | 8f925cc077f79f07ad70dbfc9478a1f72a3134f711edebac505914d76dd5af6e |
SHA512: | 278c877eeda0048f9f52c028e3c7056c981ed4bc4d62d243b0c0e23c7e662673afb95c8a8fedbacf9ca11635e34d481800cd1fbb3de48fca90c32bce5f9e88ab |
SSDEEP: | 1536:ufEqrGbtC4ftpNLg5/qXFNsRam63t5dtc2/NupbdltX8/Y6NFvv4GM:cEqz4fS5hrAt5d7FupbYbzM |
TLSH: | 2C934B95BC819A12C6D121BBFB6E428D371653E8D2EF3203DE256F20778B86B0E77541 |
File Content Preview: | .ELF...a..........(.........4....n......4. ...(.....................Xj..Xj..............Xj..Xj..Xj.......U..........Q.td..................................-...L."....R..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 93848 |
Section Header Size: | 40 |
Number of Section Headers: | 11 |
Header String Table Index: | 10 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x8094 | 0x94 | 0x18 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x80b0 | 0xb0 | 0x14a70 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x1cb20 | 0x14b20 | 0x14 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x1cb34 | 0x14b34 | 0x1f20 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.eh_frame | PROGBITS | 0x1ea54 | 0x16a54 | 0x4 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ctors | PROGBITS | 0x26a58 | 0x16a58 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x26a60 | 0x16a60 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x26a6c | 0x16a6c | 0x3e4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x26e50 | 0x16e50 | 0x51ac | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.shstrtab | STRTAB | 0x0 | 0x16e50 | 0x48 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8000 | 0x8000 | 0x16a58 | 0x16a58 | 6.1861 | 0x5 | R E | 0x8000 | .init .text .fini .rodata .eh_frame | |
LOAD | 0x16a58 | 0x26a58 | 0x26a58 | 0x3f8 | 0x55a4 | 3.4310 | 0x6 | RW | 0x8000 | .ctors .dtors .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 1, 2024 08:48:03.529385090 CET | 38570 | 10743 | 192.168.2.14 | 91.149.238.18 |
Nov 1, 2024 08:48:03.534315109 CET | 10743 | 38570 | 91.149.238.18 | 192.168.2.14 |
Nov 1, 2024 08:48:03.534451962 CET | 38570 | 10743 | 192.168.2.14 | 91.149.238.18 |
Nov 1, 2024 08:48:03.534548998 CET | 38570 | 10743 | 192.168.2.14 | 91.149.238.18 |
Nov 1, 2024 08:48:03.539361000 CET | 10743 | 38570 | 91.149.238.18 | 192.168.2.14 |
Nov 1, 2024 08:48:03.539408922 CET | 38570 | 10743 | 192.168.2.14 | 91.149.238.18 |
Nov 1, 2024 08:48:03.544282913 CET | 10743 | 38570 | 91.149.238.18 | 192.168.2.14 |
Nov 1, 2024 08:48:04.473639011 CET | 10743 | 38570 | 91.149.238.18 | 192.168.2.14 |
Nov 1, 2024 08:48:04.473697901 CET | 38570 | 10743 | 192.168.2.14 | 91.149.238.18 |
Nov 1, 2024 08:48:04.473798037 CET | 10743 | 38570 | 91.149.238.18 | 192.168.2.14 |
Nov 1, 2024 08:48:04.473978996 CET | 38570 | 10743 | 192.168.2.14 | 91.149.238.18 |
Nov 1, 2024 08:48:04.474060059 CET | 10743 | 38570 | 91.149.238.18 | 192.168.2.14 |
Nov 1, 2024 08:48:04.474109888 CET | 10743 | 38570 | 91.149.238.18 | 192.168.2.14 |
Nov 1, 2024 08:48:04.474409103 CET | 38570 | 10743 | 192.168.2.14 | 91.149.238.18 |
Nov 1, 2024 08:48:04.474410057 CET | 38570 | 10743 | 192.168.2.14 | 91.149.238.18 |
Nov 1, 2024 08:48:04.474410057 CET | 38570 | 10743 | 192.168.2.14 | 91.149.238.18 |
Nov 1, 2024 08:48:14.531096935 CET | 60122 | 18255 | 192.168.2.14 | 81.29.149.178 |
Nov 1, 2024 08:48:14.537000895 CET | 18255 | 60122 | 81.29.149.178 | 192.168.2.14 |
Nov 1, 2024 08:48:14.537066936 CET | 60122 | 18255 | 192.168.2.14 | 81.29.149.178 |
Nov 1, 2024 08:48:14.537082911 CET | 60122 | 18255 | 192.168.2.14 | 81.29.149.178 |
Nov 1, 2024 08:48:14.541970968 CET | 18255 | 60122 | 81.29.149.178 | 192.168.2.14 |
Nov 1, 2024 08:48:14.542026043 CET | 60122 | 18255 | 192.168.2.14 | 81.29.149.178 |
Nov 1, 2024 08:48:14.546937943 CET | 18255 | 60122 | 81.29.149.178 | 192.168.2.14 |
Nov 1, 2024 08:48:16.193109989 CET | 18255 | 60122 | 81.29.149.178 | 192.168.2.14 |
Nov 1, 2024 08:48:16.193155050 CET | 18255 | 60122 | 81.29.149.178 | 192.168.2.14 |
Nov 1, 2024 08:48:16.193190098 CET | 18255 | 60122 | 81.29.149.178 | 192.168.2.14 |
Nov 1, 2024 08:48:16.193219900 CET | 18255 | 60122 | 81.29.149.178 | 192.168.2.14 |
Nov 1, 2024 08:48:16.193401098 CET | 60122 | 18255 | 192.168.2.14 | 81.29.149.178 |
Nov 1, 2024 08:48:16.193439007 CET | 60122 | 18255 | 192.168.2.14 | 81.29.149.178 |
Nov 1, 2024 08:48:16.193444967 CET | 60122 | 18255 | 192.168.2.14 | 81.29.149.178 |
Nov 1, 2024 08:48:16.193470001 CET | 60122 | 18255 | 192.168.2.14 | 81.29.149.178 |
Nov 1, 2024 08:48:16.193574905 CET | 60122 | 18255 | 192.168.2.14 | 81.29.149.178 |
Nov 1, 2024 08:48:26.212430000 CET | 41424 | 22500 | 192.168.2.14 | 217.28.130.41 |
Nov 1, 2024 08:48:26.217247009 CET | 22500 | 41424 | 217.28.130.41 | 192.168.2.14 |
Nov 1, 2024 08:48:26.217300892 CET | 41424 | 22500 | 192.168.2.14 | 217.28.130.41 |
Nov 1, 2024 08:48:26.217317104 CET | 41424 | 22500 | 192.168.2.14 | 217.28.130.41 |
Nov 1, 2024 08:48:26.222048998 CET | 22500 | 41424 | 217.28.130.41 | 192.168.2.14 |
Nov 1, 2024 08:48:26.222141981 CET | 41424 | 22500 | 192.168.2.14 | 217.28.130.41 |
Nov 1, 2024 08:48:26.226938963 CET | 22500 | 41424 | 217.28.130.41 | 192.168.2.14 |
Nov 1, 2024 08:48:26.898886919 CET | 22500 | 41424 | 217.28.130.41 | 192.168.2.14 |
Nov 1, 2024 08:48:26.898912907 CET | 22500 | 41424 | 217.28.130.41 | 192.168.2.14 |
Nov 1, 2024 08:48:26.898926973 CET | 22500 | 41424 | 217.28.130.41 | 192.168.2.14 |
Nov 1, 2024 08:48:26.899167061 CET | 41424 | 22500 | 192.168.2.14 | 217.28.130.41 |
Nov 1, 2024 08:48:26.899167061 CET | 41424 | 22500 | 192.168.2.14 | 217.28.130.41 |
Nov 1, 2024 08:48:26.899167061 CET | 41424 | 22500 | 192.168.2.14 | 217.28.130.41 |
Nov 1, 2024 08:48:26.899224043 CET | 41424 | 22500 | 192.168.2.14 | 217.28.130.41 |
Nov 1, 2024 08:48:31.915124893 CET | 50972 | 7584 | 192.168.2.14 | 81.29.149.178 |
Nov 1, 2024 08:48:31.920248032 CET | 7584 | 50972 | 81.29.149.178 | 192.168.2.14 |
Nov 1, 2024 08:48:31.920315981 CET | 50972 | 7584 | 192.168.2.14 | 81.29.149.178 |
Nov 1, 2024 08:48:31.920372009 CET | 50972 | 7584 | 192.168.2.14 | 81.29.149.178 |
Nov 1, 2024 08:48:31.925168991 CET | 7584 | 50972 | 81.29.149.178 | 192.168.2.14 |
Nov 1, 2024 08:48:31.925247908 CET | 50972 | 7584 | 192.168.2.14 | 81.29.149.178 |
Nov 1, 2024 08:48:31.930043936 CET | 7584 | 50972 | 81.29.149.178 | 192.168.2.14 |
Nov 1, 2024 08:48:32.936131954 CET | 7584 | 50972 | 81.29.149.178 | 192.168.2.14 |
Nov 1, 2024 08:48:32.936152935 CET | 7584 | 50972 | 81.29.149.178 | 192.168.2.14 |
Nov 1, 2024 08:48:32.936250925 CET | 50972 | 7584 | 192.168.2.14 | 81.29.149.178 |
Nov 1, 2024 08:48:32.936250925 CET | 50972 | 7584 | 192.168.2.14 | 81.29.149.178 |
Nov 1, 2024 08:48:32.936285019 CET | 50972 | 7584 | 192.168.2.14 | 81.29.149.178 |
Nov 1, 2024 08:48:48.048932076 CET | 41106 | 10513 | 192.168.2.14 | 91.149.218.232 |
Nov 1, 2024 08:48:48.053774118 CET | 10513 | 41106 | 91.149.218.232 | 192.168.2.14 |
Nov 1, 2024 08:48:48.053828001 CET | 41106 | 10513 | 192.168.2.14 | 91.149.218.232 |
Nov 1, 2024 08:48:48.053873062 CET | 41106 | 10513 | 192.168.2.14 | 91.149.218.232 |
Nov 1, 2024 08:48:48.058828115 CET | 10513 | 41106 | 91.149.218.232 | 192.168.2.14 |
Nov 1, 2024 08:48:48.058870077 CET | 41106 | 10513 | 192.168.2.14 | 91.149.218.232 |
Nov 1, 2024 08:48:48.063767910 CET | 10513 | 41106 | 91.149.218.232 | 192.168.2.14 |
Nov 1, 2024 08:48:49.031445026 CET | 10513 | 41106 | 91.149.218.232 | 192.168.2.14 |
Nov 1, 2024 08:48:49.031508923 CET | 10513 | 41106 | 91.149.218.232 | 192.168.2.14 |
Nov 1, 2024 08:48:49.031683922 CET | 10513 | 41106 | 91.149.218.232 | 192.168.2.14 |
Nov 1, 2024 08:48:49.031805038 CET | 41106 | 10513 | 192.168.2.14 | 91.149.218.232 |
Nov 1, 2024 08:48:49.031805038 CET | 41106 | 10513 | 192.168.2.14 | 91.149.218.232 |
Nov 1, 2024 08:48:49.031805038 CET | 41106 | 10513 | 192.168.2.14 | 91.149.218.232 |
Nov 1, 2024 08:48:49.031805038 CET | 41106 | 10513 | 192.168.2.14 | 91.149.218.232 |
Nov 1, 2024 08:48:54.045610905 CET | 58880 | 12035 | 192.168.2.14 | 81.29.149.178 |
Nov 1, 2024 08:48:54.050432920 CET | 12035 | 58880 | 81.29.149.178 | 192.168.2.14 |
Nov 1, 2024 08:48:54.050523996 CET | 58880 | 12035 | 192.168.2.14 | 81.29.149.178 |
Nov 1, 2024 08:48:54.050523996 CET | 58880 | 12035 | 192.168.2.14 | 81.29.149.178 |
Nov 1, 2024 08:48:54.055440903 CET | 12035 | 58880 | 81.29.149.178 | 192.168.2.14 |
Nov 1, 2024 08:48:54.055506945 CET | 58880 | 12035 | 192.168.2.14 | 81.29.149.178 |
Nov 1, 2024 08:48:54.060316086 CET | 12035 | 58880 | 81.29.149.178 | 192.168.2.14 |
Nov 1, 2024 08:48:55.074847937 CET | 12035 | 58880 | 81.29.149.178 | 192.168.2.14 |
Nov 1, 2024 08:48:55.075118065 CET | 58880 | 12035 | 192.168.2.14 | 81.29.149.178 |
Nov 1, 2024 08:48:55.075118065 CET | 58880 | 12035 | 192.168.2.14 | 81.29.149.178 |
Nov 1, 2024 08:48:55.075139046 CET | 12035 | 58880 | 81.29.149.178 | 192.168.2.14 |
Nov 1, 2024 08:48:55.075207949 CET | 58880 | 12035 | 192.168.2.14 | 81.29.149.178 |
Nov 1, 2024 08:48:55.075406075 CET | 12035 | 58880 | 81.29.149.178 | 192.168.2.14 |
Nov 1, 2024 08:48:55.075465918 CET | 58880 | 12035 | 192.168.2.14 | 81.29.149.178 |
Nov 1, 2024 08:49:05.101026058 CET | 34894 | 5136 | 192.168.2.14 | 31.13.248.89 |
Nov 1, 2024 08:49:05.105943918 CET | 5136 | 34894 | 31.13.248.89 | 192.168.2.14 |
Nov 1, 2024 08:49:05.106030941 CET | 34894 | 5136 | 192.168.2.14 | 31.13.248.89 |
Nov 1, 2024 08:49:05.106095076 CET | 34894 | 5136 | 192.168.2.14 | 31.13.248.89 |
Nov 1, 2024 08:49:05.111083031 CET | 5136 | 34894 | 31.13.248.89 | 192.168.2.14 |
Nov 1, 2024 08:49:05.111145973 CET | 34894 | 5136 | 192.168.2.14 | 31.13.248.89 |
Nov 1, 2024 08:49:05.115997076 CET | 5136 | 34894 | 31.13.248.89 | 192.168.2.14 |
Nov 1, 2024 08:49:06.238045931 CET | 5136 | 34894 | 31.13.248.89 | 192.168.2.14 |
Nov 1, 2024 08:49:06.238415956 CET | 34894 | 5136 | 192.168.2.14 | 31.13.248.89 |
Nov 1, 2024 08:49:06.238521099 CET | 34894 | 5136 | 192.168.2.14 | 31.13.248.89 |
Nov 1, 2024 08:49:11.252090931 CET | 60436 | 7427 | 192.168.2.14 | 31.13.248.89 |
Nov 1, 2024 08:49:11.256985903 CET | 7427 | 60436 | 31.13.248.89 | 192.168.2.14 |
Nov 1, 2024 08:49:11.257076979 CET | 60436 | 7427 | 192.168.2.14 | 31.13.248.89 |
Nov 1, 2024 08:49:11.257105112 CET | 60436 | 7427 | 192.168.2.14 | 31.13.248.89 |
Nov 1, 2024 08:49:11.262049913 CET | 7427 | 60436 | 31.13.248.89 | 192.168.2.14 |
Nov 1, 2024 08:49:11.262145996 CET | 60436 | 7427 | 192.168.2.14 | 31.13.248.89 |
Nov 1, 2024 08:49:11.267011881 CET | 7427 | 60436 | 31.13.248.89 | 192.168.2.14 |
Nov 1, 2024 08:49:12.344821930 CET | 7427 | 60436 | 31.13.248.89 | 192.168.2.14 |
Nov 1, 2024 08:49:12.344965935 CET | 60436 | 7427 | 192.168.2.14 | 31.13.248.89 |
Nov 1, 2024 08:49:12.345046043 CET | 60436 | 7427 | 192.168.2.14 | 31.13.248.89 |
Nov 1, 2024 08:49:37.372873068 CET | 60438 | 7427 | 192.168.2.14 | 31.13.248.89 |
Nov 1, 2024 08:49:37.377846956 CET | 7427 | 60438 | 31.13.248.89 | 192.168.2.14 |
Nov 1, 2024 08:49:37.377928019 CET | 60438 | 7427 | 192.168.2.14 | 31.13.248.89 |
Nov 1, 2024 08:49:37.377948999 CET | 60438 | 7427 | 192.168.2.14 | 31.13.248.89 |
Nov 1, 2024 08:49:37.383047104 CET | 7427 | 60438 | 31.13.248.89 | 192.168.2.14 |
Nov 1, 2024 08:49:37.383100986 CET | 60438 | 7427 | 192.168.2.14 | 31.13.248.89 |
Nov 1, 2024 08:49:37.388037920 CET | 7427 | 60438 | 31.13.248.89 | 192.168.2.14 |
Nov 1, 2024 08:49:38.462037086 CET | 7427 | 60438 | 31.13.248.89 | 192.168.2.14 |
Nov 1, 2024 08:49:38.462111950 CET | 7427 | 60438 | 31.13.248.89 | 192.168.2.14 |
Nov 1, 2024 08:49:38.462116957 CET | 7427 | 60438 | 31.13.248.89 | 192.168.2.14 |
Nov 1, 2024 08:49:38.462326050 CET | 7427 | 60438 | 31.13.248.89 | 192.168.2.14 |
Nov 1, 2024 08:49:38.462347984 CET | 60438 | 7427 | 192.168.2.14 | 31.13.248.89 |
Nov 1, 2024 08:49:38.462347984 CET | 60438 | 7427 | 192.168.2.14 | 31.13.248.89 |
Nov 1, 2024 08:49:38.462414980 CET | 60438 | 7427 | 192.168.2.14 | 31.13.248.89 |
Nov 1, 2024 08:49:38.462414980 CET | 60438 | 7427 | 192.168.2.14 | 31.13.248.89 |
Nov 1, 2024 08:49:38.462414980 CET | 60438 | 7427 | 192.168.2.14 | 31.13.248.89 |
Nov 1, 2024 08:49:48.704472065 CET | 54584 | 10635 | 192.168.2.14 | 217.28.130.41 |
Nov 1, 2024 08:49:48.709321976 CET | 10635 | 54584 | 217.28.130.41 | 192.168.2.14 |
Nov 1, 2024 08:49:48.709402084 CET | 54584 | 10635 | 192.168.2.14 | 217.28.130.41 |
Nov 1, 2024 08:49:48.709439993 CET | 54584 | 10635 | 192.168.2.14 | 217.28.130.41 |
Nov 1, 2024 08:49:48.714240074 CET | 10635 | 54584 | 217.28.130.41 | 192.168.2.14 |
Nov 1, 2024 08:49:48.714287996 CET | 54584 | 10635 | 192.168.2.14 | 217.28.130.41 |
Nov 1, 2024 08:49:48.719269037 CET | 10635 | 54584 | 217.28.130.41 | 192.168.2.14 |
Nov 1, 2024 08:49:49.402734041 CET | 10635 | 54584 | 217.28.130.41 | 192.168.2.14 |
Nov 1, 2024 08:49:49.402750015 CET | 10635 | 54584 | 217.28.130.41 | 192.168.2.14 |
Nov 1, 2024 08:49:49.402895927 CET | 54584 | 10635 | 192.168.2.14 | 217.28.130.41 |
Nov 1, 2024 08:49:49.402895927 CET | 54584 | 10635 | 192.168.2.14 | 217.28.130.41 |
Nov 1, 2024 08:49:49.402895927 CET | 54584 | 10635 | 192.168.2.14 | 217.28.130.41 |
Nov 1, 2024 08:49:54.495878935 CET | 54036 | 3207 | 192.168.2.14 | 213.182.204.57 |
Nov 1, 2024 08:49:54.500706911 CET | 3207 | 54036 | 213.182.204.57 | 192.168.2.14 |
Nov 1, 2024 08:49:54.500807047 CET | 54036 | 3207 | 192.168.2.14 | 213.182.204.57 |
Nov 1, 2024 08:49:54.500819921 CET | 54036 | 3207 | 192.168.2.14 | 213.182.204.57 |
Nov 1, 2024 08:49:54.505564928 CET | 3207 | 54036 | 213.182.204.57 | 192.168.2.14 |
Nov 1, 2024 08:49:54.505672932 CET | 54036 | 3207 | 192.168.2.14 | 213.182.204.57 |
Nov 1, 2024 08:49:54.510593891 CET | 3207 | 54036 | 213.182.204.57 | 192.168.2.14 |
Nov 1, 2024 08:49:55.466566086 CET | 3207 | 54036 | 213.182.204.57 | 192.168.2.14 |
Nov 1, 2024 08:49:55.466753960 CET | 54036 | 3207 | 192.168.2.14 | 213.182.204.57 |
Nov 1, 2024 08:49:55.466810942 CET | 54036 | 3207 | 192.168.2.14 | 213.182.204.57 |
Nov 1, 2024 08:49:55.466856003 CET | 3207 | 54036 | 213.182.204.57 | 192.168.2.14 |
Nov 1, 2024 08:49:55.466984987 CET | 54036 | 3207 | 192.168.2.14 | 213.182.204.57 |
Nov 1, 2024 08:49:55.467006922 CET | 3207 | 54036 | 213.182.204.57 | 192.168.2.14 |
Nov 1, 2024 08:49:55.467061043 CET | 54036 | 3207 | 192.168.2.14 | 213.182.204.57 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 1, 2024 08:47:58.511673927 CET | 53325 | 53 | 192.168.2.14 | 64.176.6.48 |
Nov 1, 2024 08:47:58.603015900 CET | 43550 | 53 | 192.168.2.14 | 64.176.6.48 |
Nov 1, 2024 08:48:03.518136978 CET | 60106 | 53 | 192.168.2.14 | 202.61.197.122 |
Nov 1, 2024 08:48:03.528585911 CET | 53 | 60106 | 202.61.197.122 | 192.168.2.14 |
Nov 1, 2024 08:48:03.609112978 CET | 44809 | 53 | 192.168.2.14 | 202.61.197.122 |
Nov 1, 2024 08:48:03.619434118 CET | 53 | 44809 | 202.61.197.122 | 192.168.2.14 |
Nov 1, 2024 08:48:03.620590925 CET | 34637 | 53 | 192.168.2.14 | 152.53.15.127 |
Nov 1, 2024 08:48:03.630863905 CET | 53 | 34637 | 152.53.15.127 | 192.168.2.14 |
Nov 1, 2024 08:48:04.391918898 CET | 36330 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 1, 2024 08:48:04.391982079 CET | 44156 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 1, 2024 08:48:04.398830891 CET | 53 | 44156 | 1.1.1.1 | 192.168.2.14 |
Nov 1, 2024 08:48:04.398926020 CET | 53 | 36330 | 1.1.1.1 | 192.168.2.14 |
Nov 1, 2024 08:48:09.476969004 CET | 35282 | 53 | 192.168.2.14 | 178.254.22.166 |
Nov 1, 2024 08:48:14.483072996 CET | 56987 | 53 | 192.168.2.14 | 80.152.203.134 |
Nov 1, 2024 08:48:14.530381918 CET | 53 | 56987 | 80.152.203.134 | 192.168.2.14 |
Nov 1, 2024 08:48:21.196084976 CET | 36854 | 53 | 192.168.2.14 | 5.161.109.23 |
Nov 1, 2024 08:48:26.201951027 CET | 46321 | 53 | 192.168.2.14 | 194.36.144.87 |
Nov 1, 2024 08:48:26.211889029 CET | 53 | 46321 | 194.36.144.87 | 192.168.2.14 |
Nov 1, 2024 08:48:31.902369976 CET | 60170 | 53 | 192.168.2.14 | 202.61.197.122 |
Nov 1, 2024 08:48:31.914482117 CET | 53 | 60170 | 202.61.197.122 | 192.168.2.14 |
Nov 1, 2024 08:48:37.938775063 CET | 53217 | 53 | 192.168.2.14 | 5.161.109.23 |
Nov 1, 2024 08:48:42.945354939 CET | 49270 | 53 | 192.168.2.14 | 178.254.22.166 |
Nov 1, 2024 08:48:47.952069044 CET | 44419 | 53 | 192.168.2.14 | 168.235.111.72 |
Nov 1, 2024 08:48:48.047791958 CET | 53 | 44419 | 168.235.111.72 | 192.168.2.14 |
Nov 1, 2024 08:48:54.034728050 CET | 57470 | 53 | 192.168.2.14 | 202.61.197.122 |
Nov 1, 2024 08:48:54.044996023 CET | 53 | 57470 | 202.61.197.122 | 192.168.2.14 |
Nov 1, 2024 08:49:00.078269005 CET | 33563 | 53 | 192.168.2.14 | 137.220.52.23 |
Nov 1, 2024 08:49:05.084858894 CET | 49806 | 53 | 192.168.2.14 | 51.158.108.203 |
Nov 1, 2024 08:49:05.100255013 CET | 53 | 49806 | 51.158.108.203 | 192.168.2.14 |
Nov 1, 2024 08:49:11.240998983 CET | 44728 | 53 | 192.168.2.14 | 202.61.197.122 |
Nov 1, 2024 08:49:11.251439095 CET | 53 | 44728 | 202.61.197.122 | 192.168.2.14 |
Nov 1, 2024 08:49:17.347718954 CET | 33508 | 53 | 192.168.2.14 | 5.161.109.23 |
Nov 1, 2024 08:49:22.354116917 CET | 60145 | 53 | 192.168.2.14 | 137.220.52.23 |
Nov 1, 2024 08:49:27.360928059 CET | 37981 | 53 | 192.168.2.14 | 137.220.52.23 |
Nov 1, 2024 08:49:32.367155075 CET | 44597 | 53 | 192.168.2.14 | 5.161.109.23 |
Nov 1, 2024 08:49:43.464896917 CET | 47823 | 53 | 192.168.2.14 | 5.161.109.23 |
Nov 1, 2024 08:49:48.471343040 CET | 34726 | 53 | 192.168.2.14 | 217.160.70.42 |
Nov 1, 2024 08:49:48.703790903 CET | 53 | 34726 | 217.160.70.42 | 192.168.2.14 |
Nov 1, 2024 08:49:54.405348063 CET | 48585 | 53 | 192.168.2.14 | 168.235.111.72 |
Nov 1, 2024 08:49:54.494941950 CET | 53 | 48585 | 168.235.111.72 | 192.168.2.14 |
Nov 1, 2024 08:50:00.469556093 CET | 48236 | 53 | 192.168.2.14 | 5.161.109.23 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 1, 2024 08:47:58.511673927 CET | 192.168.2.14 | 64.176.6.48 | 0x91fb | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 1, 2024 08:48:03.518136978 CET | 192.168.2.14 | 202.61.197.122 | 0xcf6e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 1, 2024 08:48:04.391918898 CET | 192.168.2.14 | 1.1.1.1 | 0xba55 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 1, 2024 08:48:04.391982079 CET | 192.168.2.14 | 1.1.1.1 | 0x2344 | Standard query (0) | 28 | IN (0x0001) | false | |
Nov 1, 2024 08:48:09.476969004 CET | 192.168.2.14 | 178.254.22.166 | 0xb0fc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 1, 2024 08:48:14.483072996 CET | 192.168.2.14 | 80.152.203.134 | 0x12ed | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 1, 2024 08:48:21.196084976 CET | 192.168.2.14 | 5.161.109.23 | 0x7365 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 1, 2024 08:48:26.201951027 CET | 192.168.2.14 | 194.36.144.87 | 0xdaf4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 1, 2024 08:48:31.902369976 CET | 192.168.2.14 | 202.61.197.122 | 0xb545 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 1, 2024 08:48:37.938775063 CET | 192.168.2.14 | 5.161.109.23 | 0xb539 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 1, 2024 08:48:42.945354939 CET | 192.168.2.14 | 178.254.22.166 | 0xd9d5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 1, 2024 08:48:47.952069044 CET | 192.168.2.14 | 168.235.111.72 | 0x785f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 1, 2024 08:48:54.034728050 CET | 192.168.2.14 | 202.61.197.122 | 0x6ef3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 1, 2024 08:49:00.078269005 CET | 192.168.2.14 | 137.220.52.23 | 0x914d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 1, 2024 08:49:05.084858894 CET | 192.168.2.14 | 51.158.108.203 | 0xb9a0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 1, 2024 08:49:11.240998983 CET | 192.168.2.14 | 202.61.197.122 | 0xb4ee | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 1, 2024 08:49:17.347718954 CET | 192.168.2.14 | 5.161.109.23 | 0x354a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 1, 2024 08:49:22.354116917 CET | 192.168.2.14 | 137.220.52.23 | 0x26c0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 1, 2024 08:49:27.360928059 CET | 192.168.2.14 | 137.220.52.23 | 0xa506 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 1, 2024 08:49:32.367155075 CET | 192.168.2.14 | 5.161.109.23 | 0x5140 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 1, 2024 08:49:43.464896917 CET | 192.168.2.14 | 5.161.109.23 | 0xb6ec | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 1, 2024 08:49:48.471343040 CET | 192.168.2.14 | 217.160.70.42 | 0x4aa4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 1, 2024 08:49:54.405348063 CET | 192.168.2.14 | 168.235.111.72 | 0xba02 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 1, 2024 08:50:00.469556093 CET | 192.168.2.14 | 5.161.109.23 | 0xa273 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 1, 2024 08:48:03.528585911 CET | 202.61.197.122 | 192.168.2.14 | 0xcf6e | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:03.528585911 CET | 202.61.197.122 | 192.168.2.14 | 0xcf6e | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:03.528585911 CET | 202.61.197.122 | 192.168.2.14 | 0xcf6e | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:03.528585911 CET | 202.61.197.122 | 192.168.2.14 | 0xcf6e | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:03.528585911 CET | 202.61.197.122 | 192.168.2.14 | 0xcf6e | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:03.528585911 CET | 202.61.197.122 | 192.168.2.14 | 0xcf6e | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:03.528585911 CET | 202.61.197.122 | 192.168.2.14 | 0xcf6e | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:03.528585911 CET | 202.61.197.122 | 192.168.2.14 | 0xcf6e | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:03.528585911 CET | 202.61.197.122 | 192.168.2.14 | 0xcf6e | No error (0) | 217.28.130.41 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:03.619434118 CET | 202.61.197.122 | 192.168.2.14 | 0xcf6e | Format error (1) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 1, 2024 08:48:04.398926020 CET | 1.1.1.1 | 192.168.2.14 | 0xba55 | No error (0) | 162.213.35.25 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:04.398926020 CET | 1.1.1.1 | 192.168.2.14 | 0xba55 | No error (0) | 162.213.35.24 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:14.530381918 CET | 80.152.203.134 | 192.168.2.14 | 0x12ed | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:14.530381918 CET | 80.152.203.134 | 192.168.2.14 | 0x12ed | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:14.530381918 CET | 80.152.203.134 | 192.168.2.14 | 0x12ed | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:14.530381918 CET | 80.152.203.134 | 192.168.2.14 | 0x12ed | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:14.530381918 CET | 80.152.203.134 | 192.168.2.14 | 0x12ed | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:14.530381918 CET | 80.152.203.134 | 192.168.2.14 | 0x12ed | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:14.530381918 CET | 80.152.203.134 | 192.168.2.14 | 0x12ed | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:14.530381918 CET | 80.152.203.134 | 192.168.2.14 | 0x12ed | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:14.530381918 CET | 80.152.203.134 | 192.168.2.14 | 0x12ed | No error (0) | 217.28.130.41 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:26.211889029 CET | 194.36.144.87 | 192.168.2.14 | 0xdaf4 | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:26.211889029 CET | 194.36.144.87 | 192.168.2.14 | 0xdaf4 | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:26.211889029 CET | 194.36.144.87 | 192.168.2.14 | 0xdaf4 | No error (0) | 217.28.130.41 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:26.211889029 CET | 194.36.144.87 | 192.168.2.14 | 0xdaf4 | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:26.211889029 CET | 194.36.144.87 | 192.168.2.14 | 0xdaf4 | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:26.211889029 CET | 194.36.144.87 | 192.168.2.14 | 0xdaf4 | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:26.211889029 CET | 194.36.144.87 | 192.168.2.14 | 0xdaf4 | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:26.211889029 CET | 194.36.144.87 | 192.168.2.14 | 0xdaf4 | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:26.211889029 CET | 194.36.144.87 | 192.168.2.14 | 0xdaf4 | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:31.914482117 CET | 202.61.197.122 | 192.168.2.14 | 0xb545 | No error (0) | 217.28.130.41 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:31.914482117 CET | 202.61.197.122 | 192.168.2.14 | 0xb545 | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:31.914482117 CET | 202.61.197.122 | 192.168.2.14 | 0xb545 | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:31.914482117 CET | 202.61.197.122 | 192.168.2.14 | 0xb545 | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:31.914482117 CET | 202.61.197.122 | 192.168.2.14 | 0xb545 | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:31.914482117 CET | 202.61.197.122 | 192.168.2.14 | 0xb545 | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:31.914482117 CET | 202.61.197.122 | 192.168.2.14 | 0xb545 | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:31.914482117 CET | 202.61.197.122 | 192.168.2.14 | 0xb545 | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:31.914482117 CET | 202.61.197.122 | 192.168.2.14 | 0xb545 | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:48.047791958 CET | 168.235.111.72 | 192.168.2.14 | 0x785f | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:48.047791958 CET | 168.235.111.72 | 192.168.2.14 | 0x785f | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:48.047791958 CET | 168.235.111.72 | 192.168.2.14 | 0x785f | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:48.047791958 CET | 168.235.111.72 | 192.168.2.14 | 0x785f | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:48.047791958 CET | 168.235.111.72 | 192.168.2.14 | 0x785f | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:48.047791958 CET | 168.235.111.72 | 192.168.2.14 | 0x785f | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:48.047791958 CET | 168.235.111.72 | 192.168.2.14 | 0x785f | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:48.047791958 CET | 168.235.111.72 | 192.168.2.14 | 0x785f | No error (0) | 217.28.130.41 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:48.047791958 CET | 168.235.111.72 | 192.168.2.14 | 0x785f | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:54.044996023 CET | 202.61.197.122 | 192.168.2.14 | 0x6ef3 | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:54.044996023 CET | 202.61.197.122 | 192.168.2.14 | 0x6ef3 | No error (0) | 217.28.130.41 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:54.044996023 CET | 202.61.197.122 | 192.168.2.14 | 0x6ef3 | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:54.044996023 CET | 202.61.197.122 | 192.168.2.14 | 0x6ef3 | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:54.044996023 CET | 202.61.197.122 | 192.168.2.14 | 0x6ef3 | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:54.044996023 CET | 202.61.197.122 | 192.168.2.14 | 0x6ef3 | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:54.044996023 CET | 202.61.197.122 | 192.168.2.14 | 0x6ef3 | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:54.044996023 CET | 202.61.197.122 | 192.168.2.14 | 0x6ef3 | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:48:54.044996023 CET | 202.61.197.122 | 192.168.2.14 | 0x6ef3 | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:05.100255013 CET | 51.158.108.203 | 192.168.2.14 | 0xb9a0 | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:05.100255013 CET | 51.158.108.203 | 192.168.2.14 | 0xb9a0 | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:05.100255013 CET | 51.158.108.203 | 192.168.2.14 | 0xb9a0 | No error (0) | 217.28.130.41 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:05.100255013 CET | 51.158.108.203 | 192.168.2.14 | 0xb9a0 | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:05.100255013 CET | 51.158.108.203 | 192.168.2.14 | 0xb9a0 | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:05.100255013 CET | 51.158.108.203 | 192.168.2.14 | 0xb9a0 | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:05.100255013 CET | 51.158.108.203 | 192.168.2.14 | 0xb9a0 | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:05.100255013 CET | 51.158.108.203 | 192.168.2.14 | 0xb9a0 | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:05.100255013 CET | 51.158.108.203 | 192.168.2.14 | 0xb9a0 | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:11.251439095 CET | 202.61.197.122 | 192.168.2.14 | 0xb4ee | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:11.251439095 CET | 202.61.197.122 | 192.168.2.14 | 0xb4ee | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:11.251439095 CET | 202.61.197.122 | 192.168.2.14 | 0xb4ee | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:11.251439095 CET | 202.61.197.122 | 192.168.2.14 | 0xb4ee | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:11.251439095 CET | 202.61.197.122 | 192.168.2.14 | 0xb4ee | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:11.251439095 CET | 202.61.197.122 | 192.168.2.14 | 0xb4ee | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:11.251439095 CET | 202.61.197.122 | 192.168.2.14 | 0xb4ee | No error (0) | 217.28.130.41 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:11.251439095 CET | 202.61.197.122 | 192.168.2.14 | 0xb4ee | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:11.251439095 CET | 202.61.197.122 | 192.168.2.14 | 0xb4ee | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:48.703790903 CET | 217.160.70.42 | 192.168.2.14 | 0x4aa4 | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:48.703790903 CET | 217.160.70.42 | 192.168.2.14 | 0x4aa4 | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:48.703790903 CET | 217.160.70.42 | 192.168.2.14 | 0x4aa4 | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:48.703790903 CET | 217.160.70.42 | 192.168.2.14 | 0x4aa4 | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:48.703790903 CET | 217.160.70.42 | 192.168.2.14 | 0x4aa4 | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:48.703790903 CET | 217.160.70.42 | 192.168.2.14 | 0x4aa4 | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:48.703790903 CET | 217.160.70.42 | 192.168.2.14 | 0x4aa4 | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:48.703790903 CET | 217.160.70.42 | 192.168.2.14 | 0x4aa4 | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:48.703790903 CET | 217.160.70.42 | 192.168.2.14 | 0x4aa4 | No error (0) | 217.28.130.41 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:54.494941950 CET | 168.235.111.72 | 192.168.2.14 | 0xba02 | No error (0) | 217.28.130.41 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:54.494941950 CET | 168.235.111.72 | 192.168.2.14 | 0xba02 | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:54.494941950 CET | 168.235.111.72 | 192.168.2.14 | 0xba02 | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:54.494941950 CET | 168.235.111.72 | 192.168.2.14 | 0xba02 | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:54.494941950 CET | 168.235.111.72 | 192.168.2.14 | 0xba02 | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:54.494941950 CET | 168.235.111.72 | 192.168.2.14 | 0xba02 | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:54.494941950 CET | 168.235.111.72 | 192.168.2.14 | 0xba02 | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:54.494941950 CET | 168.235.111.72 | 192.168.2.14 | 0xba02 | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Nov 1, 2024 08:49:54.494941950 CET | 168.235.111.72 | 192.168.2.14 | 0xba02 | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 07:47:57 |
Start date (UTC): | 01/11/2024 |
Path: | /tmp/harm4.elf |
Arguments: | /tmp/harm4.elf |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 07:47:57 |
Start date (UTC): | 01/11/2024 |
Path: | /tmp/harm4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 07:47:57 |
Start date (UTC): | 01/11/2024 |
Path: | /tmp/harm4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 07:47:57 |
Start date (UTC): | 01/11/2024 |
Path: | /tmp/harm4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |