Edit tour
Linux
Analysis Report
debug.dbg.elf
Overview
General Information
Sample name: | debug.dbg.elf |
Analysis ID: | 1547502 |
MD5: | 5ebf5890d7d2c998b801d48b87667276 |
SHA1: | 4888c1c4df5cfc9f76b9dc5094e9b991127e16f5 |
SHA256: | d4bc44ddc24214d6409a8e0ac6eaa66c47f19c345123498373a81e7b96faed98 |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Mirai, Okiru
Score: | 88 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Yara detected Okiru
Machine Learning detection for sample
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Yara signature match
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1547502 |
Start date and time: | 2024-11-02 16:17:09 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 6m 31s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | debug.dbg.elf |
Detection: | MAL |
Classification: | mal88.troj.evad.linELF@0/0@19/0 |
- VT rate limit hit for: debug.dbg.elf
Command: | /tmp/debug.dbg.elf |
PID: | 5432 |
Exit Code: | |
Exit Code Info: | |
Killed: | True |
Standard Output: | VagneRHere [VagneR] >> debug mode, pid: 5432 [VagneR] >> We Are The Only Process On This System! (watchdog) >> failed to find a valid watchdog driver, bailing out [VagneR] >> debug mode, pid: 5432 [VagneR] >> We Are The Only Process On This System! (main) >> attempting to connect to cnc (YBot/Resolver) >> got response from select (YBot/Resolver) >> found ipv4 address: 2610d89a (YBot/Resolver) >> resolved server.myway-ing.win to 1 ipv4 addresses (main) >> resolved domain (main) >> connected to CNC. (main) >> attempting to connect to cnc (YBot/Resolver) >> got response from select (YBot/Resolver) >> found ipv4 address: 2610d89a (YBot/Resolver) >> resolved server.myway-ing.win to 1 ipv4 addresses (main) >> resolved domain (main) >> connected to CNC. (main) >> attempting to connect to cnc (YBot/Resolver) >> got response from select (YBot/Resolver) >> found ipv4 address: 2610d89a (YBot/Resolver) >> resolved server.myway-ing.win to 1 ipv4 addresses (main) >> resolved domain (main) >> connected to CNC. (main) >> attempting to connect to cnc (YBot/Resolver) >> got response from select (YBot/Resolver) >> found ipv4 address: 2610d89a (YBot/Resolver) >> resolved server.myway-ing.win to 1 ipv4 addresses (main) >> resolved domain (main) >> connected to CNC. (main) >> attempting to connect to cnc (YBot/Resolver) >> got response from select (YBot/Resolver) >> found ipv4 address: 2610d89a (YBot/Resolver) >> resolved server.myway-ing.win to 1 ipv4 addresses (main) >> resolved domain (main) >> connected to CNC. (main) >> attempting to connect to cnc (YBot/Resolver) >> got response from select (YBot/Resolver) >> found ipv4 address: 2610d89a (YBot/Resolver) >> resolved server.myway-ing.win to 1 ipv4 addresses (main) >> resolved domain (main) >> connected to CNC. (main) >> attempting to connect to cnc (YBot/Resolver) >> got response from select (YBot/Resolver) >> found ipv4 address: 2610d89a (YBot/Resolver) >> resolved server.myway-ing.win to 1 ipv4 addresses (main) >> resolved domain (main) >> connected to CNC. (main) >> attempting to connect to cnc (YBot/Resolver) >> got response from select (YBot/Resolver) >> found ipv4 address: 2610d89a (YBot/Resolver) >> resolved server.myway-ing.win to 1 ipv4 addresses (main) >> resolved domain (main) >> connected to CNC. (main) >> attempting to connect to cnc (YBot/Resolver) >> got response from select (YBot/Resolver) >> found ipv4 address: 2610d89a (YBot/Resolver) >> resolved server.myway-ing.win to 1 ipv4 addresses (main) >> resolved domain (main) >> connected to CNC. (main) >> attempting to connect to cnc (YBot/Resolver) >> got response from select (YBot/Resolver) >> found ipv4 address: 2610d89a (YBot/Resolver) >> resolved server.myway-ing.win to 1 ipv4 addresses (main) >> resolved domain (main) >> connected to CNC. (main) >> attempting to connect to cnc (YBot/Resolver) >> got response from select (YBot/Resolver) >> found ipv4 address: 2610d89a (YBot/Resolver) >> resolved server.myway-ing.win to 1 ipv4 addresses (main) >> resolved domain (main) >> connected to CNC. (main) >> attempting to connect to cnc (YBot/Resolver) >> got response from select (YBot/Resolver) >> found ipv4 address: 2610d89a (YBot/Resolver) >> resolved server.myway-ing.win to 1 ipv4 addresses (main) >> resolved domain (main) >> connected to CNC. (main) >> attempting to connect to cnc (YBot/Resolver) >> got response from select (YBot/Resolver) >> found ipv4 address: 2610d89a (YBot/Resolver) >> resolved server.myway-ing.win to 1 ipv4 addresses (main) >> resolved domain (main) >> connected to CNC. (main) >> attempting to connect to cnc (YBot/Resolver) >> got response from select (YBot/Resolver) >> found ipv4 address: 2610d89a (YBot/Resolver) >> resolved server.myway-ing.win to 1 ipv4 addresses (main) >> resolved domain (main) >> connected to CNC. (main) >> attempting to connect to cnc (YBot/Resolver) >> got response from select (YBot/Resolver) >> found ipv4 address: 2610d89a (YBot/Resolver) >> resolved server.myway-ing.win to 1 ipv4 addresses (main) >> resolved domain (main) >> connected to CNC. (main) >> attempting to connect to cnc (YBot/Resolver) >> got response from select (YBot/Resolver) >> found ipv4 address: 2610d89a (YBot/Resolver) >> resolved server.myway-ing.win to 1 ipv4 addresses |
Standard Error: |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Mirai | Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Okiru | Yara detected Okiru | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
Linux_Trojan_Mirai_b14f4c5d | unknown | unknown |
| |
Linux_Trojan_Mirai_88de437f | unknown | unknown |
| |
Click to see the 3 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Okiru | Yara detected Okiru | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
Linux_Trojan_Mirai_b14f4c5d | unknown | unknown |
| |
Linux_Trojan_Mirai_88de437f | unknown | unknown |
| |
Click to see the 17 entries |
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Source: | Joe Sandbox ML: |
Source: | TCP traffic: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | .symtab present: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | 1 File Deletion | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Non-Standard Port | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
47% | ReversingLabs | Linux.Backdoor.Mirai | ||
100% | Avira | EXP/ELF.Mirai.Z.A | ||
100% | Joe Sandbox ML |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
daisy.ubuntu.com | 162.213.35.24 | true | false | unknown | |
server.myway-ing.win | 154.216.16.38 | true | false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
154.216.16.38 | server.myway-ing.win | Seychelles | 135357 | SKHT-ASShenzhenKatherineHengTechnologyInformationCo | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
154.216.16.38 | Get hash | malicious | Mirai, Okiru | Browse | ||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Okiru | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
server.myway-ing.win | Get hash | malicious | Mirai, Okiru | Browse |
| |
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
daisy.ubuntu.com | Get hash | malicious | Okiru | Browse |
| |
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
SKHT-ASShenzhenKatherineHengTechnologyInformationCo | Get hash | malicious | Mirai, Okiru | Browse |
| |
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 6.453416635603942 |
TrID: |
|
File name: | debug.dbg.elf |
File size: | 70'832 bytes |
MD5: | 5ebf5890d7d2c998b801d48b87667276 |
SHA1: | 4888c1c4df5cfc9f76b9dc5094e9b991127e16f5 |
SHA256: | d4bc44ddc24214d6409a8e0ac6eaa66c47f19c345123498373a81e7b96faed98 |
SHA512: | 651716eaa2f1fb738361ddc500c428134627a99a98bc8260a90ed4e14a1eb93e37f41d164806e39230e9a71e72cea2f96c2a6f781e27c8c9394eb3d27f0fe24e |
SSDEEP: | 1536:bSKRI7C2wEI5Z5268+I/UCCPyimYJmoV9okwKBTx3Poui7N1OF9Q+1j:bSKRI7C2wEI5nxCCqimYJmoVikwKBTxl |
TLSH: | 9B635BC4F943C8B6FD160630217BEB775FB2F1B91358EE43D7A89972E862641E501A8C |
File Content Preview: | .ELF....................d...4... .......4. ...(......................................................... *..........Q.td............................U..S.......w....h....S...[]...$.............U......=.....t..5....$......$.......u........t....h............ |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 70432 |
Section Header Size: | 40 |
Number of Section Headers: | 10 |
Header String Table Index: | 9 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x8048094 | 0x94 | 0x1c | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.text | PROGBITS | 0x80480b0 | 0xb0 | 0xd976 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x8055a26 | 0xda26 | 0x17 | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.rodata | PROGBITS | 0x8055a40 | 0xda40 | 0x2bdc | 0x0 | 0x2 | A | 0 | 0 | 32 |
.ctors | PROGBITS | 0x8059000 | 0x11000 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x8059008 | 0x11008 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x8059020 | 0x11020 | 0x2c0 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.bss | NOBITS | 0x80592e0 | 0x112e0 | 0x2740 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.shstrtab | STRTAB | 0x0 | 0x112e0 | 0x3e | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8048000 | 0x8048000 | 0x1061c | 0x1061c | 6.6218 | 0x5 | R E | 0x1000 | .init .text .fini .rodata | |
LOAD | 0x11000 | 0x8059000 | 0x8059000 | 0x2e0 | 0x2a20 | 3.7669 | 0x6 | RW | 0x1000 | .ctors .dtors .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 2, 2024 16:17:53.863571882 CET | 55698 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:53.868647099 CET | 59962 | 55698 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:17:53.868706942 CET | 55698 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:53.868746042 CET | 55698 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:53.873637915 CET | 59962 | 55698 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:17:53.873687029 CET | 55698 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:53.878973961 CET | 59962 | 55698 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:17:54.748262882 CET | 59962 | 55698 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:17:54.748816967 CET | 55698 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:54.748817921 CET | 55698 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:54.756671906 CET | 55700 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:54.761746883 CET | 59962 | 55700 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:17:54.761811972 CET | 55700 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:54.761836052 CET | 55700 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:54.766881943 CET | 59962 | 55700 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:17:54.766921997 CET | 55700 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:54.771951914 CET | 59962 | 55700 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:17:55.645735025 CET | 59962 | 55700 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:17:55.646048069 CET | 55700 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:55.646048069 CET | 55700 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:55.653640985 CET | 55702 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:55.658608913 CET | 59962 | 55702 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:17:55.658703089 CET | 55702 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:55.658766985 CET | 55702 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:55.663789034 CET | 59962 | 55702 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:17:55.663846016 CET | 55702 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:55.669183969 CET | 59962 | 55702 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:17:56.542937040 CET | 59962 | 55702 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:17:56.543195009 CET | 55702 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:56.543195009 CET | 55702 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:56.551728010 CET | 55704 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:56.556674957 CET | 59962 | 55704 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:17:56.556741953 CET | 55704 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:56.556828022 CET | 55704 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:56.562155008 CET | 59962 | 55704 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:17:56.562200069 CET | 55704 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:56.567400932 CET | 59962 | 55704 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:17:57.492625952 CET | 59962 | 55704 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:17:57.492990017 CET | 55704 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:57.493014097 CET | 55704 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:57.502300978 CET | 55706 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:57.508256912 CET | 59962 | 55706 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:17:57.508346081 CET | 55706 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:57.508411884 CET | 55706 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:57.514072895 CET | 59962 | 55706 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:17:57.514138937 CET | 55706 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:57.520128965 CET | 59962 | 55706 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:17:58.396102905 CET | 59962 | 55706 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:17:58.396121025 CET | 59962 | 55706 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:17:58.396266937 CET | 55706 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:58.396286964 CET | 55706 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:58.396333933 CET | 55706 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:58.404263973 CET | 55708 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:58.409257889 CET | 59962 | 55708 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:17:58.409339905 CET | 55708 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:58.409399986 CET | 55708 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:58.414824963 CET | 59962 | 55708 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:17:58.414889097 CET | 55708 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:58.419698954 CET | 59962 | 55708 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:17:59.289431095 CET | 59962 | 55708 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:17:59.289554119 CET | 55708 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:59.289593935 CET | 55708 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:59.296593904 CET | 55710 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:59.301590919 CET | 59962 | 55710 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:17:59.301646948 CET | 55710 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:59.301671028 CET | 55710 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:59.306494951 CET | 59962 | 55710 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:17:59.306543112 CET | 55710 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:17:59.311542988 CET | 59962 | 55710 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:00.215033054 CET | 59962 | 55710 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:00.215102911 CET | 59962 | 55710 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:00.215193987 CET | 55710 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:00.215193987 CET | 55710 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:00.215234041 CET | 55710 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:00.222642899 CET | 55712 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:00.227806091 CET | 59962 | 55712 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:00.227891922 CET | 55712 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:00.227925062 CET | 55712 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:00.232764006 CET | 59962 | 55712 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:00.232819080 CET | 55712 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:00.237631083 CET | 59962 | 55712 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:01.102232933 CET | 59962 | 55712 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:01.102267981 CET | 59962 | 55712 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:01.102423906 CET | 55712 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:01.102423906 CET | 55712 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:01.102511883 CET | 55712 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:01.109533072 CET | 55714 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:01.114429951 CET | 59962 | 55714 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:01.114543915 CET | 55714 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:01.114578962 CET | 55714 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:01.119466066 CET | 59962 | 55714 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:01.119544029 CET | 55714 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:01.124401093 CET | 59962 | 55714 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:02.554996967 CET | 59962 | 55714 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:02.555016994 CET | 59962 | 55714 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:02.555028915 CET | 59962 | 55714 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:02.555381060 CET | 55714 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:02.555381060 CET | 55714 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:02.555382013 CET | 55714 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:02.555399895 CET | 59962 | 55714 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:02.555455923 CET | 55714 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:02.555486917 CET | 55714 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:02.563414097 CET | 55716 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:02.568257093 CET | 59962 | 55716 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:02.568340063 CET | 55716 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:02.568396091 CET | 55716 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:02.573544979 CET | 59962 | 55716 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:02.573609114 CET | 55716 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:02.579804897 CET | 59962 | 55716 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:03.466907978 CET | 59962 | 55716 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:03.466928005 CET | 59962 | 55716 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:03.467031956 CET | 55716 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:03.467051983 CET | 55716 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:03.467116117 CET | 55716 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:03.478961945 CET | 55718 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:03.483933926 CET | 59962 | 55718 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:03.483998060 CET | 55718 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:03.484081984 CET | 55718 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:03.488959074 CET | 59962 | 55718 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:03.489012003 CET | 55718 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:03.493876934 CET | 59962 | 55718 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:04.373442888 CET | 59962 | 55718 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:04.373584986 CET | 55718 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:04.373646021 CET | 55718 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:04.380454063 CET | 55720 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:04.385335922 CET | 59962 | 55720 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:04.385412931 CET | 55720 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:04.385488033 CET | 55720 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:04.390279055 CET | 59962 | 55720 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:04.390331984 CET | 55720 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:04.395200968 CET | 59962 | 55720 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:05.288845062 CET | 59962 | 55720 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:05.289165974 CET | 55720 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:05.289226055 CET | 55720 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:05.296222925 CET | 55722 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:05.301090956 CET | 59962 | 55722 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:05.301179886 CET | 55722 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:05.301251888 CET | 55722 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:05.306062937 CET | 59962 | 55722 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:05.306129932 CET | 55722 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:05.311007977 CET | 59962 | 55722 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:06.311424971 CET | 59962 | 55722 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:06.311561108 CET | 55722 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:06.311619043 CET | 55722 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:06.318519115 CET | 55724 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:06.323388100 CET | 59962 | 55724 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:06.323465109 CET | 55724 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:06.323522091 CET | 55724 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:06.328346968 CET | 59962 | 55724 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:06.328421116 CET | 55724 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:06.333210945 CET | 59962 | 55724 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:07.233908892 CET | 59962 | 55724 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:07.233931065 CET | 59962 | 55724 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:07.234220982 CET | 55724 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:07.234347105 CET | 55724 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:07.234386921 CET | 55724 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:07.241729975 CET | 55726 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:07.246579885 CET | 59962 | 55726 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:07.246670961 CET | 55726 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:07.246742964 CET | 55726 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:07.251554966 CET | 59962 | 55726 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:07.251645088 CET | 55726 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:07.256510973 CET | 59962 | 55726 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:08.123991966 CET | 59962 | 55726 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:08.124197960 CET | 55726 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:08.124293089 CET | 55726 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:08.135030031 CET | 55728 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:08.139897108 CET | 59962 | 55728 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:08.139978886 CET | 55728 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:08.140036106 CET | 55728 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:08.144972086 CET | 59962 | 55728 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:08.145030975 CET | 55728 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:08.149916887 CET | 59962 | 55728 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:09.030014038 CET | 59962 | 55728 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:09.030200958 CET | 55728 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:09.030227900 CET | 55728 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:09.038201094 CET | 55730 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:09.043149948 CET | 59962 | 55730 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:09.043226004 CET | 55730 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:09.043257952 CET | 55730 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:09.048257113 CET | 59962 | 55730 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:09.048330069 CET | 55730 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:09.053272963 CET | 59962 | 55730 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:19.043585062 CET | 55730 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:19.048829079 CET | 59962 | 55730 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:20.358720064 CET | 59962 | 55730 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:20.359087944 CET | 55730 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:20.360008001 CET | 59962 | 55730 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:20.360053062 CET | 55730 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:20.360198021 CET | 59962 | 55730 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:20.360236883 CET | 55730 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:20.360718966 CET | 59962 | 55730 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:20.360758066 CET | 55730 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:37.847217083 CET | 55730 | 59962 | 192.168.2.13 | 154.216.16.38 |
Nov 2, 2024 16:18:37.852477074 CET | 59962 | 55730 | 154.216.16.38 | 192.168.2.13 |
Nov 2, 2024 16:18:37.852534056 CET | 55730 | 59962 | 192.168.2.13 | 154.216.16.38 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 2, 2024 16:17:53.855060101 CET | 54673 | 53 | 192.168.2.13 | 8.8.8.8 |
Nov 2, 2024 16:17:53.863471031 CET | 53 | 54673 | 8.8.8.8 | 192.168.2.13 |
Nov 2, 2024 16:17:54.748817921 CET | 38071 | 53 | 192.168.2.13 | 8.8.8.8 |
Nov 2, 2024 16:17:54.756567001 CET | 53 | 38071 | 8.8.8.8 | 192.168.2.13 |
Nov 2, 2024 16:17:55.646245956 CET | 55689 | 53 | 192.168.2.13 | 8.8.8.8 |
Nov 2, 2024 16:17:55.653470039 CET | 53 | 55689 | 8.8.8.8 | 192.168.2.13 |
Nov 2, 2024 16:17:56.543335915 CET | 42106 | 53 | 192.168.2.13 | 8.8.8.8 |
Nov 2, 2024 16:17:56.551594973 CET | 53 | 42106 | 8.8.8.8 | 192.168.2.13 |
Nov 2, 2024 16:17:57.493168116 CET | 56308 | 53 | 192.168.2.13 | 8.8.8.8 |
Nov 2, 2024 16:17:57.502151966 CET | 53 | 56308 | 8.8.8.8 | 192.168.2.13 |
Nov 2, 2024 16:17:58.396425962 CET | 55429 | 53 | 192.168.2.13 | 8.8.8.8 |
Nov 2, 2024 16:17:58.404103994 CET | 53 | 55429 | 8.8.8.8 | 192.168.2.13 |
Nov 2, 2024 16:17:59.289679050 CET | 44157 | 53 | 192.168.2.13 | 8.8.8.8 |
Nov 2, 2024 16:17:59.296492100 CET | 53 | 44157 | 8.8.8.8 | 192.168.2.13 |
Nov 2, 2024 16:18:00.215361118 CET | 46551 | 53 | 192.168.2.13 | 8.8.8.8 |
Nov 2, 2024 16:18:00.222517967 CET | 53 | 46551 | 8.8.8.8 | 192.168.2.13 |
Nov 2, 2024 16:18:01.102639914 CET | 54802 | 53 | 192.168.2.13 | 8.8.8.8 |
Nov 2, 2024 16:18:01.109334946 CET | 53 | 54802 | 8.8.8.8 | 192.168.2.13 |
Nov 2, 2024 16:18:02.555581093 CET | 47669 | 53 | 192.168.2.13 | 8.8.8.8 |
Nov 2, 2024 16:18:02.563272953 CET | 53 | 47669 | 8.8.8.8 | 192.168.2.13 |
Nov 2, 2024 16:18:03.467227936 CET | 40070 | 53 | 192.168.2.13 | 8.8.8.8 |
Nov 2, 2024 16:18:03.474040985 CET | 53 | 40070 | 8.8.8.8 | 192.168.2.13 |
Nov 2, 2024 16:18:04.373779058 CET | 47133 | 53 | 192.168.2.13 | 8.8.8.8 |
Nov 2, 2024 16:18:04.380309105 CET | 53 | 47133 | 8.8.8.8 | 192.168.2.13 |
Nov 2, 2024 16:18:05.289359093 CET | 60621 | 53 | 192.168.2.13 | 8.8.8.8 |
Nov 2, 2024 16:18:05.296061993 CET | 53 | 60621 | 8.8.8.8 | 192.168.2.13 |
Nov 2, 2024 16:18:06.311688900 CET | 35493 | 53 | 192.168.2.13 | 8.8.8.8 |
Nov 2, 2024 16:18:06.318356037 CET | 53 | 35493 | 8.8.8.8 | 192.168.2.13 |
Nov 2, 2024 16:18:07.234528065 CET | 55734 | 53 | 192.168.2.13 | 8.8.8.8 |
Nov 2, 2024 16:18:07.241547108 CET | 53 | 55734 | 8.8.8.8 | 192.168.2.13 |
Nov 2, 2024 16:18:08.124435902 CET | 54835 | 53 | 192.168.2.13 | 8.8.8.8 |
Nov 2, 2024 16:18:08.130944014 CET | 53 | 54835 | 8.8.8.8 | 192.168.2.13 |
Nov 2, 2024 16:18:09.030320883 CET | 55305 | 53 | 192.168.2.13 | 8.8.8.8 |
Nov 2, 2024 16:18:09.038034916 CET | 53 | 55305 | 8.8.8.8 | 192.168.2.13 |
Nov 2, 2024 16:20:39.770241976 CET | 54142 | 53 | 192.168.2.13 | 8.8.8.8 |
Nov 2, 2024 16:20:39.770288944 CET | 48406 | 53 | 192.168.2.13 | 8.8.8.8 |
Nov 2, 2024 16:20:39.778901100 CET | 53 | 48406 | 8.8.8.8 | 192.168.2.13 |
Nov 2, 2024 16:20:39.779053926 CET | 53 | 54142 | 8.8.8.8 | 192.168.2.13 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 2, 2024 16:17:53.855060101 CET | 192.168.2.13 | 8.8.8.8 | 0x6161 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 2, 2024 16:17:54.748817921 CET | 192.168.2.13 | 8.8.8.8 | 0x1ff5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 2, 2024 16:17:55.646245956 CET | 192.168.2.13 | 8.8.8.8 | 0xfa5a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 2, 2024 16:17:56.543335915 CET | 192.168.2.13 | 8.8.8.8 | 0xf744 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 2, 2024 16:17:57.493168116 CET | 192.168.2.13 | 8.8.8.8 | 0x6e1c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 2, 2024 16:17:58.396425962 CET | 192.168.2.13 | 8.8.8.8 | 0x63cc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 2, 2024 16:17:59.289679050 CET | 192.168.2.13 | 8.8.8.8 | 0x1639 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 2, 2024 16:18:00.215361118 CET | 192.168.2.13 | 8.8.8.8 | 0xc039 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 2, 2024 16:18:01.102639914 CET | 192.168.2.13 | 8.8.8.8 | 0xb451 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 2, 2024 16:18:02.555581093 CET | 192.168.2.13 | 8.8.8.8 | 0x7fab | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 2, 2024 16:18:03.467227936 CET | 192.168.2.13 | 8.8.8.8 | 0x5d05 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 2, 2024 16:18:04.373779058 CET | 192.168.2.13 | 8.8.8.8 | 0x49fd | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 2, 2024 16:18:05.289359093 CET | 192.168.2.13 | 8.8.8.8 | 0x4a47 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 2, 2024 16:18:06.311688900 CET | 192.168.2.13 | 8.8.8.8 | 0x1736 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 2, 2024 16:18:07.234528065 CET | 192.168.2.13 | 8.8.8.8 | 0xe023 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 2, 2024 16:18:08.124435902 CET | 192.168.2.13 | 8.8.8.8 | 0x4ace | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 2, 2024 16:18:09.030320883 CET | 192.168.2.13 | 8.8.8.8 | 0x8049 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 2, 2024 16:20:39.770241976 CET | 192.168.2.13 | 8.8.8.8 | 0xb5b0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 2, 2024 16:20:39.770288944 CET | 192.168.2.13 | 8.8.8.8 | 0x1046 | Standard query (0) | 28 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 2, 2024 16:17:53.863471031 CET | 8.8.8.8 | 192.168.2.13 | 0x6161 | No error (0) | 154.216.16.38 | A (IP address) | IN (0x0001) | false | ||
Nov 2, 2024 16:17:54.756567001 CET | 8.8.8.8 | 192.168.2.13 | 0x1ff5 | No error (0) | 154.216.16.38 | A (IP address) | IN (0x0001) | false | ||
Nov 2, 2024 16:17:55.653470039 CET | 8.8.8.8 | 192.168.2.13 | 0xfa5a | No error (0) | 154.216.16.38 | A (IP address) | IN (0x0001) | false | ||
Nov 2, 2024 16:17:56.551594973 CET | 8.8.8.8 | 192.168.2.13 | 0xf744 | No error (0) | 154.216.16.38 | A (IP address) | IN (0x0001) | false | ||
Nov 2, 2024 16:17:57.502151966 CET | 8.8.8.8 | 192.168.2.13 | 0x6e1c | No error (0) | 154.216.16.38 | A (IP address) | IN (0x0001) | false | ||
Nov 2, 2024 16:17:58.404103994 CET | 8.8.8.8 | 192.168.2.13 | 0x63cc | No error (0) | 154.216.16.38 | A (IP address) | IN (0x0001) | false | ||
Nov 2, 2024 16:17:59.296492100 CET | 8.8.8.8 | 192.168.2.13 | 0x1639 | No error (0) | 154.216.16.38 | A (IP address) | IN (0x0001) | false | ||
Nov 2, 2024 16:18:00.222517967 CET | 8.8.8.8 | 192.168.2.13 | 0xc039 | No error (0) | 154.216.16.38 | A (IP address) | IN (0x0001) | false | ||
Nov 2, 2024 16:18:01.109334946 CET | 8.8.8.8 | 192.168.2.13 | 0xb451 | No error (0) | 154.216.16.38 | A (IP address) | IN (0x0001) | false | ||
Nov 2, 2024 16:18:02.563272953 CET | 8.8.8.8 | 192.168.2.13 | 0x7fab | No error (0) | 154.216.16.38 | A (IP address) | IN (0x0001) | false | ||
Nov 2, 2024 16:18:03.474040985 CET | 8.8.8.8 | 192.168.2.13 | 0x5d05 | No error (0) | 154.216.16.38 | A (IP address) | IN (0x0001) | false | ||
Nov 2, 2024 16:18:04.380309105 CET | 8.8.8.8 | 192.168.2.13 | 0x49fd | No error (0) | 154.216.16.38 | A (IP address) | IN (0x0001) | false | ||
Nov 2, 2024 16:18:05.296061993 CET | 8.8.8.8 | 192.168.2.13 | 0x4a47 | No error (0) | 154.216.16.38 | A (IP address) | IN (0x0001) | false | ||
Nov 2, 2024 16:18:06.318356037 CET | 8.8.8.8 | 192.168.2.13 | 0x1736 | No error (0) | 154.216.16.38 | A (IP address) | IN (0x0001) | false | ||
Nov 2, 2024 16:18:07.241547108 CET | 8.8.8.8 | 192.168.2.13 | 0xe023 | No error (0) | 154.216.16.38 | A (IP address) | IN (0x0001) | false | ||
Nov 2, 2024 16:18:08.130944014 CET | 8.8.8.8 | 192.168.2.13 | 0x4ace | No error (0) | 154.216.16.38 | A (IP address) | IN (0x0001) | false | ||
Nov 2, 2024 16:18:09.038034916 CET | 8.8.8.8 | 192.168.2.13 | 0x8049 | No error (0) | 154.216.16.38 | A (IP address) | IN (0x0001) | false | ||
Nov 2, 2024 16:20:39.779053926 CET | 8.8.8.8 | 192.168.2.13 | 0xb5b0 | No error (0) | 162.213.35.24 | A (IP address) | IN (0x0001) | false | ||
Nov 2, 2024 16:20:39.779053926 CET | 8.8.8.8 | 192.168.2.13 | 0xb5b0 | No error (0) | 162.213.35.25 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 15:17:51 |
Start date (UTC): | 02/11/2024 |
Path: | /tmp/debug.dbg.elf |
Arguments: | /tmp/debug.dbg.elf |
File size: | 70832 bytes |
MD5 hash: | 5ebf5890d7d2c998b801d48b87667276 |
Start time (UTC): | 15:17:52 |
Start date (UTC): | 02/11/2024 |
Path: | /tmp/debug.dbg.elf |
Arguments: | - |
File size: | 70832 bytes |
MD5 hash: | 5ebf5890d7d2c998b801d48b87667276 |