Edit tour
Linux
Analysis Report
jwwofba5.elf
Overview
General Information
Sample name: | jwwofba5.elf |
Analysis ID: | 1558456 |
MD5: | 798a06eeac9f295ad3b307bbc01af5ef |
SHA1: | bdede057907147b420918d4247e1c9724937b91e |
SHA256: | 8dfd875aa504b3b7b67691ad0cf2ab2f96d30877e9b1eb998c0fda67d197cb89 |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Mirai
Score: | 80 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Sample deletes itself
Sends malformed DNS queries
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample tries to kill a process (SIGKILL)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1558456 |
Start date and time: | 2024-11-19 13:56:42 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 37s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | jwwofba5.elf |
Detection: | MAL |
Classification: | mal80.troj.evad.linELF@0/1@61/0 |
- VT rate limit hit for: jwwofba5.elf
Command: | /tmp/jwwofba5.elf |
PID: | 5461 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | about to cum inside a femboy btw |
Standard Error: |
- system is lnxubuntu20
- jwwofba5.elf New Fork (PID: 5464, Parent: 5461)
- jwwofba5.elf New Fork (PID: 5466, Parent: 5464)
- gnome-session-binary New Fork (PID: 5468, Parent: 1383)
- systemd New Fork (PID: 5473, Parent: 1)
- dash New Fork (PID: 5706, Parent: 3632)
- dash New Fork (PID: 5707, Parent: 3632)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Mirai | Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
|
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Source: | String: |
Networking |
---|
Source: | DNS traffic detected: |
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: |
Source: | .symtab present: |
Source: | SIGKILL sent: | Jump to behavior |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | Windows Management Instrumentation | 1 Scripting | Path Interception | 1 Hidden Files and Directories | 1 OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 11 File Deletion | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 2 Application Layer Protocol | Traffic Duplication | Data Destruction |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
55% | ReversingLabs | Linux.Trojan.Mirai | ||
100% | Avira | EXP/ELF.Mirai.Z.A |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
ksdjwi.eye-network.ru | 154.216.16.109 | true | false | high | |
ksdjwi.eye-network.ru. [malformed] | unknown | unknown | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
185.125.190.26 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
151.101.2.49 | unknown | United States | 54113 | FASTLYUS | false | |
154.216.16.109 | ksdjwi.eye-network.ru | Seychelles | 135357 | SKHT-ASShenzhenKatherineHengTechnologyInformationCo | false | |
89.190.156.145 | unknown | United Kingdom | 7489 | HOSTUS-GLOBAL-ASHostUSHK | false | |
34.243.160.129 | unknown | United States | 16509 | AMAZON-02US | false | |
54.247.62.1 | unknown | United States | 16509 | AMAZON-02US | false | |
151.101.66.49 | unknown | United States | 54113 | FASTLYUS | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
185.125.190.26 | Get hash | malicious | Mirai | Browse | ||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
151.101.2.49 | Get hash | malicious | Mirai | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | Amadey, Go Injector, LummaC Stealer, Phorpiex, PureLog Stealer, Stealc, Vidar | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
154.216.16.109 | Get hash | malicious | Mirai | Browse | ||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
89.190.156.145 | Get hash | malicious | Mirai | Browse | ||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
34.243.160.129 | Get hash | malicious | Mirai | Browse | ||
Get hash | malicious | Gafgyt | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
ksdjwi.eye-network.ru | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
HOSTUS-GLOBAL-ASHostUSHK | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
SKHT-ASShenzhenKatherineHengTechnologyInformationCo | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
CANONICAL-ASGB | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
FASTLYUS | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Credential Flusher | Browse |
| ||
Get hash | malicious | Credential Flusher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Credential Flusher | Browse |
| ||
Get hash | malicious | Credential Flusher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
Process: | /tmp/jwwofba5.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 28 |
Entropy (8bit): | 4.066108939837481 |
Encrypted: | false |
SSDEEP: | 3:TgkDHEf78HJN:TgKHEyJN |
MD5: | 1A6398985244FAE3C6FF7BC9F9F155F1 |
SHA1: | C61D992BA5CBF27E4840EAC967479914ED72DD66 |
SHA-256: | 3C89BEBA0D467433C41C7937E511207C90EFD2A201A3778A9D8ED19DA31A0560 |
SHA-512: | 8A80B92996E985EF7C1F475AF7C3D389B6C98F762586601F87D6F7D3EBE987D7ACFE02D27981943322C6BDA290170527E63938881716C66A32B8F482BF2E70CA |
Malicious: | false |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 5.60686658926047 |
TrID: |
|
File name: | jwwofba5.elf |
File size: | 158'464 bytes |
MD5: | 798a06eeac9f295ad3b307bbc01af5ef |
SHA1: | bdede057907147b420918d4247e1c9724937b91e |
SHA256: | 8dfd875aa504b3b7b67691ad0cf2ab2f96d30877e9b1eb998c0fda67d197cb89 |
SHA512: | 07da063492492386deb063c0a61bda0c87104ac12625e4f1201a19d948d04f07f3bb1b59b50912f17d00ead90fbe000059420ce23bac9ae19e44664223e140d2 |
SSDEEP: | 1536:e+zqnkngFHoIr+L9sr9MWcM5F22RjA7Tr4VLiNETDHjcF9U9aO10lAPP+UQldiUJ:e+zOOLUM2JRjw4w6fjcFCGSX+H4wL3 |
TLSH: | 8FF30945F8818F23C6D622BBFB5E428D372617A8D3EE72039D256F20379685B0E77542 |
File Content Preview: | .ELF...a..........(.........4...pi......4. ...(.......................................... ... ... ..0I..............Q.td..................................-...L."....z..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 158064 |
Section Header Size: | 40 |
Number of Section Headers: | 10 |
Header String Table Index: | 9 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x8094 | 0x94 | 0x18 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x80b0 | 0xb0 | 0x1eaa0 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x26b50 | 0x1eb50 | 0x14 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x26b64 | 0x1eb64 | 0x3090 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ctors | PROGBITS | 0x32000 | 0x22000 | 0xc | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x3200c | 0x2200c | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x32020 | 0x22020 | 0x4910 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.bss | NOBITS | 0x36930 | 0x26930 | 0x45c4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.shstrtab | STRTAB | 0x0 | 0x26930 | 0x3e | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8000 | 0x8000 | 0x21bf4 | 0x21bf4 | 6.0647 | 0x5 | R E | 0x8000 | .init .text .fini .rodata | |
LOAD | 0x22000 | 0x32000 | 0x32000 | 0x4930 | 0x8ef4 | 0.4245 | 0x6 | RW | 0x8000 | .ctors .dtors .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 19, 2024 13:57:25.626086950 CET | 43384 | 443 | 192.168.2.14 | 54.247.62.1 |
Nov 19, 2024 13:57:25.630059004 CET | 37616 | 443 | 192.168.2.14 | 151.101.66.49 |
Nov 19, 2024 13:57:25.993204117 CET | 56342 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:57:26.979739904 CET | 57248 | 7733 | 192.168.2.14 | 89.190.156.145 |
Nov 19, 2024 13:57:27.001965046 CET | 56342 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:57:27.993932962 CET | 57248 | 7733 | 192.168.2.14 | 89.190.156.145 |
Nov 19, 2024 13:57:29.018018007 CET | 56342 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:57:30.009938955 CET | 57248 | 7733 | 192.168.2.14 | 89.190.156.145 |
Nov 19, 2024 13:57:33.049784899 CET | 56342 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:57:34.073915958 CET | 57248 | 7733 | 192.168.2.14 | 89.190.156.145 |
Nov 19, 2024 13:57:36.121747017 CET | 46540 | 443 | 192.168.2.14 | 185.125.190.26 |
Nov 19, 2024 13:57:37.085717916 CET | 56346 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:57:38.105756998 CET | 56346 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:57:40.121720076 CET | 56346 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:57:42.265446901 CET | 57248 | 7733 | 192.168.2.14 | 89.190.156.145 |
Nov 19, 2024 13:57:44.313359976 CET | 56346 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:57:48.173998117 CET | 56348 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:57:49.177232027 CET | 56348 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:57:51.193027020 CET | 56348 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:57:54.226558924 CET | 42484 | 443 | 192.168.2.14 | 34.243.160.129 |
Nov 19, 2024 13:57:54.226624012 CET | 443 | 42484 | 34.243.160.129 | 192.168.2.14 |
Nov 19, 2024 13:57:54.226764917 CET | 42484 | 443 | 192.168.2.14 | 34.243.160.129 |
Nov 19, 2024 13:57:54.228576899 CET | 42484 | 443 | 192.168.2.14 | 34.243.160.129 |
Nov 19, 2024 13:57:54.228610039 CET | 443 | 42484 | 34.243.160.129 | 192.168.2.14 |
Nov 19, 2024 13:57:54.247632027 CET | 56178 | 443 | 192.168.2.14 | 151.101.2.49 |
Nov 19, 2024 13:57:54.247683048 CET | 443 | 56178 | 151.101.2.49 | 192.168.2.14 |
Nov 19, 2024 13:57:54.247761011 CET | 56178 | 443 | 192.168.2.14 | 151.101.2.49 |
Nov 19, 2024 13:57:54.248560905 CET | 56178 | 443 | 192.168.2.14 | 151.101.2.49 |
Nov 19, 2024 13:57:54.248574972 CET | 443 | 56178 | 151.101.2.49 | 192.168.2.14 |
Nov 19, 2024 13:57:55.320929050 CET | 56348 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:57:58.392729998 CET | 57248 | 7733 | 192.168.2.14 | 89.190.156.145 |
Nov 19, 2024 13:57:59.264292002 CET | 56354 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:58:00.280654907 CET | 56354 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:58:02.296658039 CET | 56354 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:58:06.328502893 CET | 56354 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:58:07.096483946 CET | 46540 | 443 | 192.168.2.14 | 185.125.190.26 |
Nov 19, 2024 13:58:10.353110075 CET | 56356 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:58:11.384160042 CET | 56356 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:58:13.400130987 CET | 56356 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:58:17.592082024 CET | 56356 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:58:21.444605112 CET | 56358 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:58:22.455751896 CET | 56358 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:58:24.471697092 CET | 56358 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:58:28.599445105 CET | 56358 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:58:31.671469927 CET | 57248 | 7733 | 192.168.2.14 | 89.190.156.145 |
Nov 19, 2024 13:58:32.537092924 CET | 56360 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:58:33.559257984 CET | 56360 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:58:35.575232983 CET | 56360 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:58:39.606997013 CET | 56360 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:58:43.641113043 CET | 56362 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:58:44.662868977 CET | 56362 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:58:46.678750992 CET | 56362 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:58:50.870646000 CET | 56362 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:58:54.224822044 CET | 42484 | 443 | 192.168.2.14 | 34.243.160.129 |
Nov 19, 2024 13:58:54.271344900 CET | 443 | 42484 | 34.243.160.129 | 192.168.2.14 |
Nov 19, 2024 13:58:54.302683115 CET | 56178 | 443 | 192.168.2.14 | 151.101.2.49 |
Nov 19, 2024 13:58:54.347342968 CET | 443 | 56178 | 151.101.2.49 | 192.168.2.14 |
Nov 19, 2024 13:58:54.731699944 CET | 56364 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:58:55.734314919 CET | 56364 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:58:57.750193119 CET | 56364 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:59:01.878046036 CET | 56364 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:59:05.820055008 CET | 56366 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:59:06.837987900 CET | 56366 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:59:08.853904009 CET | 56366 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:59:12.885689974 CET | 56366 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:59:16.898329020 CET | 56368 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:59:17.909411907 CET | 56368 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:59:19.925340891 CET | 56368 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:59:24.149167061 CET | 56368 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:59:27.986408949 CET | 56370 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:59:29.012916088 CET | 56370 | 33966 | 192.168.2.14 | 154.216.16.109 |
Nov 19, 2024 13:59:29.957545042 CET | 443 | 56178 | 151.101.2.49 | 192.168.2.14 |
Nov 19, 2024 13:59:29.957580090 CET | 443 | 42484 | 34.243.160.129 | 192.168.2.14 |
Nov 19, 2024 13:59:31.028858900 CET | 56370 | 33966 | 192.168.2.14 | 154.216.16.109 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 19, 2024 13:57:25.932662964 CET | 41517 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:25.943054914 CET | 53 | 41517 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:25.949552059 CET | 50811 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:25.956434965 CET | 53 | 50811 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:25.957555056 CET | 57245 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:25.963995934 CET | 53 | 57245 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:25.970510960 CET | 49804 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:25.976927042 CET | 53 | 49804 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:25.978100061 CET | 36573 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:25.984502077 CET | 53 | 36573 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:25.985960007 CET | 47905 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:25.992422104 CET | 53 | 47905 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:37.007927895 CET | 34408 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:37.014653921 CET | 53 | 34408 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:37.015758991 CET | 57407 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:37.022465944 CET | 53 | 57407 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:37.023482084 CET | 58576 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:37.029987097 CET | 53 | 58576 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:37.031101942 CET | 39344 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:37.037910938 CET | 53 | 39344 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:37.038908005 CET | 52237 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:37.045906067 CET | 53 | 52237 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:37.046976089 CET | 48456 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:37.053998947 CET | 53 | 48456 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:37.055036068 CET | 37665 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:37.061925888 CET | 53 | 37665 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:37.063080072 CET | 36407 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:37.070055962 CET | 53 | 36407 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:37.071171999 CET | 59747 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:37.077680111 CET | 53 | 59747 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:37.078551054 CET | 35035 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:37.085187912 CET | 53 | 35035 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:48.099483013 CET | 51542 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:48.105705023 CET | 53 | 51542 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:48.106618881 CET | 53196 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:48.112971067 CET | 53 | 53196 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:48.113903999 CET | 49583 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:48.120630026 CET | 53 | 49583 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:48.121604919 CET | 51965 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:48.128321886 CET | 53 | 51965 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:48.129245043 CET | 44321 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:48.135521889 CET | 53 | 44321 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:48.136497021 CET | 33914 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:48.142798901 CET | 53 | 33914 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:48.143979073 CET | 43950 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:48.150269032 CET | 53 | 43950 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:48.151699066 CET | 43278 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:48.158318996 CET | 53 | 43278 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:48.159491062 CET | 51744 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:48.166100025 CET | 53 | 51744 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:48.167000055 CET | 60483 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:48.173424959 CET | 53 | 60483 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:59.187302113 CET | 33585 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:59.193696022 CET | 53 | 33585 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:59.194994926 CET | 54332 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:59.201322079 CET | 53 | 54332 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:59.202433109 CET | 35429 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:59.208470106 CET | 53 | 35429 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:59.209523916 CET | 33123 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:59.216212988 CET | 53 | 33123 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:59.217870951 CET | 40578 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:59.224319935 CET | 53 | 40578 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:59.225943089 CET | 52477 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:59.232450962 CET | 53 | 52477 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:59.233967066 CET | 51438 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:59.240236044 CET | 53 | 51438 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:59.241655111 CET | 37182 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:59.248172045 CET | 53 | 37182 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:59.249706984 CET | 51712 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:59.256064892 CET | 53 | 51712 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:57:59.257487059 CET | 46767 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:57:59.263676882 CET | 53 | 46767 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:10.277554989 CET | 44410 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:10.283883095 CET | 53 | 44410 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:10.285069942 CET | 59311 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:10.291413069 CET | 53 | 59311 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:10.292566061 CET | 49349 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:10.298836946 CET | 53 | 49349 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:10.300087929 CET | 39502 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:10.306420088 CET | 53 | 39502 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:10.308835983 CET | 59705 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:10.314954042 CET | 53 | 59705 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:10.316205978 CET | 35050 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:10.322288036 CET | 53 | 35050 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:10.323383093 CET | 46142 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:10.329988956 CET | 53 | 46142 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:10.331084967 CET | 38897 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:10.337371111 CET | 53 | 38897 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:10.338556051 CET | 60905 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:10.344929934 CET | 53 | 60905 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:10.346013069 CET | 52212 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:10.352448940 CET | 53 | 52212 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:21.368235111 CET | 36792 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:21.374644995 CET | 53 | 36792 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:21.376173973 CET | 53178 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:21.382711887 CET | 53 | 53178 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:21.383753061 CET | 32776 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:21.390126944 CET | 53 | 32776 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:21.391168118 CET | 42628 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:21.397828102 CET | 53 | 42628 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:21.398830891 CET | 56772 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:21.405328989 CET | 53 | 56772 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:21.406636000 CET | 57988 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:21.412983894 CET | 53 | 57988 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:21.414196014 CET | 46477 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:21.420380116 CET | 53 | 46477 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:21.421613932 CET | 55492 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:21.428366899 CET | 53 | 55492 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:21.429728031 CET | 49156 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:21.436204910 CET | 53 | 49156 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:21.437566996 CET | 50508 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:21.444016933 CET | 53 | 50508 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:32.458359003 CET | 46565 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:32.464962959 CET | 53 | 46565 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:32.466526031 CET | 48965 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:32.473112106 CET | 53 | 48965 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:32.474817991 CET | 46638 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:32.481183052 CET | 53 | 46638 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:32.482718945 CET | 35689 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:32.489124060 CET | 53 | 35689 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:32.490247965 CET | 54808 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:32.496773005 CET | 53 | 54808 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:32.497920036 CET | 50456 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:32.504343987 CET | 53 | 50456 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:32.505682945 CET | 58578 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:32.511969090 CET | 53 | 58578 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:32.513438940 CET | 39197 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:32.520306110 CET | 53 | 39197 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:32.521743059 CET | 43892 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:32.528460979 CET | 53 | 43892 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:32.529679060 CET | 52872 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:32.536047935 CET | 53 | 52872 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:43.551450968 CET | 54460 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:43.557933092 CET | 53 | 54460 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:43.559767008 CET | 49620 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:43.571218014 CET | 53 | 49620 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:43.573658943 CET | 38123 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:43.580638885 CET | 53 | 38123 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:43.582967043 CET | 58254 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:43.589276075 CET | 53 | 58254 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:43.591170073 CET | 54954 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:43.597513914 CET | 53 | 54954 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:43.599039078 CET | 41885 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:43.605742931 CET | 53 | 41885 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:43.608453989 CET | 50106 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:43.615150928 CET | 53 | 50106 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:43.617013931 CET | 33034 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:43.623369932 CET | 53 | 33034 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:43.625154972 CET | 39179 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:43.631705046 CET | 53 | 39179 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:43.633388042 CET | 52636 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:43.640062094 CET | 53 | 52636 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:54.655411005 CET | 46616 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:54.661874056 CET | 53 | 46616 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:54.663466930 CET | 53680 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:54.669836044 CET | 53 | 53680 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:54.671483994 CET | 36688 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:54.678225994 CET | 53 | 36688 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:54.679698944 CET | 53696 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:54.685919046 CET | 53 | 53696 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:54.687179089 CET | 39356 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:54.693465948 CET | 53 | 39356 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:54.694606066 CET | 36158 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:54.700831890 CET | 53 | 36158 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:54.701966047 CET | 41119 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:54.708120108 CET | 53 | 41119 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:54.709273100 CET | 33761 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:54.715718031 CET | 53 | 33761 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:54.716993093 CET | 47786 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:54.723650932 CET | 53 | 47786 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:58:54.724775076 CET | 43149 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:58:54.731189966 CET | 53 | 43149 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:05.737339020 CET | 36848 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:05.743840933 CET | 53 | 36848 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:05.745193005 CET | 42632 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:05.751584053 CET | 53 | 42632 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:05.752695084 CET | 59681 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:05.759562969 CET | 53 | 59681 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:05.760662079 CET | 54540 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:05.767952919 CET | 53 | 54540 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:05.769057989 CET | 37498 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:05.775779963 CET | 53 | 37498 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:05.776825905 CET | 44886 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:05.783252001 CET | 53 | 44886 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:05.784873009 CET | 58451 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:05.798054934 CET | 53 | 58451 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:05.798913956 CET | 58188 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:05.805444956 CET | 53 | 58188 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:05.806245089 CET | 44251 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:05.812403917 CET | 53 | 44251 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:05.813184977 CET | 33188 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:05.819549084 CET | 53 | 33188 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:16.823235035 CET | 37046 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:16.830358982 CET | 53 | 37046 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:16.831485033 CET | 38150 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:16.838017941 CET | 53 | 38150 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:16.839128017 CET | 55277 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:16.846317053 CET | 53 | 55277 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:16.847361088 CET | 52267 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:16.853914976 CET | 53 | 52267 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:16.855047941 CET | 58022 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:16.861223936 CET | 53 | 58022 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:16.862375975 CET | 52894 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:16.868715048 CET | 53 | 52894 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:16.869774103 CET | 33592 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:16.876091957 CET | 53 | 33592 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:16.877031088 CET | 57999 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:16.883637905 CET | 53 | 57999 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:16.884407043 CET | 59742 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:16.890863895 CET | 53 | 59742 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:16.891624928 CET | 43499 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:16.897917032 CET | 53 | 43499 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:27.910440922 CET | 56146 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:27.916969061 CET | 53 | 56146 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:27.918435097 CET | 47903 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:27.925173044 CET | 53 | 47903 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:27.926312923 CET | 45324 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:27.932920933 CET | 53 | 45324 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:27.933736086 CET | 58563 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:27.940124989 CET | 53 | 58563 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:27.940850019 CET | 44313 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:27.947186947 CET | 53 | 44313 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:27.948266983 CET | 37504 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:27.955010891 CET | 53 | 37504 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:27.956005096 CET | 35537 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:27.964056969 CET | 53 | 35537 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:27.965104103 CET | 33447 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:27.971451998 CET | 53 | 33447 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:27.972446918 CET | 53479 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:27.978693962 CET | 53 | 53479 | 8.8.8.8 | 192.168.2.14 |
Nov 19, 2024 13:59:27.979321957 CET | 49775 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 19, 2024 13:59:27.985907078 CET | 53 | 49775 | 8.8.8.8 | 192.168.2.14 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 19, 2024 13:57:25.932662964 CET | 192.168.2.14 | 8.8.8.8 | 0x5fb7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 13:57:25.949552059 CET | 192.168.2.14 | 8.8.8.8 | 0x6a15 | Standard query (0) | 256 | 309 | false | |
Nov 19, 2024 13:57:25.957555056 CET | 192.168.2.14 | 8.8.8.8 | 0x6a15 | Standard query (0) | 256 | 309 | false | |
Nov 19, 2024 13:57:25.970510960 CET | 192.168.2.14 | 8.8.8.8 | 0x6a15 | Standard query (0) | 256 | 309 | false | |
Nov 19, 2024 13:57:25.978100061 CET | 192.168.2.14 | 8.8.8.8 | 0x6a15 | Standard query (0) | 256 | 309 | false | |
Nov 19, 2024 13:57:25.985960007 CET | 192.168.2.14 | 8.8.8.8 | 0x6a15 | Standard query (0) | 256 | 309 | false | |
Nov 19, 2024 13:57:37.046976089 CET | 192.168.2.14 | 8.8.8.8 | 0xb7e6 | Standard query (0) | 256 | 321 | false | |
Nov 19, 2024 13:57:37.055036068 CET | 192.168.2.14 | 8.8.8.8 | 0xb7e6 | Standard query (0) | 256 | 321 | false | |
Nov 19, 2024 13:57:37.063080072 CET | 192.168.2.14 | 8.8.8.8 | 0xb7e6 | Standard query (0) | 256 | 321 | false | |
Nov 19, 2024 13:57:37.071171999 CET | 192.168.2.14 | 8.8.8.8 | 0xb7e6 | Standard query (0) | 256 | 321 | false | |
Nov 19, 2024 13:57:37.078551054 CET | 192.168.2.14 | 8.8.8.8 | 0xb7e6 | Standard query (0) | 256 | 321 | false | |
Nov 19, 2024 13:57:48.136497021 CET | 192.168.2.14 | 8.8.8.8 | 0xba4a | Standard query (0) | 256 | 332 | false | |
Nov 19, 2024 13:57:48.143979073 CET | 192.168.2.14 | 8.8.8.8 | 0xba4a | Standard query (0) | 256 | 332 | false | |
Nov 19, 2024 13:57:48.151699066 CET | 192.168.2.14 | 8.8.8.8 | 0xba4a | Standard query (0) | 256 | 332 | false | |
Nov 19, 2024 13:57:48.159491062 CET | 192.168.2.14 | 8.8.8.8 | 0xba4a | Standard query (0) | 256 | 332 | false | |
Nov 19, 2024 13:57:48.167000055 CET | 192.168.2.14 | 8.8.8.8 | 0xba4a | Standard query (0) | 256 | 332 | false | |
Nov 19, 2024 13:57:59.225943089 CET | 192.168.2.14 | 8.8.8.8 | 0xd590 | Standard query (0) | 256 | 343 | false | |
Nov 19, 2024 13:57:59.233967066 CET | 192.168.2.14 | 8.8.8.8 | 0xd590 | Standard query (0) | 256 | 343 | false | |
Nov 19, 2024 13:57:59.241655111 CET | 192.168.2.14 | 8.8.8.8 | 0xd590 | Standard query (0) | 256 | 343 | false | |
Nov 19, 2024 13:57:59.249706984 CET | 192.168.2.14 | 8.8.8.8 | 0xd590 | Standard query (0) | 256 | 343 | false | |
Nov 19, 2024 13:57:59.257487059 CET | 192.168.2.14 | 8.8.8.8 | 0xd590 | Standard query (0) | 256 | 343 | false | |
Nov 19, 2024 13:58:10.316205978 CET | 192.168.2.14 | 8.8.8.8 | 0x2550 | Standard query (0) | 256 | 354 | false | |
Nov 19, 2024 13:58:10.323383093 CET | 192.168.2.14 | 8.8.8.8 | 0x2550 | Standard query (0) | 256 | 354 | false | |
Nov 19, 2024 13:58:10.331084967 CET | 192.168.2.14 | 8.8.8.8 | 0x2550 | Standard query (0) | 256 | 354 | false | |
Nov 19, 2024 13:58:10.338556051 CET | 192.168.2.14 | 8.8.8.8 | 0x2550 | Standard query (0) | 256 | 354 | false | |
Nov 19, 2024 13:58:10.346013069 CET | 192.168.2.14 | 8.8.8.8 | 0x2550 | Standard query (0) | 256 | 354 | false | |
Nov 19, 2024 13:58:21.406636000 CET | 192.168.2.14 | 8.8.8.8 | 0x86ca | Standard query (0) | 256 | 365 | false | |
Nov 19, 2024 13:58:21.414196014 CET | 192.168.2.14 | 8.8.8.8 | 0x86ca | Standard query (0) | 256 | 365 | false | |
Nov 19, 2024 13:58:21.421613932 CET | 192.168.2.14 | 8.8.8.8 | 0x86ca | Standard query (0) | 256 | 365 | false | |
Nov 19, 2024 13:58:21.429728031 CET | 192.168.2.14 | 8.8.8.8 | 0x86ca | Standard query (0) | 256 | 365 | false | |
Nov 19, 2024 13:58:21.437566996 CET | 192.168.2.14 | 8.8.8.8 | 0x86ca | Standard query (0) | 256 | 365 | false | |
Nov 19, 2024 13:58:32.497920036 CET | 192.168.2.14 | 8.8.8.8 | 0x5936 | Standard query (0) | 256 | 376 | false | |
Nov 19, 2024 13:58:32.505682945 CET | 192.168.2.14 | 8.8.8.8 | 0x5936 | Standard query (0) | 256 | 376 | false | |
Nov 19, 2024 13:58:32.513438940 CET | 192.168.2.14 | 8.8.8.8 | 0x5936 | Standard query (0) | 256 | 376 | false | |
Nov 19, 2024 13:58:32.521743059 CET | 192.168.2.14 | 8.8.8.8 | 0x5936 | Standard query (0) | 256 | 376 | false | |
Nov 19, 2024 13:58:32.529679060 CET | 192.168.2.14 | 8.8.8.8 | 0x5936 | Standard query (0) | 256 | 376 | false | |
Nov 19, 2024 13:58:43.599039078 CET | 192.168.2.14 | 8.8.8.8 | 0x5de1 | Standard query (0) | 256 | 387 | false | |
Nov 19, 2024 13:58:43.608453989 CET | 192.168.2.14 | 8.8.8.8 | 0x5de1 | Standard query (0) | 256 | 387 | false | |
Nov 19, 2024 13:58:43.617013931 CET | 192.168.2.14 | 8.8.8.8 | 0x5de1 | Standard query (0) | 256 | 387 | false | |
Nov 19, 2024 13:58:43.625154972 CET | 192.168.2.14 | 8.8.8.8 | 0x5de1 | Standard query (0) | 256 | 387 | false | |
Nov 19, 2024 13:58:43.633388042 CET | 192.168.2.14 | 8.8.8.8 | 0x5de1 | Standard query (0) | 256 | 387 | false | |
Nov 19, 2024 13:58:54.694606066 CET | 192.168.2.14 | 8.8.8.8 | 0x810c | Standard query (0) | 256 | 398 | false | |
Nov 19, 2024 13:58:54.701966047 CET | 192.168.2.14 | 8.8.8.8 | 0x810c | Standard query (0) | 256 | 398 | false | |
Nov 19, 2024 13:58:54.709273100 CET | 192.168.2.14 | 8.8.8.8 | 0x810c | Standard query (0) | 256 | 398 | false | |
Nov 19, 2024 13:58:54.716993093 CET | 192.168.2.14 | 8.8.8.8 | 0x810c | Standard query (0) | 256 | 398 | false | |
Nov 19, 2024 13:58:54.724775076 CET | 192.168.2.14 | 8.8.8.8 | 0x810c | Standard query (0) | 256 | 398 | false | |
Nov 19, 2024 13:59:05.776825905 CET | 192.168.2.14 | 8.8.8.8 | 0xbf15 | Standard query (0) | 256 | 409 | false | |
Nov 19, 2024 13:59:05.784873009 CET | 192.168.2.14 | 8.8.8.8 | 0xbf15 | Standard query (0) | 256 | 409 | false | |
Nov 19, 2024 13:59:05.798913956 CET | 192.168.2.14 | 8.8.8.8 | 0xbf15 | Standard query (0) | 256 | 409 | false | |
Nov 19, 2024 13:59:05.806245089 CET | 192.168.2.14 | 8.8.8.8 | 0xbf15 | Standard query (0) | 256 | 409 | false | |
Nov 19, 2024 13:59:05.813184977 CET | 192.168.2.14 | 8.8.8.8 | 0xbf15 | Standard query (0) | 256 | 409 | false | |
Nov 19, 2024 13:59:16.862375975 CET | 192.168.2.14 | 8.8.8.8 | 0x6ec0 | Standard query (0) | 256 | 420 | false | |
Nov 19, 2024 13:59:16.869774103 CET | 192.168.2.14 | 8.8.8.8 | 0x6ec0 | Standard query (0) | 256 | 420 | false | |
Nov 19, 2024 13:59:16.877031088 CET | 192.168.2.14 | 8.8.8.8 | 0x6ec0 | Standard query (0) | 256 | 420 | false | |
Nov 19, 2024 13:59:16.884407043 CET | 192.168.2.14 | 8.8.8.8 | 0x6ec0 | Standard query (0) | 256 | 420 | false | |
Nov 19, 2024 13:59:16.891624928 CET | 192.168.2.14 | 8.8.8.8 | 0x6ec0 | Standard query (0) | 256 | 420 | false | |
Nov 19, 2024 13:59:27.948266983 CET | 192.168.2.14 | 8.8.8.8 | 0x93cc | Standard query (0) | 256 | 431 | false | |
Nov 19, 2024 13:59:27.956005096 CET | 192.168.2.14 | 8.8.8.8 | 0x93cc | Standard query (0) | 256 | 431 | false | |
Nov 19, 2024 13:59:27.965104103 CET | 192.168.2.14 | 8.8.8.8 | 0x93cc | Standard query (0) | 256 | 431 | false | |
Nov 19, 2024 13:59:27.972446918 CET | 192.168.2.14 | 8.8.8.8 | 0x93cc | Standard query (0) | 256 | 431 | false | |
Nov 19, 2024 13:59:27.979321957 CET | 192.168.2.14 | 8.8.8.8 | 0x93cc | Standard query (0) | 256 | 431 | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 19, 2024 13:57:25.943054914 CET | 8.8.8.8 | 192.168.2.14 | 0x5fb7 | No error (0) | 154.216.16.109 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 12:57:25 |
Start date (UTC): | 19/11/2024 |
Path: | /tmp/jwwofba5.elf |
Arguments: | /tmp/jwwofba5.elf |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 12:57:25 |
Start date (UTC): | 19/11/2024 |
Path: | /tmp/jwwofba5.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 12:57:25 |
Start date (UTC): | 19/11/2024 |
Path: | /tmp/jwwofba5.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 12:57:26 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 12:57:26 |
Start date (UTC): | 19/11/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 12:57:26 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/libexec/gsd-rfkill |
Arguments: | /usr/libexec/gsd-rfkill |
File size: | 51808 bytes |
MD5 hash: | 88a16a3c0aba1759358c06215ecfb5cc |
Start time (UTC): | 12:57:27 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 12:57:27 |
Start date (UTC): | 19/11/2024 |
Path: | /lib/systemd/systemd-hostnamed |
Arguments: | /lib/systemd/systemd-hostnamed |
File size: | 35040 bytes |
MD5 hash: | 2cc8a5576629a2d5bd98e49a4b8bef65 |
Start time (UTC): | 12:58:53 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 12:58:53 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/bin/rm |
Arguments: | rm -f /tmp/tmp.5fzx02eP2K /tmp/tmp.pMcQBbaIQi /tmp/tmp.9KdLrORBCS |
File size: | 72056 bytes |
MD5 hash: | aa2b5496fdbfd88e38791ab81f90b95b |
Start time (UTC): | 12:58:53 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 12:58:53 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/bin/rm |
Arguments: | rm -f /tmp/tmp.5fzx02eP2K /tmp/tmp.pMcQBbaIQi /tmp/tmp.9KdLrORBCS |
File size: | 72056 bytes |
MD5 hash: | aa2b5496fdbfd88e38791ab81f90b95b |