Edit tour
Linux
Analysis Report
arm7.elf
Overview
General Information
Detection
Score: | 52 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1560463 |
Start date and time: | 2024-11-21 20:46:05 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 4s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | arm7.elf |
Detection: | MAL |
Classification: | mal52.troj.linELF@0/0@25/0 |
- VT rate limit hit for: arm7.elf
Command: | /tmp/arm7.elf |
PID: | 6217 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | you are now apart of hail cock botnet |
Standard Error: |
⊘No yara matches
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | ReversingLabs: |
Networking |
---|
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | .symtab present: |
Source: | Classification label: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | Direct Volume Access | 1 OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 2 Application Layer Protocol | Traffic Duplication | Data Destruction |
⊘No configs have been found
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
18% | ReversingLabs | Linux.Backdoor.Mirai |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
kingstonwikkerink.dyn | unknown | unknown | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
194.58.66.244 | unknown | Russian Federation | 2118 | RELCOM-ASRelcomGroup19022019RU | false | |
194.87.30.79 | unknown | Russian Federation | 2118 | RELCOM-ASRelcomGroup19022019RU | true | |
27.102.118.111 | unknown | Korea Republic of | 45996 | GNJ-AS-KRDAOUTECHNOLOGYKR | false | |
31.13.248.89 | unknown | Bulgaria | 34224 | NETERRA-ASBG | false | |
209.141.57.98 | unknown | United States | 53667 | PONYNETUS | true | |
195.133.53.106 | unknown | Russian Federation | 21453 | FLEX-ASRU | false | |
45.147.200.148 | unknown | Russian Federation | 51659 | ASBAXETRU | false | |
45.140.168.235 | unknown | Russian Federation | 51659 | ASBAXETRU | true | |
91.189.91.43 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
5.39.254.71 | unknown | United Kingdom | 30938 | ABSTATIONwwwabstationnetGB | false | |
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
107.189.8.204 | unknown | United States | 53667 | PONYNETUS | true | |
103.136.150.114 | unknown | Hong Kong | 46261 | QUICKPACKETUS | false | |
89.32.41.42 | unknown | Romania | 48874 | HOSTMAZEHOSTMAZERO | false | |
209.141.44.226 | unknown | United States | 53667 | PONYNETUS | true |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
194.58.66.244 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
194.87.30.79 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
209.141.57.98 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
195.133.53.106 | Get hash | malicious | Unknown | Browse | ||
27.102.118.111 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
31.13.248.89 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
45.147.200.148 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
45.140.168.235 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
91.189.91.43 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse |
⊘No context
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
NETERRA-ASBG | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | BruteRatel, Latrodectus | Browse |
| ||
Get hash | malicious | BruteRatel, Latrodectus | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
PONYNETUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
RELCOM-ASRelcomGroup19022019RU | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | GuLoader, Remcos | Browse |
| ||
Get hash | malicious | Quasar | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
GNJ-AS-KRDAOUTECHNOLOGYKR | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
RELCOM-ASRelcomGroup19022019RU | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | GuLoader, Remcos | Browse |
| ||
Get hash | malicious | Quasar | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 6.1541041301068855 |
TrID: |
|
File name: | arm7.elf |
File size: | 92'868 bytes |
MD5: | a4ee5e23e5da3a75937be4c88baa39bb |
SHA1: | 0b70f8502bc45e6d01a7445966adcadcc25adbf3 |
SHA256: | f53aac9bb8328931c4e27fa264461b34038611c2fe81f689aed9064f9385bf78 |
SHA512: | b121409c1f80cd31f6ac9b08f8d757f609476569bc09161cf854b3222256d43a18c078245947f9548a82fd3bef5982743434c3000a55401650beb331db7883f8 |
SSDEEP: | 1536:linyn5kYqWLn4pJjaJQFCdtqUjQll3wiCSNV9Qfq7ZbYHpIei:lLLnMJjaJQFCdtgoSNV9Qfq7ViIei |
TLSH: | 9993095AA9819F11D4C631FAFB9F414933136FB8E3FA7101D920AF6027CA9DB0E76512 |
File Content Preview: | .ELF..............(.........4....g......4. ...(........p.V..........................................4W..4W..............4W..4W..4W......8a..............8W..8W..8W..................Q.td..................................-...L..................@-.,@...0....S |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 5 |
Section Header Offset: | 92148 |
Section Header Size: | 40 |
Number of Section Headers: | 18 |
Header String Table Index: | 17 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x80d4 | 0xd4 | 0x10 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x80f0 | 0xf0 | 0x14174 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x1c264 | 0x14264 | 0x10 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x1c278 | 0x14278 | 0x138c | 0x0 | 0x2 | A | 0 | 0 | 8 |
.ARM.extab | PROGBITS | 0x1d604 | 0x15604 | 0x18 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ARM.exidx | ARM_EXIDX | 0x1d61c | 0x1561c | 0x118 | 0x0 | 0x82 | AL | 2 | 0 | 4 |
.eh_frame | PROGBITS | 0x25734 | 0x15734 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.tbss | NOBITS | 0x25738 | 0x15738 | 0x8 | 0x0 | 0x403 | WAT | 0 | 0 | 4 |
.init_array | INIT_ARRAY | 0x25738 | 0x15738 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.fini_array | FINI_ARRAY | 0x2573c | 0x1573c | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.jcr | PROGBITS | 0x25740 | 0x15740 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.got | PROGBITS | 0x25744 | 0x15744 | 0xac | 0x4 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x257f0 | 0x157f0 | 0x230 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x25a20 | 0x15a20 | 0x5e4c | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.comment | PROGBITS | 0x0 | 0x15a20 | 0xd2a | 0x0 | 0x0 | 0 | 0 | 1 | |
.ARM.attributes | ARM_ATTRIBUTES | 0x0 | 0x1674a | 0x16 | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0x16760 | 0x91 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
EXIDX | 0x1561c | 0x1d61c | 0x1d61c | 0x118 | 0x118 | 4.4888 | 0x4 | R | 0x4 | .ARM.exidx | |
LOAD | 0x0 | 0x8000 | 0x8000 | 0x15734 | 0x15734 | 6.1183 | 0x5 | R E | 0x8000 | .init .text .fini .rodata .ARM.extab .ARM.exidx | |
LOAD | 0x15734 | 0x25734 | 0x25734 | 0x2ec | 0x6138 | 4.1477 | 0x6 | RW | 0x8000 | .eh_frame .tbss .init_array .fini_array .jcr .got .data .bss | |
TLS | 0x15738 | 0x25738 | 0x25738 | 0x0 | 0x8 | 0.0000 | 0x4 | R | 0x4 | .tbss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 21, 2024 20:46:43.938210964 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Nov 21, 2024 20:46:44.740087986 CET | 38916 | 5578 | 192.168.2.23 | 27.102.118.111 |
Nov 21, 2024 20:46:44.862493038 CET | 5578 | 38916 | 27.102.118.111 | 192.168.2.23 |
Nov 21, 2024 20:46:44.863236904 CET | 38916 | 5578 | 192.168.2.23 | 27.102.118.111 |
Nov 21, 2024 20:46:44.863236904 CET | 38916 | 5578 | 192.168.2.23 | 27.102.118.111 |
Nov 21, 2024 20:46:44.987596035 CET | 5578 | 38916 | 27.102.118.111 | 192.168.2.23 |
Nov 21, 2024 20:46:44.990298033 CET | 38916 | 5578 | 192.168.2.23 | 27.102.118.111 |
Nov 21, 2024 20:46:45.113279104 CET | 5578 | 38916 | 27.102.118.111 | 192.168.2.23 |
Nov 21, 2024 20:46:46.747459888 CET | 5578 | 38916 | 27.102.118.111 | 192.168.2.23 |
Nov 21, 2024 20:46:46.747518063 CET | 38916 | 5578 | 192.168.2.23 | 27.102.118.111 |
Nov 21, 2024 20:46:46.747879028 CET | 38916 | 5578 | 192.168.2.23 | 27.102.118.111 |
Nov 21, 2024 20:46:49.565424919 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Nov 21, 2024 20:46:51.101296902 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Nov 21, 2024 20:46:51.983871937 CET | 59406 | 14356 | 192.168.2.23 | 45.140.168.235 |
Nov 21, 2024 20:46:52.104090929 CET | 14356 | 59406 | 45.140.168.235 | 192.168.2.23 |
Nov 21, 2024 20:46:52.104238987 CET | 59406 | 14356 | 192.168.2.23 | 45.140.168.235 |
Nov 21, 2024 20:46:52.104273081 CET | 59406 | 14356 | 192.168.2.23 | 45.140.168.235 |
Nov 21, 2024 20:46:52.223828077 CET | 14356 | 59406 | 45.140.168.235 | 192.168.2.23 |
Nov 21, 2024 20:46:52.224091053 CET | 59406 | 14356 | 192.168.2.23 | 45.140.168.235 |
Nov 21, 2024 20:46:52.345791101 CET | 14356 | 59406 | 45.140.168.235 | 192.168.2.23 |
Nov 21, 2024 20:46:54.038088083 CET | 14356 | 59406 | 45.140.168.235 | 192.168.2.23 |
Nov 21, 2024 20:46:54.038144112 CET | 59406 | 14356 | 192.168.2.23 | 45.140.168.235 |
Nov 21, 2024 20:46:54.038325071 CET | 59406 | 14356 | 192.168.2.23 | 45.140.168.235 |
Nov 21, 2024 20:46:59.284177065 CET | 58940 | 5166 | 192.168.2.23 | 194.58.66.244 |
Nov 21, 2024 20:46:59.403789997 CET | 5166 | 58940 | 194.58.66.244 | 192.168.2.23 |
Nov 21, 2024 20:46:59.403865099 CET | 58940 | 5166 | 192.168.2.23 | 194.58.66.244 |
Nov 21, 2024 20:46:59.403904915 CET | 58940 | 5166 | 192.168.2.23 | 194.58.66.244 |
Nov 21, 2024 20:46:59.523472071 CET | 5166 | 58940 | 194.58.66.244 | 192.168.2.23 |
Nov 21, 2024 20:46:59.523551941 CET | 58940 | 5166 | 192.168.2.23 | 194.58.66.244 |
Nov 21, 2024 20:46:59.643179893 CET | 5166 | 58940 | 194.58.66.244 | 192.168.2.23 |
Nov 21, 2024 20:47:01.037229061 CET | 5166 | 58940 | 194.58.66.244 | 192.168.2.23 |
Nov 21, 2024 20:47:01.037326097 CET | 58940 | 5166 | 192.168.2.23 | 194.58.66.244 |
Nov 21, 2024 20:47:01.037420988 CET | 58940 | 5166 | 192.168.2.23 | 194.58.66.244 |
Nov 21, 2024 20:47:04.411403894 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Nov 21, 2024 20:47:06.535001040 CET | 50526 | 7001 | 192.168.2.23 | 194.58.66.244 |
Nov 21, 2024 20:47:06.658566952 CET | 7001 | 50526 | 194.58.66.244 | 192.168.2.23 |
Nov 21, 2024 20:47:06.658695936 CET | 50526 | 7001 | 192.168.2.23 | 194.58.66.244 |
Nov 21, 2024 20:47:06.658695936 CET | 50526 | 7001 | 192.168.2.23 | 194.58.66.244 |
Nov 21, 2024 20:47:06.778347969 CET | 7001 | 50526 | 194.58.66.244 | 192.168.2.23 |
Nov 21, 2024 20:47:06.779340029 CET | 50526 | 7001 | 192.168.2.23 | 194.58.66.244 |
Nov 21, 2024 20:47:06.900391102 CET | 7001 | 50526 | 194.58.66.244 | 192.168.2.23 |
Nov 21, 2024 20:47:08.242638111 CET | 7001 | 50526 | 194.58.66.244 | 192.168.2.23 |
Nov 21, 2024 20:47:08.242696047 CET | 50526 | 7001 | 192.168.2.23 | 194.58.66.244 |
Nov 21, 2024 20:47:08.242750883 CET | 50526 | 7001 | 192.168.2.23 | 194.58.66.244 |
Nov 21, 2024 20:47:13.511145115 CET | 46140 | 17194 | 192.168.2.23 | 103.136.150.114 |
Nov 21, 2024 20:47:13.634115934 CET | 17194 | 46140 | 103.136.150.114 | 192.168.2.23 |
Nov 21, 2024 20:47:13.634212017 CET | 46140 | 17194 | 192.168.2.23 | 103.136.150.114 |
Nov 21, 2024 20:47:13.634280920 CET | 46140 | 17194 | 192.168.2.23 | 103.136.150.114 |
Nov 21, 2024 20:47:13.756162882 CET | 17194 | 46140 | 103.136.150.114 | 192.168.2.23 |
Nov 21, 2024 20:47:13.756340027 CET | 46140 | 17194 | 192.168.2.23 | 103.136.150.114 |
Nov 21, 2024 20:47:13.876621962 CET | 17194 | 46140 | 103.136.150.114 | 192.168.2.23 |
Nov 21, 2024 20:47:15.544671059 CET | 17194 | 46140 | 103.136.150.114 | 192.168.2.23 |
Nov 21, 2024 20:47:15.544797897 CET | 46140 | 17194 | 192.168.2.23 | 103.136.150.114 |
Nov 21, 2024 20:47:15.544856071 CET | 46140 | 17194 | 192.168.2.23 | 103.136.150.114 |
Nov 21, 2024 20:47:16.697663069 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Nov 21, 2024 20:47:20.793088913 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Nov 21, 2024 20:47:20.863040924 CET | 56060 | 9874 | 192.168.2.23 | 195.133.53.106 |
Nov 21, 2024 20:47:20.984445095 CET | 9874 | 56060 | 195.133.53.106 | 192.168.2.23 |
Nov 21, 2024 20:47:20.984533072 CET | 56060 | 9874 | 192.168.2.23 | 195.133.53.106 |
Nov 21, 2024 20:47:20.984596968 CET | 56060 | 9874 | 192.168.2.23 | 195.133.53.106 |
Nov 21, 2024 20:47:21.104471922 CET | 9874 | 56060 | 195.133.53.106 | 192.168.2.23 |
Nov 21, 2024 20:47:21.104562044 CET | 56060 | 9874 | 192.168.2.23 | 195.133.53.106 |
Nov 21, 2024 20:47:21.224613905 CET | 9874 | 56060 | 195.133.53.106 | 192.168.2.23 |
Nov 21, 2024 20:47:22.780486107 CET | 9874 | 56060 | 195.133.53.106 | 192.168.2.23 |
Nov 21, 2024 20:47:22.780548096 CET | 56060 | 9874 | 192.168.2.23 | 195.133.53.106 |
Nov 21, 2024 20:47:22.780637026 CET | 56060 | 9874 | 192.168.2.23 | 195.133.53.106 |
Nov 21, 2024 20:47:28.049092054 CET | 36300 | 12976 | 192.168.2.23 | 107.189.8.204 |
Nov 21, 2024 20:47:28.169338942 CET | 12976 | 36300 | 107.189.8.204 | 192.168.2.23 |
Nov 21, 2024 20:47:28.171155930 CET | 36300 | 12976 | 192.168.2.23 | 107.189.8.204 |
Nov 21, 2024 20:47:28.171233892 CET | 36300 | 12976 | 192.168.2.23 | 107.189.8.204 |
Nov 21, 2024 20:47:28.292221069 CET | 12976 | 36300 | 107.189.8.204 | 192.168.2.23 |
Nov 21, 2024 20:47:28.292336941 CET | 36300 | 12976 | 192.168.2.23 | 107.189.8.204 |
Nov 21, 2024 20:47:28.411884069 CET | 12976 | 36300 | 107.189.8.204 | 192.168.2.23 |
Nov 21, 2024 20:47:38.178930044 CET | 36300 | 12976 | 192.168.2.23 | 107.189.8.204 |
Nov 21, 2024 20:47:38.298475027 CET | 12976 | 36300 | 107.189.8.204 | 192.168.2.23 |
Nov 21, 2024 20:47:45.365740061 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Nov 21, 2024 20:47:50.136125088 CET | 12976 | 36300 | 107.189.8.204 | 192.168.2.23 |
Nov 21, 2024 20:47:50.136385918 CET | 36300 | 12976 | 192.168.2.23 | 107.189.8.204 |
Nov 21, 2024 20:47:50.256522894 CET | 12976 | 36300 | 107.189.8.204 | 192.168.2.23 |
Nov 21, 2024 20:47:55.418570042 CET | 37704 | 14153 | 192.168.2.23 | 31.13.248.89 |
Nov 21, 2024 20:47:55.540652990 CET | 14153 | 37704 | 31.13.248.89 | 192.168.2.23 |
Nov 21, 2024 20:47:55.540747881 CET | 37704 | 14153 | 192.168.2.23 | 31.13.248.89 |
Nov 21, 2024 20:47:55.540795088 CET | 37704 | 14153 | 192.168.2.23 | 31.13.248.89 |
Nov 21, 2024 20:47:55.662857056 CET | 14153 | 37704 | 31.13.248.89 | 192.168.2.23 |
Nov 21, 2024 20:47:55.663058043 CET | 37704 | 14153 | 192.168.2.23 | 31.13.248.89 |
Nov 21, 2024 20:47:55.789881945 CET | 14153 | 37704 | 31.13.248.89 | 192.168.2.23 |
Nov 21, 2024 20:47:57.834368944 CET | 14153 | 37704 | 31.13.248.89 | 192.168.2.23 |
Nov 21, 2024 20:47:57.834681034 CET | 37704 | 14153 | 192.168.2.23 | 31.13.248.89 |
Nov 21, 2024 20:47:57.954170942 CET | 14153 | 37704 | 31.13.248.89 | 192.168.2.23 |
Nov 21, 2024 20:48:03.106421947 CET | 51360 | 17729 | 192.168.2.23 | 194.87.30.79 |
Nov 21, 2024 20:48:03.225984097 CET | 17729 | 51360 | 194.87.30.79 | 192.168.2.23 |
Nov 21, 2024 20:48:03.226119041 CET | 51360 | 17729 | 192.168.2.23 | 194.87.30.79 |
Nov 21, 2024 20:48:03.226166010 CET | 51360 | 17729 | 192.168.2.23 | 194.87.30.79 |
Nov 21, 2024 20:48:03.345604897 CET | 17729 | 51360 | 194.87.30.79 | 192.168.2.23 |
Nov 21, 2024 20:48:03.345719099 CET | 51360 | 17729 | 192.168.2.23 | 194.87.30.79 |
Nov 21, 2024 20:48:03.466502905 CET | 17729 | 51360 | 194.87.30.79 | 192.168.2.23 |
Nov 21, 2024 20:48:04.900173903 CET | 17729 | 51360 | 194.87.30.79 | 192.168.2.23 |
Nov 21, 2024 20:48:04.900300980 CET | 51360 | 17729 | 192.168.2.23 | 194.87.30.79 |
Nov 21, 2024 20:48:04.900341988 CET | 51360 | 17729 | 192.168.2.23 | 194.87.30.79 |
Nov 21, 2024 20:48:10.151392937 CET | 42232 | 18450 | 192.168.2.23 | 209.141.44.226 |
Nov 21, 2024 20:48:10.277723074 CET | 18450 | 42232 | 209.141.44.226 | 192.168.2.23 |
Nov 21, 2024 20:48:10.277852058 CET | 42232 | 18450 | 192.168.2.23 | 209.141.44.226 |
Nov 21, 2024 20:48:10.277903080 CET | 42232 | 18450 | 192.168.2.23 | 209.141.44.226 |
Nov 21, 2024 20:48:10.397418976 CET | 18450 | 42232 | 209.141.44.226 | 192.168.2.23 |
Nov 21, 2024 20:48:10.397594929 CET | 42232 | 18450 | 192.168.2.23 | 209.141.44.226 |
Nov 21, 2024 20:48:10.517239094 CET | 18450 | 42232 | 209.141.44.226 | 192.168.2.23 |
Nov 21, 2024 20:48:32.262041092 CET | 18450 | 42232 | 209.141.44.226 | 192.168.2.23 |
Nov 21, 2024 20:48:32.262249947 CET | 42232 | 18450 | 192.168.2.23 | 209.141.44.226 |
Nov 21, 2024 20:48:32.381831884 CET | 18450 | 42232 | 209.141.44.226 | 192.168.2.23 |
Nov 21, 2024 20:48:37.508690119 CET | 41342 | 1991 | 192.168.2.23 | 89.32.41.42 |
Nov 21, 2024 20:48:37.634987116 CET | 1991 | 41342 | 89.32.41.42 | 192.168.2.23 |
Nov 21, 2024 20:48:37.635176897 CET | 41342 | 1991 | 192.168.2.23 | 89.32.41.42 |
Nov 21, 2024 20:48:37.635210037 CET | 41342 | 1991 | 192.168.2.23 | 89.32.41.42 |
Nov 21, 2024 20:48:37.761727095 CET | 1991 | 41342 | 89.32.41.42 | 192.168.2.23 |
Nov 21, 2024 20:48:37.761913061 CET | 41342 | 1991 | 192.168.2.23 | 89.32.41.42 |
Nov 21, 2024 20:48:37.881598949 CET | 1991 | 41342 | 89.32.41.42 | 192.168.2.23 |
Nov 21, 2024 20:48:39.941665888 CET | 1991 | 41342 | 89.32.41.42 | 192.168.2.23 |
Nov 21, 2024 20:48:39.942023993 CET | 41342 | 1991 | 192.168.2.23 | 89.32.41.42 |
Nov 21, 2024 20:48:40.063201904 CET | 1991 | 41342 | 89.32.41.42 | 192.168.2.23 |
Nov 21, 2024 20:48:45.260876894 CET | 51306 | 13669 | 192.168.2.23 | 209.141.57.98 |
Nov 21, 2024 20:48:45.381663084 CET | 13669 | 51306 | 209.141.57.98 | 192.168.2.23 |
Nov 21, 2024 20:48:45.381808996 CET | 51306 | 13669 | 192.168.2.23 | 209.141.57.98 |
Nov 21, 2024 20:48:45.381870985 CET | 51306 | 13669 | 192.168.2.23 | 209.141.57.98 |
Nov 21, 2024 20:48:45.502101898 CET | 13669 | 51306 | 209.141.57.98 | 192.168.2.23 |
Nov 21, 2024 20:48:45.502358913 CET | 51306 | 13669 | 192.168.2.23 | 209.141.57.98 |
Nov 21, 2024 20:48:45.625422955 CET | 13669 | 51306 | 209.141.57.98 | 192.168.2.23 |
Nov 21, 2024 20:49:07.331496000 CET | 13669 | 51306 | 209.141.57.98 | 192.168.2.23 |
Nov 21, 2024 20:49:07.331804037 CET | 51306 | 13669 | 192.168.2.23 | 209.141.57.98 |
Nov 21, 2024 20:49:07.454096079 CET | 13669 | 51306 | 209.141.57.98 | 192.168.2.23 |
Nov 21, 2024 20:49:12.597341061 CET | 49530 | 13476 | 192.168.2.23 | 27.102.118.111 |
Nov 21, 2024 20:49:12.723886967 CET | 13476 | 49530 | 27.102.118.111 | 192.168.2.23 |
Nov 21, 2024 20:49:12.724021912 CET | 49530 | 13476 | 192.168.2.23 | 27.102.118.111 |
Nov 21, 2024 20:49:12.724123955 CET | 49530 | 13476 | 192.168.2.23 | 27.102.118.111 |
Nov 21, 2024 20:49:12.846539021 CET | 13476 | 49530 | 27.102.118.111 | 192.168.2.23 |
Nov 21, 2024 20:49:12.846774101 CET | 49530 | 13476 | 192.168.2.23 | 27.102.118.111 |
Nov 21, 2024 20:49:12.966388941 CET | 13476 | 49530 | 27.102.118.111 | 192.168.2.23 |
Nov 21, 2024 20:49:14.545866013 CET | 13476 | 49530 | 27.102.118.111 | 192.168.2.23 |
Nov 21, 2024 20:49:14.546072006 CET | 49530 | 13476 | 192.168.2.23 | 27.102.118.111 |
Nov 21, 2024 20:49:14.546072006 CET | 49530 | 13476 | 192.168.2.23 | 27.102.118.111 |
Nov 21, 2024 20:49:19.795555115 CET | 47824 | 2922 | 192.168.2.23 | 45.140.168.235 |
Nov 21, 2024 20:49:19.915561914 CET | 2922 | 47824 | 45.140.168.235 | 192.168.2.23 |
Nov 21, 2024 20:49:19.915787935 CET | 47824 | 2922 | 192.168.2.23 | 45.140.168.235 |
Nov 21, 2024 20:49:19.915836096 CET | 47824 | 2922 | 192.168.2.23 | 45.140.168.235 |
Nov 21, 2024 20:49:20.039669991 CET | 2922 | 47824 | 45.140.168.235 | 192.168.2.23 |
Nov 21, 2024 20:49:20.039815903 CET | 47824 | 2922 | 192.168.2.23 | 45.140.168.235 |
Nov 21, 2024 20:49:20.159466982 CET | 2922 | 47824 | 45.140.168.235 | 192.168.2.23 |
Nov 21, 2024 20:49:21.621968031 CET | 2922 | 47824 | 45.140.168.235 | 192.168.2.23 |
Nov 21, 2024 20:49:21.622148037 CET | 47824 | 2922 | 192.168.2.23 | 45.140.168.235 |
Nov 21, 2024 20:49:21.622210026 CET | 47824 | 2922 | 192.168.2.23 | 45.140.168.235 |
Nov 21, 2024 20:49:27.010014057 CET | 38056 | 13340 | 192.168.2.23 | 45.147.200.148 |
Nov 21, 2024 20:49:27.129605055 CET | 13340 | 38056 | 45.147.200.148 | 192.168.2.23 |
Nov 21, 2024 20:49:27.129756927 CET | 38056 | 13340 | 192.168.2.23 | 45.147.200.148 |
Nov 21, 2024 20:49:27.129846096 CET | 38056 | 13340 | 192.168.2.23 | 45.147.200.148 |
Nov 21, 2024 20:49:27.249469042 CET | 13340 | 38056 | 45.147.200.148 | 192.168.2.23 |
Nov 21, 2024 20:49:27.249699116 CET | 38056 | 13340 | 192.168.2.23 | 45.147.200.148 |
Nov 21, 2024 20:49:27.370317936 CET | 13340 | 38056 | 45.147.200.148 | 192.168.2.23 |
Nov 21, 2024 20:49:28.882361889 CET | 13340 | 38056 | 45.147.200.148 | 192.168.2.23 |
Nov 21, 2024 20:49:28.882764101 CET | 38056 | 13340 | 192.168.2.23 | 45.147.200.148 |
Nov 21, 2024 20:49:28.882850885 CET | 38056 | 13340 | 192.168.2.23 | 45.147.200.148 |
Nov 21, 2024 20:49:34.810142994 CET | 43428 | 2097 | 192.168.2.23 | 5.39.254.71 |
Nov 21, 2024 20:49:35.052398920 CET | 2097 | 43428 | 5.39.254.71 | 192.168.2.23 |
Nov 21, 2024 20:49:35.052681923 CET | 43428 | 2097 | 192.168.2.23 | 5.39.254.71 |
Nov 21, 2024 20:49:35.052766085 CET | 43428 | 2097 | 192.168.2.23 | 5.39.254.71 |
Nov 21, 2024 20:49:35.173093081 CET | 2097 | 43428 | 5.39.254.71 | 192.168.2.23 |
Nov 21, 2024 20:49:35.173422098 CET | 43428 | 2097 | 192.168.2.23 | 5.39.254.71 |
Nov 21, 2024 20:49:35.293082952 CET | 2097 | 43428 | 5.39.254.71 | 192.168.2.23 |
Nov 21, 2024 20:49:36.536139011 CET | 2097 | 43428 | 5.39.254.71 | 192.168.2.23 |
Nov 21, 2024 20:49:36.536345959 CET | 43428 | 2097 | 192.168.2.23 | 5.39.254.71 |
Nov 21, 2024 20:49:36.536407948 CET | 43428 | 2097 | 192.168.2.23 | 5.39.254.71 |
Nov 21, 2024 20:49:42.549246073 CET | 46908 | 1698 | 192.168.2.23 | 209.141.57.98 |
Nov 21, 2024 20:49:42.669884920 CET | 1698 | 46908 | 209.141.57.98 | 192.168.2.23 |
Nov 21, 2024 20:49:42.670208931 CET | 46908 | 1698 | 192.168.2.23 | 209.141.57.98 |
Nov 21, 2024 20:49:42.670324087 CET | 46908 | 1698 | 192.168.2.23 | 209.141.57.98 |
Nov 21, 2024 20:49:42.790220976 CET | 1698 | 46908 | 209.141.57.98 | 192.168.2.23 |
Nov 21, 2024 20:49:42.790385962 CET | 46908 | 1698 | 192.168.2.23 | 209.141.57.98 |
Nov 21, 2024 20:49:42.910134077 CET | 1698 | 46908 | 209.141.57.98 | 192.168.2.23 |
Nov 21, 2024 20:50:04.654542923 CET | 1698 | 46908 | 209.141.57.98 | 192.168.2.23 |
Nov 21, 2024 20:50:04.654769897 CET | 46908 | 1698 | 192.168.2.23 | 209.141.57.98 |
Nov 21, 2024 20:50:04.779032946 CET | 1698 | 46908 | 209.141.57.98 | 192.168.2.23 |
Nov 21, 2024 20:50:09.986815929 CET | 59166 | 13967 | 192.168.2.23 | 194.87.30.79 |
Nov 21, 2024 20:50:10.109184980 CET | 13967 | 59166 | 194.87.30.79 | 192.168.2.23 |
Nov 21, 2024 20:50:10.109319925 CET | 59166 | 13967 | 192.168.2.23 | 194.87.30.79 |
Nov 21, 2024 20:50:10.109381914 CET | 59166 | 13967 | 192.168.2.23 | 194.87.30.79 |
Nov 21, 2024 20:50:10.229032040 CET | 13967 | 59166 | 194.87.30.79 | 192.168.2.23 |
Nov 21, 2024 20:50:10.229188919 CET | 59166 | 13967 | 192.168.2.23 | 194.87.30.79 |
Nov 21, 2024 20:50:10.348665953 CET | 13967 | 59166 | 194.87.30.79 | 192.168.2.23 |
Nov 21, 2024 20:50:11.660240889 CET | 13967 | 59166 | 194.87.30.79 | 192.168.2.23 |
Nov 21, 2024 20:50:11.660408020 CET | 59166 | 13967 | 192.168.2.23 | 194.87.30.79 |
Nov 21, 2024 20:50:11.660667896 CET | 59166 | 13967 | 192.168.2.23 | 194.87.30.79 |
Nov 21, 2024 20:50:16.898613930 CET | 34832 | 4618 | 192.168.2.23 | 194.87.30.79 |
Nov 21, 2024 20:50:17.018333912 CET | 4618 | 34832 | 194.87.30.79 | 192.168.2.23 |
Nov 21, 2024 20:50:17.018496037 CET | 34832 | 4618 | 192.168.2.23 | 194.87.30.79 |
Nov 21, 2024 20:50:17.018517017 CET | 34832 | 4618 | 192.168.2.23 | 194.87.30.79 |
Nov 21, 2024 20:50:17.139730930 CET | 4618 | 34832 | 194.87.30.79 | 192.168.2.23 |
Nov 21, 2024 20:50:17.139884949 CET | 34832 | 4618 | 192.168.2.23 | 194.87.30.79 |
Nov 21, 2024 20:50:17.261167049 CET | 4618 | 34832 | 194.87.30.79 | 192.168.2.23 |
Nov 21, 2024 20:50:18.551860094 CET | 4618 | 34832 | 194.87.30.79 | 192.168.2.23 |
Nov 21, 2024 20:50:18.552031040 CET | 34832 | 4618 | 192.168.2.23 | 194.87.30.79 |
Nov 21, 2024 20:50:18.552073956 CET | 34832 | 4618 | 192.168.2.23 | 194.87.30.79 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 21, 2024 20:46:44.207473040 CET | 60099 | 53 | 192.168.2.23 | 194.36.144.87 |
Nov 21, 2024 20:46:44.331943989 CET | 36743 | 53 | 192.168.2.23 | 194.36.144.87 |
Nov 21, 2024 20:46:44.451518059 CET | 53 | 60099 | 194.36.144.87 | 192.168.2.23 |
Nov 21, 2024 20:46:44.463968992 CET | 43687 | 53 | 192.168.2.23 | 109.91.184.21 |
Nov 21, 2024 20:46:44.572753906 CET | 53 | 36743 | 194.36.144.87 | 192.168.2.23 |
Nov 21, 2024 20:46:44.737740040 CET | 53 | 43687 | 109.91.184.21 | 192.168.2.23 |
Nov 21, 2024 20:46:51.751364946 CET | 36587 | 53 | 192.168.2.23 | 213.202.211.221 |
Nov 21, 2024 20:46:51.982695103 CET | 53 | 36587 | 213.202.211.221 | 192.168.2.23 |
Nov 21, 2024 20:46:59.040604115 CET | 43833 | 53 | 192.168.2.23 | 81.169.136.222 |
Nov 21, 2024 20:46:59.283739090 CET | 53 | 43833 | 81.169.136.222 | 192.168.2.23 |
Nov 21, 2024 20:47:06.038440943 CET | 48447 | 53 | 192.168.2.23 | 81.169.136.222 |
Nov 21, 2024 20:47:06.534265995 CET | 53 | 48447 | 81.169.136.222 | 192.168.2.23 |
Nov 21, 2024 20:47:13.243944883 CET | 38817 | 53 | 192.168.2.23 | 109.91.184.21 |
Nov 21, 2024 20:47:13.510267973 CET | 53 | 38817 | 109.91.184.21 | 192.168.2.23 |
Nov 21, 2024 20:47:20.547173977 CET | 42531 | 53 | 192.168.2.23 | 168.235.111.72 |
Nov 21, 2024 20:47:20.862314939 CET | 53 | 42531 | 168.235.111.72 | 192.168.2.23 |
Nov 21, 2024 20:47:27.784137964 CET | 44463 | 53 | 192.168.2.23 | 185.181.61.24 |
Nov 21, 2024 20:47:28.048016071 CET | 53 | 44463 | 185.181.61.24 | 192.168.2.23 |
Nov 21, 2024 20:47:55.139234066 CET | 40699 | 53 | 192.168.2.23 | 109.91.184.21 |
Nov 21, 2024 20:47:55.417298079 CET | 53 | 40699 | 109.91.184.21 | 192.168.2.23 |
Nov 21, 2024 20:48:02.836620092 CET | 46660 | 53 | 192.168.2.23 | 213.202.211.221 |
Nov 21, 2024 20:48:03.105393887 CET | 53 | 46660 | 213.202.211.221 | 192.168.2.23 |
Nov 21, 2024 20:48:09.902179956 CET | 43865 | 53 | 192.168.2.23 | 217.160.70.42 |
Nov 21, 2024 20:48:10.150630951 CET | 53 | 43865 | 217.160.70.42 | 192.168.2.23 |
Nov 21, 2024 20:48:37.264369965 CET | 41533 | 53 | 192.168.2.23 | 202.61.197.122 |
Nov 21, 2024 20:48:37.507545948 CET | 53 | 41533 | 202.61.197.122 | 192.168.2.23 |
Nov 21, 2024 20:48:44.943630934 CET | 58552 | 53 | 192.168.2.23 | 168.235.111.72 |
Nov 21, 2024 20:48:45.259891987 CET | 53 | 58552 | 168.235.111.72 | 192.168.2.23 |
Nov 21, 2024 20:49:12.335091114 CET | 57237 | 53 | 192.168.2.23 | 185.181.61.24 |
Nov 21, 2024 20:49:12.596268892 CET | 53 | 57237 | 185.181.61.24 | 192.168.2.23 |
Nov 21, 2024 20:49:19.548373938 CET | 58542 | 53 | 192.168.2.23 | 202.61.197.122 |
Nov 21, 2024 20:49:19.794495106 CET | 53 | 58542 | 202.61.197.122 | 192.168.2.23 |
Nov 21, 2024 20:49:26.624870062 CET | 54624 | 53 | 192.168.2.23 | 109.91.184.21 |
Nov 21, 2024 20:49:27.008651972 CET | 53 | 54624 | 109.91.184.21 | 192.168.2.23 |
Nov 21, 2024 20:49:33.885698080 CET | 44592 | 53 | 192.168.2.23 | 152.53.15.127 |
Nov 21, 2024 20:49:34.136116028 CET | 53 | 44592 | 152.53.15.127 | 192.168.2.23 |
Nov 21, 2024 20:49:34.137710094 CET | 45031 | 53 | 192.168.2.23 | 152.53.15.127 |
Nov 21, 2024 20:49:34.388164997 CET | 53 | 45031 | 152.53.15.127 | 192.168.2.23 |
Nov 21, 2024 20:49:34.389619112 CET | 45310 | 53 | 192.168.2.23 | 168.138.12.137 |
Nov 21, 2024 20:49:34.809082985 CET | 53 | 45310 | 168.138.12.137 | 192.168.2.23 |
Nov 21, 2024 20:49:41.538431883 CET | 37910 | 53 | 192.168.2.23 | 194.36.144.87 |
Nov 21, 2024 20:49:41.812252998 CET | 53 | 37910 | 194.36.144.87 | 192.168.2.23 |
Nov 21, 2024 20:49:41.813592911 CET | 54942 | 53 | 192.168.2.23 | 152.53.15.127 |
Nov 21, 2024 20:49:42.061131954 CET | 53 | 54942 | 152.53.15.127 | 192.168.2.23 |
Nov 21, 2024 20:49:42.062875032 CET | 47575 | 53 | 192.168.2.23 | 51.158.108.203 |
Nov 21, 2024 20:49:42.302182913 CET | 53 | 47575 | 51.158.108.203 | 192.168.2.23 |
Nov 21, 2024 20:49:42.303977966 CET | 53680 | 53 | 192.168.2.23 | 217.160.70.42 |
Nov 21, 2024 20:49:42.547885895 CET | 53 | 53680 | 217.160.70.42 | 192.168.2.23 |
Nov 21, 2024 20:50:09.657529116 CET | 43520 | 53 | 192.168.2.23 | 80.152.203.134 |
Nov 21, 2024 20:50:09.985671997 CET | 53 | 43520 | 80.152.203.134 | 192.168.2.23 |
Nov 21, 2024 20:50:16.661995888 CET | 34982 | 53 | 192.168.2.23 | 213.202.211.221 |
Nov 21, 2024 20:50:16.897610903 CET | 53 | 34982 | 213.202.211.221 | 192.168.2.23 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 21, 2024 20:46:44.207473040 CET | 192.168.2.23 | 194.36.144.87 | 0x103e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 21, 2024 20:46:44.463968992 CET | 192.168.2.23 | 109.91.184.21 | 0xbb0c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 21, 2024 20:46:51.751364946 CET | 192.168.2.23 | 213.202.211.221 | 0x5d82 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 21, 2024 20:46:59.040604115 CET | 192.168.2.23 | 81.169.136.222 | 0xc15f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 21, 2024 20:47:06.038440943 CET | 192.168.2.23 | 81.169.136.222 | 0xbfc3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 21, 2024 20:47:13.243944883 CET | 192.168.2.23 | 109.91.184.21 | 0xb542 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 21, 2024 20:47:20.547173977 CET | 192.168.2.23 | 168.235.111.72 | 0x8769 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 21, 2024 20:47:27.784137964 CET | 192.168.2.23 | 185.181.61.24 | 0xb806 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 21, 2024 20:47:55.139234066 CET | 192.168.2.23 | 109.91.184.21 | 0xc68b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 21, 2024 20:48:02.836620092 CET | 192.168.2.23 | 213.202.211.221 | 0x71bc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 21, 2024 20:48:09.902179956 CET | 192.168.2.23 | 217.160.70.42 | 0x4ef5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 21, 2024 20:48:37.264369965 CET | 192.168.2.23 | 202.61.197.122 | 0x315 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 21, 2024 20:48:44.943630934 CET | 192.168.2.23 | 168.235.111.72 | 0x3f69 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 21, 2024 20:49:12.335091114 CET | 192.168.2.23 | 185.181.61.24 | 0x1aea | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 21, 2024 20:49:19.548373938 CET | 192.168.2.23 | 202.61.197.122 | 0x8750 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 21, 2024 20:49:26.624870062 CET | 192.168.2.23 | 109.91.184.21 | 0xeb4f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 21, 2024 20:49:33.885698080 CET | 192.168.2.23 | 152.53.15.127 | 0x91ea | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 21, 2024 20:49:34.137710094 CET | 192.168.2.23 | 152.53.15.127 | 0xb1df | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 21, 2024 20:49:34.389619112 CET | 192.168.2.23 | 168.138.12.137 | 0xcb42 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 21, 2024 20:49:41.538431883 CET | 192.168.2.23 | 194.36.144.87 | 0xe87d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 21, 2024 20:49:41.813592911 CET | 192.168.2.23 | 152.53.15.127 | 0x62e5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 21, 2024 20:49:42.062875032 CET | 192.168.2.23 | 51.158.108.203 | 0xed6c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 21, 2024 20:49:42.303977966 CET | 192.168.2.23 | 217.160.70.42 | 0xd2b4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 21, 2024 20:50:09.657529116 CET | 192.168.2.23 | 80.152.203.134 | 0xf171 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 21, 2024 20:50:16.661995888 CET | 192.168.2.23 | 213.202.211.221 | 0xdfc9 | Standard query (0) | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 19:46:43 |
Start date (UTC): | 21/11/2024 |
Path: | /tmp/arm7.elf |
Arguments: | /tmp/arm7.elf |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 19:46:43 |
Start date (UTC): | 21/11/2024 |
Path: | /tmp/arm7.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 19:46:43 |
Start date (UTC): | 21/11/2024 |
Path: | /tmp/arm7.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 19:46:43 |
Start date (UTC): | 21/11/2024 |
Path: | /tmp/arm7.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 19:46:43 |
Start date (UTC): | 21/11/2024 |
Path: | /tmp/arm7.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 19:46:43 |
Start date (UTC): | 21/11/2024 |
Path: | /tmp/arm7.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |