Edit tour
Linux
Analysis Report
arm.elf
Overview
General Information
Detection
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Sample reads /proc/mounts (often used for finding a writable filesystem)
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1564144 |
Start date and time: | 2024-11-27 22:02:09 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 53s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | arm.elf |
Detection: | MAL |
Classification: | mal56.troj.linELF@0/0@5/0 |
- VT rate limit hit for: arm.elf
Command: | /tmp/arm.elf |
PID: | 5522 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | I jun ok ter my cats, man. |
Standard Error: |
⊘No yara matches
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | ReversingLabs: |
Networking |
---|
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | .symtab present: |
Source: | Classification label: |
Persistence and Installation Behavior |
---|
Source: | File: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | Direct Volume Access | 1 OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Non-Standard Port | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | 1 File and Directory Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
13% | ReversingLabs | Linux.Backdoor.Mirai |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
daisy.ubuntu.com | 162.213.35.24 | true | false | high | |
catvision.dyn | unknown | unknown | false | unknown | |
hikvision.geek | unknown | unknown | false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
185.22.155.213 | unknown | Russian Federation | 51659 | ASBAXETRU | false | |
195.133.53.106 | unknown | Russian Federation | 21453 | FLEX-ASRU | true |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
185.22.155.213 | Get hash | malicious | Unknown | Browse | ||
195.133.53.106 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
daisy.ubuntu.com | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Xmrig | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
ASBAXETRU | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | FormBook, PureLog Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
FLEX-ASRU | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 6.057791807124935 |
TrID: |
|
File name: | arm.elf |
File size: | 65'844 bytes |
MD5: | 672e5e2fe024d48bd7b078636e2c8dc7 |
SHA1: | f0336d57682eb36954597b3b4d2dfd198dd7ccff |
SHA256: | 789b111acdd4db48bfa20b404e744aeec665e97a4763a7f32d8e90dcfa01e399 |
SHA512: | 237557a9a60da815e105cc966127df3456dd1ed773a046598c0580acd8c642c27c270e3f0948ed3a17f873e1225fad0f00fe9d013ba617e02bf1755738dda589 |
SSDEEP: | 1536:3ov7//j4KL90s5JbUhElmvBpg190yzvqyD:Wb/020eJbUWKwq |
TLSH: | 9E533A85BD819713C6C122BBFB1E42CD7B2613A8D2EE32039E156F21378796B0E7B551 |
File Content Preview: | .ELF...a..........(.........4...........4. ...(..........................................................T..........Q.td..................................-...L."...L9..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 65444 |
Section Header Size: | 40 |
Number of Section Headers: | 10 |
Header String Table Index: | 9 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x8094 | 0x94 | 0x18 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x80b0 | 0xb0 | 0xe568 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x16618 | 0xe618 | 0x14 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x1662c | 0xe62c | 0x1590 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ctors | PROGBITS | 0x1fbc0 | 0xfbc0 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x1fbc8 | 0xfbc8 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x1fbd4 | 0xfbd4 | 0x390 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x1ff64 | 0xff64 | 0x5064 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.shstrtab | STRTAB | 0x0 | 0xff64 | 0x3e | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8000 | 0x8000 | 0xfbbc | 0xfbbc | 6.0934 | 0x5 | R E | 0x8000 | .init .text .fini .rodata | |
LOAD | 0xfbc0 | 0x1fbc0 | 0x1fbc0 | 0x3a4 | 0x5408 | 2.8570 | 0x6 | RW | 0x8000 | .ctors .dtors .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 27, 2024 22:02:58.036921978 CET | 44480 | 21736 | 192.168.2.15 | 195.133.53.106 |
Nov 27, 2024 22:02:58.159663916 CET | 21736 | 44480 | 195.133.53.106 | 192.168.2.15 |
Nov 27, 2024 22:02:58.159787893 CET | 44480 | 21736 | 192.168.2.15 | 195.133.53.106 |
Nov 27, 2024 22:02:58.159993887 CET | 44480 | 21736 | 192.168.2.15 | 195.133.53.106 |
Nov 27, 2024 22:02:58.281296015 CET | 21736 | 44480 | 195.133.53.106 | 192.168.2.15 |
Nov 27, 2024 22:02:58.281377077 CET | 44480 | 21736 | 192.168.2.15 | 195.133.53.106 |
Nov 27, 2024 22:02:58.401309967 CET | 21736 | 44480 | 195.133.53.106 | 192.168.2.15 |
Nov 27, 2024 22:03:00.038387060 CET | 21736 | 44480 | 195.133.53.106 | 192.168.2.15 |
Nov 27, 2024 22:03:00.038487911 CET | 44480 | 21736 | 192.168.2.15 | 195.133.53.106 |
Nov 27, 2024 22:03:00.038659096 CET | 44480 | 21736 | 192.168.2.15 | 195.133.53.106 |
Nov 27, 2024 22:03:05.308670044 CET | 34106 | 1985 | 192.168.2.15 | 185.22.155.213 |
Nov 27, 2024 22:03:05.429374933 CET | 1985 | 34106 | 185.22.155.213 | 192.168.2.15 |
Nov 27, 2024 22:03:05.429450035 CET | 34106 | 1985 | 192.168.2.15 | 185.22.155.213 |
Nov 27, 2024 22:03:05.429476976 CET | 34106 | 1985 | 192.168.2.15 | 185.22.155.213 |
Nov 27, 2024 22:03:05.549565077 CET | 1985 | 34106 | 185.22.155.213 | 192.168.2.15 |
Nov 27, 2024 22:03:05.549603939 CET | 34106 | 1985 | 192.168.2.15 | 185.22.155.213 |
Nov 27, 2024 22:03:05.669569016 CET | 1985 | 34106 | 185.22.155.213 | 192.168.2.15 |
Nov 27, 2024 22:03:15.438239098 CET | 34106 | 1985 | 192.168.2.15 | 185.22.155.213 |
Nov 27, 2024 22:03:15.558257103 CET | 1985 | 34106 | 185.22.155.213 | 192.168.2.15 |
Nov 27, 2024 22:03:16.045479059 CET | 1985 | 34106 | 185.22.155.213 | 192.168.2.15 |
Nov 27, 2024 22:03:16.045531988 CET | 34106 | 1985 | 192.168.2.15 | 185.22.155.213 |
Nov 27, 2024 22:04:36.107903004 CET | 34106 | 1985 | 192.168.2.15 | 185.22.155.213 |
Nov 27, 2024 22:04:36.234746933 CET | 1985 | 34106 | 185.22.155.213 | 192.168.2.15 |
Nov 27, 2024 22:04:36.712379932 CET | 1985 | 34106 | 185.22.155.213 | 192.168.2.15 |
Nov 27, 2024 22:04:36.712513924 CET | 34106 | 1985 | 192.168.2.15 | 185.22.155.213 |
Nov 27, 2024 22:05:56.778062105 CET | 34106 | 1985 | 192.168.2.15 | 185.22.155.213 |
Nov 27, 2024 22:05:56.898015022 CET | 1985 | 34106 | 185.22.155.213 | 192.168.2.15 |
Nov 27, 2024 22:05:57.380311966 CET | 1985 | 34106 | 185.22.155.213 | 192.168.2.15 |
Nov 27, 2024 22:05:57.380412102 CET | 34106 | 1985 | 192.168.2.15 | 185.22.155.213 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 27, 2024 22:02:52.780363083 CET | 55051 | 53 | 192.168.2.15 | 168.138.12.137 |
Nov 27, 2024 22:02:52.864291906 CET | 40634 | 53 | 192.168.2.15 | 168.138.12.137 |
Nov 27, 2024 22:02:57.785269976 CET | 37471 | 53 | 192.168.2.15 | 51.158.108.203 |
Nov 27, 2024 22:02:57.871432066 CET | 47082 | 53 | 192.168.2.15 | 51.158.108.203 |
Nov 27, 2024 22:02:58.035892963 CET | 53 | 37471 | 51.158.108.203 | 192.168.2.15 |
Nov 27, 2024 22:02:58.119765997 CET | 53 | 47082 | 51.158.108.203 | 192.168.2.15 |
Nov 27, 2024 22:02:58.122684002 CET | 49540 | 53 | 192.168.2.15 | 109.91.184.21 |
Nov 27, 2024 22:03:03.127545118 CET | 48971 | 53 | 192.168.2.15 | 152.53.15.127 |
Nov 27, 2024 22:03:03.380497932 CET | 53 | 48971 | 152.53.15.127 | 192.168.2.15 |
Nov 27, 2024 22:03:05.040920019 CET | 51348 | 53 | 192.168.2.15 | 109.91.184.21 |
Nov 27, 2024 22:03:05.308187962 CET | 53 | 51348 | 109.91.184.21 | 192.168.2.15 |
Nov 27, 2024 22:03:05.385890007 CET | 54145 | 53 | 192.168.2.15 | 194.36.144.87 |
Nov 27, 2024 22:03:05.631402969 CET | 53 | 54145 | 194.36.144.87 | 192.168.2.15 |
Nov 27, 2024 22:03:05.632154942 CET | 42697 | 53 | 192.168.2.15 | 80.152.203.134 |
Nov 27, 2024 22:03:05.967657089 CET | 53 | 42697 | 80.152.203.134 | 192.168.2.15 |
Nov 27, 2024 22:03:05.968441010 CET | 44140 | 53 | 192.168.2.15 | 185.181.61.24 |
Nov 27, 2024 22:03:06.230659962 CET | 53 | 44140 | 185.181.61.24 | 192.168.2.15 |
Nov 27, 2024 22:03:06.231484890 CET | 39302 | 53 | 192.168.2.15 | 80.152.203.134 |
Nov 27, 2024 22:03:06.537276030 CET | 53 | 39302 | 80.152.203.134 | 192.168.2.15 |
Nov 27, 2024 22:03:12.539619923 CET | 46804 | 53 | 192.168.2.15 | 81.169.136.222 |
Nov 27, 2024 22:03:12.782567024 CET | 53 | 46804 | 81.169.136.222 | 192.168.2.15 |
Nov 27, 2024 22:03:12.783487082 CET | 39617 | 53 | 192.168.2.15 | 80.152.203.134 |
Nov 27, 2024 22:03:13.037343025 CET | 53 | 39617 | 80.152.203.134 | 192.168.2.15 |
Nov 27, 2024 22:03:13.039580107 CET | 47760 | 53 | 192.168.2.15 | 109.91.184.21 |
Nov 27, 2024 22:03:13.313638926 CET | 53 | 47760 | 109.91.184.21 | 192.168.2.15 |
Nov 27, 2024 22:03:13.314443111 CET | 41720 | 53 | 192.168.2.15 | 185.181.61.24 |
Nov 27, 2024 22:03:13.574987888 CET | 53 | 41720 | 185.181.61.24 | 192.168.2.15 |
Nov 27, 2024 22:03:14.579159975 CET | 50213 | 53 | 192.168.2.15 | 185.181.61.24 |
Nov 27, 2024 22:03:14.845160007 CET | 53 | 50213 | 185.181.61.24 | 192.168.2.15 |
Nov 27, 2024 22:03:14.845933914 CET | 43980 | 53 | 192.168.2.15 | 109.91.184.21 |
Nov 27, 2024 22:03:15.175460100 CET | 53 | 43980 | 109.91.184.21 | 192.168.2.15 |
Nov 27, 2024 22:03:15.177167892 CET | 56460 | 53 | 192.168.2.15 | 109.91.184.21 |
Nov 27, 2024 22:03:15.440167904 CET | 53 | 56460 | 109.91.184.21 | 192.168.2.15 |
Nov 27, 2024 22:03:15.440789938 CET | 47573 | 53 | 192.168.2.15 | 109.91.184.21 |
Nov 27, 2024 22:03:15.725224018 CET | 53 | 47573 | 109.91.184.21 | 192.168.2.15 |
Nov 27, 2024 22:03:23.727222919 CET | 48950 | 53 | 192.168.2.15 | 185.181.61.24 |
Nov 27, 2024 22:03:23.992350101 CET | 53 | 48950 | 185.181.61.24 | 192.168.2.15 |
Nov 27, 2024 22:03:23.993179083 CET | 52694 | 53 | 192.168.2.15 | 109.91.184.21 |
Nov 27, 2024 22:03:24.285908937 CET | 53 | 52694 | 109.91.184.21 | 192.168.2.15 |
Nov 27, 2024 22:03:24.286736965 CET | 44035 | 53 | 192.168.2.15 | 194.36.144.87 |
Nov 27, 2024 22:03:24.525669098 CET | 53 | 44035 | 194.36.144.87 | 192.168.2.15 |
Nov 27, 2024 22:03:24.526475906 CET | 33016 | 53 | 192.168.2.15 | 185.181.61.24 |
Nov 27, 2024 22:03:24.795087099 CET | 53 | 33016 | 185.181.61.24 | 192.168.2.15 |
Nov 27, 2024 22:03:33.797413111 CET | 37083 | 53 | 192.168.2.15 | 152.53.15.127 |
Nov 27, 2024 22:03:34.058864117 CET | 53 | 37083 | 152.53.15.127 | 192.168.2.15 |
Nov 27, 2024 22:03:34.059827089 CET | 57591 | 53 | 192.168.2.15 | 152.53.15.127 |
Nov 27, 2024 22:03:34.299097061 CET | 53 | 57591 | 152.53.15.127 | 192.168.2.15 |
Nov 27, 2024 22:03:34.299923897 CET | 50991 | 53 | 192.168.2.15 | 194.36.144.87 |
Nov 27, 2024 22:03:34.549737930 CET | 53 | 50991 | 194.36.144.87 | 192.168.2.15 |
Nov 27, 2024 22:03:34.550710917 CET | 49616 | 53 | 192.168.2.15 | 168.235.111.72 |
Nov 27, 2024 22:03:34.860981941 CET | 53 | 49616 | 168.235.111.72 | 192.168.2.15 |
Nov 27, 2024 22:03:43.863550901 CET | 38970 | 53 | 192.168.2.15 | 152.53.15.127 |
Nov 27, 2024 22:03:44.108633995 CET | 53 | 38970 | 152.53.15.127 | 192.168.2.15 |
Nov 27, 2024 22:03:44.109750032 CET | 49545 | 53 | 192.168.2.15 | 194.36.144.87 |
Nov 27, 2024 22:03:44.362617016 CET | 53 | 49545 | 194.36.144.87 | 192.168.2.15 |
Nov 27, 2024 22:03:44.364058971 CET | 52433 | 53 | 192.168.2.15 | 51.158.108.203 |
Nov 27, 2024 22:03:44.613706112 CET | 53 | 52433 | 51.158.108.203 | 192.168.2.15 |
Nov 27, 2024 22:03:44.615192890 CET | 41711 | 53 | 192.168.2.15 | 202.61.197.122 |
Nov 27, 2024 22:03:44.859430075 CET | 53 | 41711 | 202.61.197.122 | 192.168.2.15 |
Nov 27, 2024 22:03:53.863267899 CET | 36634 | 53 | 192.168.2.15 | 217.160.70.42 |
Nov 27, 2024 22:03:54.103189945 CET | 53 | 36634 | 217.160.70.42 | 192.168.2.15 |
Nov 27, 2024 22:03:54.104433060 CET | 40119 | 53 | 192.168.2.15 | 51.158.108.203 |
Nov 27, 2024 22:03:54.344027996 CET | 53 | 40119 | 51.158.108.203 | 192.168.2.15 |
Nov 27, 2024 22:03:54.345444918 CET | 56638 | 53 | 192.168.2.15 | 168.235.111.72 |
Nov 27, 2024 22:03:54.671298027 CET | 53 | 56638 | 168.235.111.72 | 192.168.2.15 |
Nov 27, 2024 22:03:54.672790051 CET | 52716 | 53 | 192.168.2.15 | 202.61.197.122 |
Nov 27, 2024 22:03:54.925103903 CET | 53 | 52716 | 202.61.197.122 | 192.168.2.15 |
Nov 27, 2024 22:03:59.928921938 CET | 38823 | 53 | 192.168.2.15 | 217.160.70.42 |
Nov 27, 2024 22:04:00.169581890 CET | 53 | 38823 | 217.160.70.42 | 192.168.2.15 |
Nov 27, 2024 22:04:00.171209097 CET | 32788 | 53 | 192.168.2.15 | 168.235.111.72 |
Nov 27, 2024 22:04:00.484015942 CET | 53 | 32788 | 168.235.111.72 | 192.168.2.15 |
Nov 27, 2024 22:04:00.485476017 CET | 41122 | 53 | 192.168.2.15 | 80.152.203.134 |
Nov 27, 2024 22:04:00.770199060 CET | 53 | 41122 | 80.152.203.134 | 192.168.2.15 |
Nov 27, 2024 22:04:00.771954060 CET | 48188 | 53 | 192.168.2.15 | 80.152.203.134 |
Nov 27, 2024 22:04:10.780833006 CET | 51076 | 53 | 192.168.2.15 | 81.169.136.222 |
Nov 27, 2024 22:04:11.026921988 CET | 53 | 51076 | 81.169.136.222 | 192.168.2.15 |
Nov 27, 2024 22:04:11.028096914 CET | 45282 | 53 | 192.168.2.15 | 152.53.15.127 |
Nov 27, 2024 22:04:11.282143116 CET | 53 | 45282 | 152.53.15.127 | 192.168.2.15 |
Nov 27, 2024 22:04:11.283600092 CET | 45722 | 53 | 192.168.2.15 | 109.91.184.21 |
Nov 27, 2024 22:04:11.560282946 CET | 53 | 45722 | 109.91.184.21 | 192.168.2.15 |
Nov 27, 2024 22:04:11.561674118 CET | 41985 | 53 | 192.168.2.15 | 194.36.144.87 |
Nov 27, 2024 22:04:11.810857058 CET | 53 | 41985 | 194.36.144.87 | 192.168.2.15 |
Nov 27, 2024 22:04:19.814448118 CET | 46988 | 53 | 192.168.2.15 | 194.36.144.87 |
Nov 27, 2024 22:04:20.065407991 CET | 53 | 46988 | 194.36.144.87 | 192.168.2.15 |
Nov 27, 2024 22:04:20.066673994 CET | 52120 | 53 | 192.168.2.15 | 152.53.15.127 |
Nov 27, 2024 22:04:20.327488899 CET | 53 | 52120 | 152.53.15.127 | 192.168.2.15 |
Nov 27, 2024 22:04:20.328722954 CET | 39078 | 53 | 192.168.2.15 | 109.91.184.21 |
Nov 27, 2024 22:04:20.695468903 CET | 53 | 39078 | 109.91.184.21 | 192.168.2.15 |
Nov 27, 2024 22:04:20.696882010 CET | 43761 | 53 | 192.168.2.15 | 168.138.12.137 |
Nov 27, 2024 22:04:30.705262899 CET | 38815 | 53 | 192.168.2.15 | 51.158.108.203 |
Nov 27, 2024 22:04:30.963044882 CET | 53 | 38815 | 51.158.108.203 | 192.168.2.15 |
Nov 27, 2024 22:04:30.963996887 CET | 35724 | 53 | 192.168.2.15 | 194.36.144.87 |
Nov 27, 2024 22:04:31.215779066 CET | 53 | 35724 | 194.36.144.87 | 192.168.2.15 |
Nov 27, 2024 22:04:31.217068911 CET | 54718 | 53 | 192.168.2.15 | 168.138.12.137 |
Nov 27, 2024 22:04:36.221031904 CET | 37879 | 53 | 192.168.2.15 | 185.181.61.24 |
Nov 27, 2024 22:04:36.486278057 CET | 53 | 37879 | 185.181.61.24 | 192.168.2.15 |
Nov 27, 2024 22:04:40.489258051 CET | 55982 | 53 | 192.168.2.15 | 51.158.108.203 |
Nov 27, 2024 22:04:40.738787889 CET | 53 | 55982 | 51.158.108.203 | 192.168.2.15 |
Nov 27, 2024 22:04:40.739480019 CET | 44776 | 53 | 192.168.2.15 | 202.61.197.122 |
Nov 27, 2024 22:04:40.988971949 CET | 53 | 44776 | 202.61.197.122 | 192.168.2.15 |
Nov 27, 2024 22:04:40.989548922 CET | 41616 | 53 | 192.168.2.15 | 152.53.15.127 |
Nov 27, 2024 22:04:41.244141102 CET | 53 | 41616 | 152.53.15.127 | 192.168.2.15 |
Nov 27, 2024 22:04:41.244720936 CET | 48091 | 53 | 192.168.2.15 | 168.235.111.72 |
Nov 27, 2024 22:04:41.559381008 CET | 53 | 48091 | 168.235.111.72 | 192.168.2.15 |
Nov 27, 2024 22:04:47.562515974 CET | 33906 | 53 | 192.168.2.15 | 109.91.184.21 |
Nov 27, 2024 22:04:47.831238031 CET | 53 | 33906 | 109.91.184.21 | 192.168.2.15 |
Nov 27, 2024 22:04:47.831924915 CET | 42827 | 53 | 192.168.2.15 | 109.91.184.21 |
Nov 27, 2024 22:04:52.837063074 CET | 53361 | 53 | 192.168.2.15 | 109.91.184.21 |
Nov 27, 2024 22:04:53.108227968 CET | 53 | 53361 | 109.91.184.21 | 192.168.2.15 |
Nov 27, 2024 22:04:53.109280109 CET | 41561 | 53 | 192.168.2.15 | 168.138.12.137 |
Nov 27, 2024 22:05:08.113890886 CET | 45133 | 53 | 192.168.2.15 | 217.160.70.42 |
Nov 27, 2024 22:05:08.352632999 CET | 53 | 45133 | 217.160.70.42 | 192.168.2.15 |
Nov 27, 2024 22:05:08.353899956 CET | 51386 | 53 | 192.168.2.15 | 213.202.211.221 |
Nov 27, 2024 22:05:08.591379881 CET | 53 | 51386 | 213.202.211.221 | 192.168.2.15 |
Nov 27, 2024 22:05:08.592628002 CET | 42527 | 53 | 192.168.2.15 | 80.152.203.134 |
Nov 27, 2024 22:05:08.847580910 CET | 53 | 42527 | 80.152.203.134 | 192.168.2.15 |
Nov 27, 2024 22:05:08.848675966 CET | 39707 | 53 | 192.168.2.15 | 81.169.136.222 |
Nov 27, 2024 22:05:09.089265108 CET | 53 | 39707 | 81.169.136.222 | 192.168.2.15 |
Nov 27, 2024 22:05:15.092521906 CET | 57762 | 53 | 192.168.2.15 | 194.36.144.87 |
Nov 27, 2024 22:05:15.348104000 CET | 53 | 57762 | 194.36.144.87 | 192.168.2.15 |
Nov 27, 2024 22:05:15.349229097 CET | 50961 | 53 | 192.168.2.15 | 185.181.61.24 |
Nov 27, 2024 22:05:15.611840010 CET | 53 | 50961 | 185.181.61.24 | 192.168.2.15 |
Nov 27, 2024 22:05:15.612900972 CET | 37851 | 53 | 192.168.2.15 | 213.202.211.221 |
Nov 27, 2024 22:05:15.846719027 CET | 53 | 37851 | 213.202.211.221 | 192.168.2.15 |
Nov 27, 2024 22:05:15.847820997 CET | 36653 | 53 | 192.168.2.15 | 80.152.203.134 |
Nov 27, 2024 22:05:16.186254025 CET | 53 | 36653 | 80.152.203.134 | 192.168.2.15 |
Nov 27, 2024 22:05:25.188075066 CET | 39615 | 53 | 192.168.2.15 | 213.202.211.221 |
Nov 27, 2024 22:05:25.426135063 CET | 53 | 39615 | 213.202.211.221 | 192.168.2.15 |
Nov 27, 2024 22:05:25.427841902 CET | 55271 | 53 | 192.168.2.15 | 51.158.108.203 |
Nov 27, 2024 22:05:25.667260885 CET | 53 | 55271 | 51.158.108.203 | 192.168.2.15 |
Nov 27, 2024 22:05:25.668579102 CET | 57187 | 53 | 192.168.2.15 | 185.181.61.24 |
Nov 27, 2024 22:05:25.925262928 CET | 53 | 57187 | 185.181.61.24 | 192.168.2.15 |
Nov 27, 2024 22:05:25.926562071 CET | 38997 | 53 | 192.168.2.15 | 80.152.203.134 |
Nov 27, 2024 22:05:26.318172932 CET | 53 | 38997 | 80.152.203.134 | 192.168.2.15 |
Nov 27, 2024 22:05:36.320741892 CET | 55624 | 53 | 192.168.2.15 | 81.169.136.222 |
Nov 27, 2024 22:05:36.560282946 CET | 53 | 55624 | 81.169.136.222 | 192.168.2.15 |
Nov 27, 2024 22:05:36.561661959 CET | 42057 | 53 | 192.168.2.15 | 152.53.15.127 |
Nov 27, 2024 22:05:36.800705910 CET | 53 | 42057 | 152.53.15.127 | 192.168.2.15 |
Nov 27, 2024 22:05:36.801786900 CET | 58561 | 53 | 192.168.2.15 | 217.160.70.42 |
Nov 27, 2024 22:05:37.040452003 CET | 53 | 58561 | 217.160.70.42 | 192.168.2.15 |
Nov 27, 2024 22:05:37.041657925 CET | 53941 | 53 | 192.168.2.15 | 217.160.70.42 |
Nov 27, 2024 22:05:37.280500889 CET | 53 | 53941 | 217.160.70.42 | 192.168.2.15 |
Nov 27, 2024 22:05:38.665862083 CET | 38116 | 53 | 192.168.2.15 | 1.1.1.1 |
Nov 27, 2024 22:05:38.665935040 CET | 49720 | 53 | 192.168.2.15 | 1.1.1.1 |
Nov 27, 2024 22:05:38.808851957 CET | 53 | 49720 | 1.1.1.1 | 192.168.2.15 |
Nov 27, 2024 22:05:38.808862925 CET | 53 | 38116 | 1.1.1.1 | 192.168.2.15 |
Nov 27, 2024 22:05:46.283782005 CET | 57714 | 53 | 192.168.2.15 | 152.53.15.127 |
Nov 27, 2024 22:05:46.539983034 CET | 53 | 57714 | 152.53.15.127 | 192.168.2.15 |
Nov 27, 2024 22:05:46.541055918 CET | 37690 | 53 | 192.168.2.15 | 194.36.144.87 |
Nov 27, 2024 22:05:46.782130003 CET | 53 | 37690 | 194.36.144.87 | 192.168.2.15 |
Nov 27, 2024 22:05:46.783143044 CET | 45888 | 53 | 192.168.2.15 | 152.53.15.127 |
Nov 27, 2024 22:05:47.023448944 CET | 53 | 45888 | 152.53.15.127 | 192.168.2.15 |
Nov 27, 2024 22:05:47.024521112 CET | 56785 | 53 | 192.168.2.15 | 168.235.111.72 |
Nov 27, 2024 22:05:47.344614029 CET | 53 | 56785 | 168.235.111.72 | 192.168.2.15 |
Nov 27, 2024 22:05:57.346817970 CET | 60450 | 53 | 192.168.2.15 | 168.138.12.137 |
Nov 27, 2024 22:06:02.350827932 CET | 46155 | 53 | 192.168.2.15 | 185.181.61.24 |
Nov 27, 2024 22:06:02.616488934 CET | 53 | 46155 | 185.181.61.24 | 192.168.2.15 |
Nov 27, 2024 22:06:02.617762089 CET | 47778 | 53 | 192.168.2.15 | 109.91.184.21 |
Nov 27, 2024 22:06:02.930126905 CET | 53 | 47778 | 109.91.184.21 | 192.168.2.15 |
Nov 27, 2024 22:06:02.931499004 CET | 58027 | 53 | 192.168.2.15 | 109.91.184.21 |
Nov 27, 2024 22:06:03.262850046 CET | 53 | 58027 | 109.91.184.21 | 192.168.2.15 |
Nov 27, 2024 22:06:12.266119957 CET | 43477 | 53 | 192.168.2.15 | 81.169.136.222 |
Nov 27, 2024 22:06:12.505450010 CET | 53 | 43477 | 81.169.136.222 | 192.168.2.15 |
Nov 27, 2024 22:06:12.506794930 CET | 54549 | 53 | 192.168.2.15 | 152.53.15.127 |
Nov 27, 2024 22:06:12.764256001 CET | 53 | 54549 | 152.53.15.127 | 192.168.2.15 |
Nov 27, 2024 22:06:12.766109943 CET | 44304 | 53 | 192.168.2.15 | 217.160.70.42 |
Nov 27, 2024 22:06:13.008202076 CET | 53 | 44304 | 217.160.70.42 | 192.168.2.15 |
Nov 27, 2024 22:06:13.009574890 CET | 37902 | 53 | 192.168.2.15 | 213.202.211.221 |
Nov 27, 2024 22:06:13.242258072 CET | 53 | 37902 | 213.202.211.221 | 192.168.2.15 |
Nov 27, 2024 22:06:17.246278048 CET | 45185 | 53 | 192.168.2.15 | 80.152.203.134 |
Nov 27, 2024 22:06:17.600523949 CET | 53 | 45185 | 80.152.203.134 | 192.168.2.15 |
Nov 27, 2024 22:06:17.601998091 CET | 45500 | 53 | 192.168.2.15 | 168.138.12.137 |
Nov 27, 2024 22:06:22.608401060 CET | 57330 | 53 | 192.168.2.15 | 152.53.15.127 |
Nov 27, 2024 22:06:22.856523991 CET | 53 | 57330 | 152.53.15.127 | 192.168.2.15 |
Nov 27, 2024 22:06:22.857382059 CET | 42838 | 53 | 192.168.2.15 | 80.152.203.134 |
Nov 27, 2024 22:06:23.127012014 CET | 53 | 42838 | 80.152.203.134 | 192.168.2.15 |
Nov 27, 2024 22:06:25.130752087 CET | 37554 | 53 | 192.168.2.15 | 81.169.136.222 |
Nov 27, 2024 22:06:25.369932890 CET | 53 | 37554 | 81.169.136.222 | 192.168.2.15 |
Nov 27, 2024 22:06:25.371342897 CET | 44475 | 53 | 192.168.2.15 | 185.181.61.24 |
Nov 27, 2024 22:06:25.632503033 CET | 53 | 44475 | 185.181.61.24 | 192.168.2.15 |
Nov 27, 2024 22:06:25.634113073 CET | 43123 | 53 | 192.168.2.15 | 152.53.15.127 |
Nov 27, 2024 22:06:25.882375956 CET | 53 | 43123 | 152.53.15.127 | 192.168.2.15 |
Nov 27, 2024 22:06:25.883687973 CET | 58329 | 53 | 192.168.2.15 | 51.158.108.203 |
Nov 27, 2024 22:06:26.128973007 CET | 53 | 58329 | 51.158.108.203 | 192.168.2.15 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 27, 2024 22:02:52.780363083 CET | 192.168.2.15 | 168.138.12.137 | 0xba79 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 27, 2024 22:02:57.785269976 CET | 192.168.2.15 | 51.158.108.203 | 0x73e0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 27, 2024 22:03:05.040920019 CET | 192.168.2.15 | 109.91.184.21 | 0x55ac | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 27, 2024 22:05:38.665862083 CET | 192.168.2.15 | 1.1.1.1 | 0x6a8d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 27, 2024 22:05:38.665935040 CET | 192.168.2.15 | 1.1.1.1 | 0x8f2 | Standard query (0) | 28 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 27, 2024 22:03:54.671298027 CET | 168.235.111.72 | 192.168.2.15 | 0x9e4f | Format error (1) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 27, 2024 22:04:41.559381008 CET | 168.235.111.72 | 192.168.2.15 | 0x8d0c | Format error (1) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 27, 2024 22:05:09.089265108 CET | 81.169.136.222 | 192.168.2.15 | 0x9c3f | Format error (1) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 27, 2024 22:05:15.846719027 CET | 213.202.211.221 | 192.168.2.15 | 0xe61f | Format error (1) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 27, 2024 22:05:25.426135063 CET | 213.202.211.221 | 192.168.2.15 | 0x1ab7 | Format error (1) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 27, 2024 22:05:37.040452003 CET | 217.160.70.42 | 192.168.2.15 | 0xe073 | Format error (1) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 27, 2024 22:05:38.808862925 CET | 1.1.1.1 | 192.168.2.15 | 0x6a8d | No error (0) | 162.213.35.24 | A (IP address) | IN (0x0001) | false | ||
Nov 27, 2024 22:05:38.808862925 CET | 1.1.1.1 | 192.168.2.15 | 0x6a8d | No error (0) | 162.213.35.25 | A (IP address) | IN (0x0001) | false | ||
Nov 27, 2024 22:06:13.008202076 CET | 217.160.70.42 | 192.168.2.15 | 0xa814 | Format error (1) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 27, 2024 22:06:13.242258072 CET | 213.202.211.221 | 192.168.2.15 | 0x9e0a | Format error (1) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 27, 2024 22:06:25.632503033 CET | 185.181.61.24 | 192.168.2.15 | 0x58fc | Format error (1) | none | none | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 21:02:51 |
Start date (UTC): | 27/11/2024 |
Path: | /tmp/arm.elf |
Arguments: | /tmp/arm.elf |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 21:02:51 |
Start date (UTC): | 27/11/2024 |
Path: | /tmp/arm.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 21:02:51 |
Start date (UTC): | 27/11/2024 |
Path: | /tmp/arm.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 21:02:51 |
Start date (UTC): | 27/11/2024 |
Path: | /tmp/arm.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 21:02:51 |
Start date (UTC): | 27/11/2024 |
Path: | /tmp/arm.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 21:02:51 |
Start date (UTC): | 27/11/2024 |
Path: | /tmp/arm.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |