Edit tour
Linux
Analysis Report
arm7.elf
Overview
General Information
Sample name: | arm7.elf |
Analysis ID: | 1576202 |
MD5: | e860dce716df2059091f4338eece3115 |
SHA1: | a683983a24720fdb5f89f59ddfe688da4c0329a4 |
SHA256: | 55041ad0affc5402dc6a159cd69ee06b116cb7783e1ce584e17b8ed2b31b88f6 |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Mirai
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Multi AV Scanner detection for submitted file
Yara detected Mirai
Detected TCP or UDP traffic on non-standard ports
Sample contains strings that are user agent strings indicative of HTTP manipulation
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1576202 |
Start date and time: | 2024-12-16 16:28:08 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 0s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | arm7.elf |
Detection: | MAL |
Classification: | mal56.troj.linELF@0/0@2/0 |
- VT rate limit hit for: arm7.elf
Command: | /tmp/arm7.elf |
PID: | 5426 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | Infected |
Standard Error: |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Mirai | Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security |
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | ReversingLabs: |
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | .symtab present: |
Source: | Classification label: |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: | ||
Source: | User agent string found: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | Direct Volume Access | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Application Layer Protocol | Traffic Duplication | Data Destruction |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
45% | ReversingLabs | Linux.Trojan.Mirai |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
daisy.ubuntu.com | 162.213.35.24 | true | false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
85.239.34.134 | unknown | Russian Federation | 134121 | RAINBOW-HKRainbownetworklimitedHK | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
85.239.34.134 | Get hash | malicious | Mirai | Browse | ||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
daisy.ubuntu.com | Get hash | malicious | Mirai, Okiru | Browse |
| |
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
RAINBOW-HKRainbownetworklimitedHK | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 6.261855827876342 |
TrID: |
|
File name: | arm7.elf |
File size: | 94'196 bytes |
MD5: | e860dce716df2059091f4338eece3115 |
SHA1: | a683983a24720fdb5f89f59ddfe688da4c0329a4 |
SHA256: | 55041ad0affc5402dc6a159cd69ee06b116cb7783e1ce584e17b8ed2b31b88f6 |
SHA512: | 20888dfe6d33605e55db474f3ba3068ff965f610eb20da76781e34b2642a68705628c1a36b77b18a075697d9e9cca69a77cfe1cb31f58a2ed8cc85023ca7b5b0 |
SSDEEP: | 1536:dUn5Q049+qO78ryxh6vadA40HbUdgql/viydfkHN8TvY7pI5hEs:cA9BOp6vadA40HCndfkHKTviI5hE |
TLSH: | FD933A5AF8809F01D9D5257BFA4E228933534B7CE3EF71129E249B2067C696B0F7B841 |
File Content Preview: | .ELF..............(.........4...tm......4. ...(........p.h.......... ... ............................j...j...............j..............Hu...............j..........................Q.td..................................-...L..................@-.,@...0....S |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 5 |
Section Header Offset: | 93556 |
Section Header Size: | 40 |
Number of Section Headers: | 16 |
Header String Table Index: | 15 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x80d4 | 0xd4 | 0x10 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x80f0 | 0xf0 | 0x137f4 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x1b8e4 | 0x138e4 | 0x10 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x1b8f8 | 0x138f8 | 0x2fdc | 0x0 | 0x2 | A | 0 | 0 | 8 |
.ARM.extab | PROGBITS | 0x1e8d4 | 0x168d4 | 0x18 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ARM.exidx | ARM_EXIDX | 0x1e8ec | 0x168ec | 0x120 | 0x0 | 0x82 | AL | 2 | 0 | 4 |
.eh_frame | PROGBITS | 0x1fa0c | 0x16a0c | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.tbss | NOBITS | 0x1fa10 | 0x16a10 | 0x8 | 0x0 | 0x403 | WAT | 0 | 0 | 4 |
.init_array | INIT_ARRAY | 0x1fa10 | 0x16a10 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.fini_array | FINI_ARRAY | 0x1fa14 | 0x16a14 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.jcr | PROGBITS | 0x1fa18 | 0x16a18 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.got | PROGBITS | 0x1fa1c | 0x16a1c | 0xb0 | 0x4 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x1facc | 0x16acc | 0x230 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x1fd00 | 0x16cfc | 0x7254 | 0x0 | 0x3 | WA | 0 | 0 | 8 |
.shstrtab | STRTAB | 0x0 | 0x16cfc | 0x78 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
EXIDX | 0x168ec | 0x1e8ec | 0x1e8ec | 0x120 | 0x120 | 4.5262 | 0x4 | R | 0x4 | .ARM.exidx | |
LOAD | 0x0 | 0x8000 | 0x8000 | 0x16a0c | 0x16a0c | 6.2821 | 0x5 | R E | 0x1000 | .init .text .fini .rodata .ARM.extab .ARM.exidx | |
LOAD | 0x16a0c | 0x1fa0c | 0x1fa0c | 0x2f0 | 0x7548 | 4.0202 | 0x6 | RW | 0x1000 | .eh_frame .tbss .init_array .fini_array .jcr .got .data .bss | |
TLS | 0x16a10 | 0x1fa10 | 0x1fa10 | 0x0 | 0x8 | 0.0000 | 0x4 | R | 0x4 | .tbss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 16, 2024 16:28:55.828509092 CET | 53650 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:28:55.953377008 CET | 6666 | 53650 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:28:55.953432083 CET | 53650 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:28:55.953831911 CET | 53650 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:28:56.079979897 CET | 6666 | 53650 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:28:57.137116909 CET | 6666 | 53650 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:28:57.137412071 CET | 6666 | 53650 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:28:57.137438059 CET | 53650 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:28:57.137859106 CET | 53650 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:28:57.257687092 CET | 6666 | 53650 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:06.146193981 CET | 53652 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:06.266088009 CET | 6666 | 53652 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:06.266395092 CET | 53652 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:06.267002106 CET | 53652 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:06.387041092 CET | 6666 | 53652 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:07.437994957 CET | 6666 | 53652 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:07.438155890 CET | 6666 | 53652 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:07.438493013 CET | 53652 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:07.438606024 CET | 53652 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:07.559578896 CET | 6666 | 53652 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:16.448920965 CET | 53654 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:16.569307089 CET | 6666 | 53654 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:16.569597006 CET | 53654 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:16.569699049 CET | 53654 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:16.690412998 CET | 6666 | 53654 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:17.737303019 CET | 6666 | 53654 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:17.737349987 CET | 6666 | 53654 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:17.737524033 CET | 53654 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:17.737787962 CET | 53654 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:17.857956886 CET | 6666 | 53654 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:26.747864008 CET | 53656 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:26.868966103 CET | 6666 | 53656 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:26.869098902 CET | 53656 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:26.869220018 CET | 53656 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:26.989188910 CET | 6666 | 53656 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:28.034918070 CET | 6666 | 53656 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:28.035034895 CET | 6666 | 53656 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:28.035058975 CET | 53656 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:28.035190105 CET | 53656 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:28.155710936 CET | 6666 | 53656 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:37.045263052 CET | 53658 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:37.165180922 CET | 6666 | 53658 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:37.165312052 CET | 53658 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:37.165342093 CET | 53658 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:37.285633087 CET | 6666 | 53658 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:38.337567091 CET | 6666 | 53658 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:38.337891102 CET | 6666 | 53658 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:38.337891102 CET | 53658 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:38.338013887 CET | 53658 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:38.458378077 CET | 6666 | 53658 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:47.348437071 CET | 53660 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:47.468369007 CET | 6666 | 53660 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:47.468652964 CET | 53660 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:47.468727112 CET | 53660 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:47.588567019 CET | 6666 | 53660 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:48.634442091 CET | 6666 | 53660 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:48.634504080 CET | 6666 | 53660 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:48.634753942 CET | 53660 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:48.634783983 CET | 53660 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:48.754704952 CET | 6666 | 53660 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:57.644560099 CET | 53662 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:57.765086889 CET | 6666 | 53662 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:57.765254974 CET | 53662 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:57.765336037 CET | 53662 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:57.885298967 CET | 6666 | 53662 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:58.934812069 CET | 6666 | 53662 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:58.934837103 CET | 6666 | 53662 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:29:58.934978008 CET | 53662 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:58.935034990 CET | 53662 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:29:59.054936886 CET | 6666 | 53662 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:30:07.944767952 CET | 53664 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:30:08.065315008 CET | 6666 | 53664 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:30:08.065649033 CET | 53664 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:30:08.065756083 CET | 53664 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:30:08.186990976 CET | 6666 | 53664 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:30:09.311672926 CET | 6666 | 53664 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:30:09.311827898 CET | 6666 | 53664 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:30:09.312015057 CET | 53664 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:30:09.312108994 CET | 53664 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:30:09.435813904 CET | 6666 | 53664 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:30:18.322937965 CET | 53666 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:30:18.443200111 CET | 6666 | 53666 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:30:18.443356037 CET | 53666 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:30:18.443562984 CET | 53666 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:30:18.567075014 CET | 6666 | 53666 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:30:19.587955952 CET | 6666 | 53666 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:30:19.588015079 CET | 6666 | 53666 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:30:19.588231087 CET | 53666 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:30:19.588231087 CET | 53666 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:30:19.708615065 CET | 6666 | 53666 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:30:28.598617077 CET | 53668 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:30:28.718683004 CET | 6666 | 53668 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:30:28.718954086 CET | 53668 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:30:28.718954086 CET | 53668 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:30:28.839088917 CET | 6666 | 53668 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:30:29.934530973 CET | 6666 | 53668 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:30:29.934604883 CET | 6666 | 53668 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:30:29.934802055 CET | 53668 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:30:29.934802055 CET | 53668 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:30:30.054990053 CET | 6666 | 53668 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:30:38.942400932 CET | 53670 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:30:39.063553095 CET | 6666 | 53670 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:30:39.063981056 CET | 53670 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:30:39.063981056 CET | 53670 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:30:39.184075117 CET | 6666 | 53670 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:30:40.207797050 CET | 6666 | 53670 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:30:40.207853079 CET | 6666 | 53670 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:30:40.208297014 CET | 53670 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:30:40.208297014 CET | 53670 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:30:40.331391096 CET | 6666 | 53670 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:30:49.218295097 CET | 53672 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:30:49.339492083 CET | 6666 | 53672 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:30:49.339967966 CET | 53672 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:30:49.340017080 CET | 53672 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:30:49.460608006 CET | 6666 | 53672 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:30:50.485641003 CET | 6666 | 53672 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:30:50.485860109 CET | 6666 | 53672 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:30:50.485863924 CET | 53672 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:30:50.485933065 CET | 53672 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:30:50.608372927 CET | 6666 | 53672 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:30:59.495481014 CET | 53674 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:30:59.615991116 CET | 6666 | 53674 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:30:59.616276026 CET | 53674 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:30:59.616276979 CET | 53674 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:30:59.736284971 CET | 6666 | 53674 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:00.762705088 CET | 6666 | 53674 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:00.762736082 CET | 6666 | 53674 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:00.763029099 CET | 53674 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:31:00.763226032 CET | 53674 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:31:00.883311033 CET | 6666 | 53674 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:09.771910906 CET | 53676 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:31:09.892004967 CET | 6666 | 53676 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:09.892254114 CET | 53676 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:31:09.892337084 CET | 53676 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:31:10.012263060 CET | 6666 | 53676 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:11.063668966 CET | 6666 | 53676 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:11.063718081 CET | 6666 | 53676 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:11.063925982 CET | 53676 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:31:11.063976049 CET | 53676 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:31:11.183830976 CET | 6666 | 53676 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:20.071738005 CET | 53678 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:31:20.191560984 CET | 6666 | 53678 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:20.191690922 CET | 53678 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:31:20.191792965 CET | 53678 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:31:20.311777115 CET | 6666 | 53678 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:21.363027096 CET | 6666 | 53678 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:21.363363028 CET | 53678 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:31:21.363528967 CET | 6666 | 53678 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:21.363755941 CET | 53678 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:31:21.483804941 CET | 6666 | 53678 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:30.373620987 CET | 53680 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:31:30.493952036 CET | 6666 | 53680 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:30.494298935 CET | 53680 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:31:30.494472980 CET | 53680 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:31:30.616667986 CET | 6666 | 53680 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:31.662823915 CET | 6666 | 53680 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:31.662924051 CET | 6666 | 53680 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:31.662990093 CET | 53680 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:31:31.663121939 CET | 53680 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:31:31.783032894 CET | 6666 | 53680 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:40.672115088 CET | 53682 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:31:40.792035103 CET | 6666 | 53682 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:40.792143106 CET | 53682 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:31:40.792205095 CET | 53682 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:31:40.912193060 CET | 6666 | 53682 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:42.317092896 CET | 6666 | 53682 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:42.317116976 CET | 6666 | 53682 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:42.317332983 CET | 53682 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:31:42.317332983 CET | 53682 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:31:42.353223085 CET | 6666 | 53682 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:42.353426933 CET | 53682 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:31:42.437386990 CET | 6666 | 53682 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:51.326673031 CET | 53684 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:31:51.446860075 CET | 6666 | 53684 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:51.447046041 CET | 53684 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:31:51.447093964 CET | 53684 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:31:51.567104101 CET | 6666 | 53684 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:52.592597008 CET | 6666 | 53684 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:52.592741013 CET | 6666 | 53684 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:31:52.592818975 CET | 53684 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:31:52.592899084 CET | 53684 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:31:52.712866068 CET | 6666 | 53684 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:32:01.601181984 CET | 53686 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:32:01.721777916 CET | 6666 | 53686 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:32:01.722027063 CET | 53686 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:32:01.722202063 CET | 53686 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:32:01.842236042 CET | 6666 | 53686 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:32:02.867094994 CET | 6666 | 53686 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:32:02.867491961 CET | 53686 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:32:02.867703915 CET | 6666 | 53686 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:32:02.867945910 CET | 53686 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:32:02.987782955 CET | 6666 | 53686 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:32:11.877851009 CET | 53688 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:32:11.998112917 CET | 6666 | 53688 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:32:11.998249054 CET | 53688 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:32:11.998306990 CET | 53688 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:32:12.118268013 CET | 6666 | 53688 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:32:13.163687944 CET | 6666 | 53688 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:32:13.163803101 CET | 6666 | 53688 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:32:13.163921118 CET | 53688 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:32:13.164011955 CET | 53688 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:32:13.284085035 CET | 6666 | 53688 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:32:22.175734043 CET | 53690 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:32:22.295711994 CET | 6666 | 53690 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:32:22.295933008 CET | 53690 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:32:22.296024084 CET | 53690 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:32:22.416022062 CET | 6666 | 53690 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:32:23.472436905 CET | 6666 | 53690 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:32:23.472506046 CET | 6666 | 53690 | 85.239.34.134 | 192.168.2.13 |
Dec 16, 2024 16:32:23.472614050 CET | 53690 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:32:23.472728014 CET | 53690 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 16, 2024 16:32:23.592782021 CET | 6666 | 53690 | 85.239.34.134 | 192.168.2.13 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 16, 2024 16:31:40.323445082 CET | 52220 | 53 | 192.168.2.13 | 8.8.8.8 |
Dec 16, 2024 16:31:40.323497057 CET | 53387 | 53 | 192.168.2.13 | 8.8.8.8 |
Dec 16, 2024 16:31:40.446238995 CET | 53 | 52220 | 8.8.8.8 | 192.168.2.13 |
Dec 16, 2024 16:31:40.446269989 CET | 53 | 53387 | 8.8.8.8 | 192.168.2.13 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 16, 2024 16:31:40.323445082 CET | 192.168.2.13 | 8.8.8.8 | 0x6ab2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 16, 2024 16:31:40.323497057 CET | 192.168.2.13 | 8.8.8.8 | 0x515f | Standard query (0) | 28 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 16, 2024 16:31:40.446238995 CET | 8.8.8.8 | 192.168.2.13 | 0x6ab2 | No error (0) | 162.213.35.24 | A (IP address) | IN (0x0001) | false | ||
Dec 16, 2024 16:31:40.446238995 CET | 8.8.8.8 | 192.168.2.13 | 0x6ab2 | No error (0) | 162.213.35.25 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 15:28:55 |
Start date (UTC): | 16/12/2024 |
Path: | /tmp/arm7.elf |
Arguments: | /tmp/arm7.elf |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 15:28:55 |
Start date (UTC): | 16/12/2024 |
Path: | /tmp/arm7.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 15:28:55 |
Start date (UTC): | 16/12/2024 |
Path: | /tmp/arm7.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 15:28:55 |
Start date (UTC): | 16/12/2024 |
Path: | /tmp/arm7.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |