Edit tour
Linux
Analysis Report
njvwa4.elf
Overview
General Information
Sample name: | njvwa4.elf |
Analysis ID: | 1580753 |
MD5: | c3f85618d0ca2cf5079fd5a2d4b3ad90 |
SHA1: | da8818a04c09611711b01a4077654136728d0d08 |
SHA256: | c6584786641c09b602c19a28e0e041392bbacf8dfaefec720b7bc1b57bc825b5 |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Mirai
Score: | 80 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Sample deletes itself
Sends malformed DNS queries
Detected TCP or UDP traffic on non-standard ports
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample tries to kill a process (SIGKILL)
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1580753 |
Start date and time: | 2024-12-26 03:32:04 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 35s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | njvwa4.elf |
Detection: | MAL |
Classification: | mal80.troj.evad.linELF@0/1@56/0 |
Command: | /tmp/njvwa4.elf |
PID: | 6237 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | about to cum inside a femboy btw |
Standard Error: |
- system is lnxubuntu20
- njvwa4.elf New Fork (PID: 6239, Parent: 6237)
- njvwa4.elf New Fork (PID: 6241, Parent: 6239)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Mirai | Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
|
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Networking |
---|
Source: | DNS traffic detected: |
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: |
Source: | .symtab present: |
Source: | SIGKILL sent: | Jump to behavior |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | 1 File Deletion | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 2 Application Layer Protocol | Traffic Duplication | Data Destruction |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
42% | ReversingLabs | Linux.Backdoor.Mirai | ||
100% | Avira | EXP/ELF.Mirai.Z.A |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
raw.cardiacpure.ru | 178.215.238.25 | true | false | high | |
raw.cardiacpure.ru. [malformed] | unknown | unknown | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
178.215.238.25 | raw.cardiacpure.ru | Germany | 10753 | LVLT-10753US | false | |
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
91.189.91.43 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
178.215.238.25 | Get hash | malicious | Mirai | Browse | ||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
109.202.202.202 | Get hash | malicious | Unknown | Browse |
| |
91.189.91.43 | Get hash | malicious | Mirai | Browse | ||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
raw.cardiacpure.ru | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CANONICAL-ASGB | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
CANONICAL-ASGB | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
LVLT-10753US | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
INIT7CH | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
Process: | /tmp/njvwa4.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 4.132944044980959 |
Encrypted: | false |
SSDEEP: | 3:TgXSEYoHJN:TgCEYaJN |
MD5: | 025152826A2533895AFC3422A8C8BDEB |
SHA1: | E2A58110B590C4632223D3495850D9EF40BF4B1D |
SHA-256: | 5EE423FAAFCF89DB4B92EC512A388AC5D5ABDF1C42E2584739D6439ED3EE9E29 |
SHA-512: | E57499681DDFE88A3011B78F9EF3F85097C1F05911E7ED218027D453191B0E931B27E4C67D7F510B2580BAA8AB27C6B5D803E2AF177AC2A1C305967660AE5CFB |
Malicious: | false |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 5.564656398743216 |
TrID: |
|
File name: | njvwa4.elf |
File size: | 146'272 bytes |
MD5: | c3f85618d0ca2cf5079fd5a2d4b3ad90 |
SHA1: | da8818a04c09611711b01a4077654136728d0d08 |
SHA256: | c6584786641c09b602c19a28e0e041392bbacf8dfaefec720b7bc1b57bc825b5 |
SHA512: | 5dfa60dc3f5f4b8c0e5b588abc5e3e803699174ceff811b2331eecddef0e774d3276fad0dd7fb5bcd11da0d4787296b5c6e5e133d2fb7a0e7135d9f1bac11e60 |
SSDEEP: | 1536:IH9LjqmPiqn0+52kctiGBuAEzML4VPYVTz+NqxR5Ak9DKyMlUfwywlucS6HhZwNk:IH9Iq0BtdBu/U4OV2NqFx59USOT2 |
TLSH: | 0DE30941F8418B27C6D612BBFB5E428D3B2A17E8D3EE720399215F21379795B0E37642 |
File Content Preview: | .ELF...a..........(.........4....9......4. ...(.....................0...0............................I..D...........Q.td..................................-...L."....n..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 145872 |
Section Header Size: | 40 |
Number of Section Headers: | 10 |
Header String Table Index: | 9 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x8094 | 0x94 | 0x18 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x80b0 | 0xb0 | 0x1bb2c | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x23bdc | 0x1bbdc | 0x14 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x23bf0 | 0x1bbf0 | 0x2f40 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ctors | PROGBITS | 0x2f000 | 0x1f000 | 0xc | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x2f00c | 0x1f00c | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x2f020 | 0x1f020 | 0x4970 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.bss | NOBITS | 0x33990 | 0x23990 | 0x45b4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.shstrtab | STRTAB | 0x0 | 0x23990 | 0x3e | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8000 | 0x8000 | 0x1eb30 | 0x1eb30 | 6.0673 | 0x5 | R E | 0x8000 | .init .text .fini .rodata | |
LOAD | 0x1f000 | 0x2f000 | 0x2f000 | 0x4990 | 0x8f44 | 0.4668 | 0x6 | RW | 0x8000 | .ctors .dtors .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 26, 2024 03:32:48.195772886 CET | 38188 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:32:48.315262079 CET | 33966 | 38188 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:32:48.315535069 CET | 38188 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:32:48.317085028 CET | 38188 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:32:48.436603069 CET | 33966 | 38188 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:32:48.436712027 CET | 38188 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:32:48.556145906 CET | 33966 | 38188 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:32:49.173578024 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Dec 26, 2024 03:32:49.606143951 CET | 33966 | 38188 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:32:49.606257915 CET | 38188 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:32:49.606400967 CET | 38188 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:32:50.845201969 CET | 38190 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:32:50.964745045 CET | 33966 | 38190 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:32:50.964807034 CET | 38190 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:32:50.967133999 CET | 38190 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:32:51.086585999 CET | 33966 | 38190 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:32:51.086668015 CET | 38190 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:32:51.206146002 CET | 33966 | 38190 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:32:52.230674028 CET | 33966 | 38190 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:32:52.230803967 CET | 38190 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:32:52.230804920 CET | 38190 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:32:53.468132019 CET | 38192 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:32:53.587897062 CET | 33966 | 38192 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:32:53.587996006 CET | 38192 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:32:53.588722944 CET | 38192 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:32:53.708131075 CET | 33966 | 38192 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:32:53.708188057 CET | 38192 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:32:53.828926086 CET | 33966 | 38192 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:32:54.548751116 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Dec 26, 2024 03:32:56.084580898 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Dec 26, 2024 03:33:09.394782066 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Dec 26, 2024 03:33:21.681037903 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Dec 26, 2024 03:33:25.776506901 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Dec 26, 2024 03:33:50.348952055 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Dec 26, 2024 03:34:03.627228022 CET | 38192 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:03.746939898 CET | 33966 | 38192 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:13.635941029 CET | 38192 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:13.755601883 CET | 33966 | 38192 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:30.375925064 CET | 33966 | 38192 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:30.376153946 CET | 38192 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:30.495923042 CET | 33966 | 38192 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:32.611295938 CET | 38194 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:32.730840921 CET | 33966 | 38194 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:32.731015921 CET | 38194 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:32.731985092 CET | 38194 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:32.851464987 CET | 33966 | 38194 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:32.851533890 CET | 38194 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:32.971085072 CET | 33966 | 38194 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:33.996879101 CET | 33966 | 38194 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:33.996957064 CET | 38194 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:33.997076988 CET | 38194 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:35.232095957 CET | 38196 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:35.354427099 CET | 33966 | 38196 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:35.354512930 CET | 38196 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:35.355350971 CET | 38196 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:35.474793911 CET | 33966 | 38196 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:35.475028038 CET | 38196 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:35.594487906 CET | 33966 | 38196 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:36.618670940 CET | 33966 | 38196 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:36.618940115 CET | 38196 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:36.619143009 CET | 38196 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:37.856041908 CET | 38198 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:37.975590944 CET | 33966 | 38198 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:37.975657940 CET | 38198 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:37.976804018 CET | 38198 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:38.096302986 CET | 33966 | 38198 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:38.096533060 CET | 38198 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:38.216017962 CET | 33966 | 38198 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:39.240438938 CET | 33966 | 38198 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:39.240573883 CET | 38198 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:39.240675926 CET | 38198 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:40.475543022 CET | 38200 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:40.595057964 CET | 33966 | 38200 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:40.595216036 CET | 38200 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:40.596364021 CET | 38200 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:40.716494083 CET | 33966 | 38200 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:40.716677904 CET | 38200 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:40.836272001 CET | 33966 | 38200 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:41.872920036 CET | 33966 | 38200 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:41.873217106 CET | 38200 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:41.873249054 CET | 38200 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:43.108504057 CET | 38202 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:43.228152037 CET | 33966 | 38202 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:43.228230953 CET | 38202 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:43.229043007 CET | 38202 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:43.348632097 CET | 33966 | 38202 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:43.348730087 CET | 38202 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:43.468276978 CET | 33966 | 38202 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:44.493174076 CET | 33966 | 38202 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:44.493280888 CET | 38202 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:44.493320942 CET | 38202 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:45.729115009 CET | 38204 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:45.848679066 CET | 33966 | 38204 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:45.848874092 CET | 38204 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:45.850130081 CET | 38204 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:45.969945908 CET | 33966 | 38204 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:45.970206976 CET | 38204 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:46.089715958 CET | 33966 | 38204 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:47.113812923 CET | 33966 | 38204 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:47.113997936 CET | 38204 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:47.114304066 CET | 38204 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:48.351152897 CET | 38206 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:48.470850945 CET | 33966 | 38206 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:48.471081018 CET | 38206 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:48.472486973 CET | 38206 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:48.592113018 CET | 33966 | 38206 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:48.592372894 CET | 38206 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:48.711873055 CET | 33966 | 38206 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:49.736555099 CET | 33966 | 38206 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:49.736763954 CET | 38206 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:49.736824036 CET | 38206 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:50.979664087 CET | 38208 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:51.099283934 CET | 33966 | 38208 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:51.099383116 CET | 38208 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:51.100673914 CET | 38208 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:51.220099926 CET | 33966 | 38208 | 178.215.238.25 | 192.168.2.23 |
Dec 26, 2024 03:34:51.220243931 CET | 38208 | 33966 | 192.168.2.23 | 178.215.238.25 |
Dec 26, 2024 03:34:51.339694977 CET | 33966 | 38208 | 178.215.238.25 | 192.168.2.23 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 26, 2024 03:32:47.336491108 CET | 53727 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:32:47.575903893 CET | 53 | 53727 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:32:47.577804089 CET | 38937 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:32:47.699923038 CET | 53 | 38937 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:32:47.701430082 CET | 39543 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:32:47.823532104 CET | 53 | 39543 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:32:47.825031996 CET | 58693 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:32:47.947293043 CET | 53 | 58693 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:32:47.948908091 CET | 58351 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:32:48.071196079 CET | 53 | 58351 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:32:48.072720051 CET | 46274 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:32:48.194829941 CET | 53 | 46274 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:32:49.608527899 CET | 41021 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:32:49.730758905 CET | 53 | 41021 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:32:49.731820107 CET | 55312 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:32:49.854001045 CET | 53 | 55312 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:32:49.855329037 CET | 47290 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:32:49.977483988 CET | 53 | 47290 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:32:49.978832006 CET | 56376 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:32:50.101192951 CET | 53 | 56376 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:32:50.102947950 CET | 44414 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:32:50.225121975 CET | 53 | 44414 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:32:50.227238894 CET | 33646 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:32:50.349562883 CET | 53 | 33646 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:32:50.350886106 CET | 43419 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:32:50.473113060 CET | 53 | 43419 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:32:50.474319935 CET | 43869 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:32:50.596781015 CET | 53 | 43869 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:32:50.597846985 CET | 48500 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:32:50.720129967 CET | 53 | 48500 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:32:50.722187996 CET | 55002 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:32:50.844326973 CET | 53 | 55002 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:32:52.231559992 CET | 55893 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:32:52.353811026 CET | 53 | 55893 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:32:52.354852915 CET | 33784 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:32:52.477050066 CET | 53 | 33784 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:32:52.479237080 CET | 57722 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:32:52.601761103 CET | 53 | 57722 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:32:52.603792906 CET | 56851 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:32:52.726089954 CET | 53 | 56851 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:32:52.727325916 CET | 46913 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:32:52.849623919 CET | 53 | 46913 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:32:52.850801945 CET | 57385 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:32:52.972981930 CET | 53 | 57385 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:32:52.975131035 CET | 50615 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:32:53.097373009 CET | 53 | 50615 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:32:53.098541975 CET | 48139 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:32:53.220731974 CET | 53 | 48139 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:32:53.222131014 CET | 52589 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:32:53.344501019 CET | 53 | 52589 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:32:53.345366001 CET | 38547 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:32:53.467578888 CET | 53 | 38547 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:31.378453016 CET | 43789 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:31.500920057 CET | 53 | 43789 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:31.501868010 CET | 41132 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:31.624555111 CET | 53 | 41132 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:31.625432014 CET | 46546 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:31.747679949 CET | 53 | 46546 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:31.748492002 CET | 52530 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:31.870724916 CET | 53 | 52530 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:31.871577024 CET | 36916 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:31.993840933 CET | 53 | 36916 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:31.994803905 CET | 36716 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:32.117968082 CET | 53 | 36716 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:32.118926048 CET | 55556 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:32.241122007 CET | 53 | 55556 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:32.242041111 CET | 43660 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:32.364223957 CET | 53 | 43660 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:32.365282059 CET | 36286 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:32.487447023 CET | 53 | 36286 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:32.488663912 CET | 36274 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:32.610835075 CET | 53 | 36274 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:33.998327971 CET | 60158 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:34.120614052 CET | 53 | 60158 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:34.121923923 CET | 55604 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:34.244173050 CET | 53 | 55604 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:34.245260954 CET | 38686 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:34.367450953 CET | 53 | 38686 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:34.368263006 CET | 54547 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:34.490417004 CET | 53 | 54547 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:34.491647959 CET | 36857 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:34.614012957 CET | 53 | 36857 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:34.615334988 CET | 47672 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:34.737525940 CET | 53 | 47672 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:34.738502979 CET | 48849 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:34.860693932 CET | 53 | 48849 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:34.861934900 CET | 40875 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:34.984154940 CET | 53 | 40875 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:34.985512972 CET | 50393 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:35.107906103 CET | 53 | 50393 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:35.109278917 CET | 34639 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:35.231489897 CET | 53 | 34639 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:36.620254040 CET | 47937 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:36.742472887 CET | 53 | 47937 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:36.743870020 CET | 43075 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:36.866200924 CET | 53 | 43075 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:36.867558956 CET | 35300 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:36.989909887 CET | 53 | 35300 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:36.990902901 CET | 58536 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:37.113265038 CET | 53 | 58536 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:37.114473104 CET | 39994 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:37.236680984 CET | 53 | 39994 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:37.237888098 CET | 48249 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:37.360161066 CET | 53 | 48249 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:37.361340046 CET | 43228 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:37.483551025 CET | 53 | 43228 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:37.484827042 CET | 38118 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:37.607635975 CET | 53 | 38118 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:37.609105110 CET | 44001 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:37.731403112 CET | 53 | 44001 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:37.732817888 CET | 48471 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:37.855057001 CET | 53 | 48471 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:39.241986036 CET | 55468 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:39.364171982 CET | 53 | 55468 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:39.365665913 CET | 49227 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:39.487929106 CET | 53 | 49227 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:39.489352942 CET | 45398 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:39.611691952 CET | 53 | 45398 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:39.613224983 CET | 43505 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:39.735559940 CET | 53 | 43505 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:39.736608982 CET | 37889 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:39.858844042 CET | 53 | 37889 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:39.859685898 CET | 50049 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:39.982019901 CET | 53 | 50049 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:39.982969999 CET | 53044 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:40.105376005 CET | 53 | 53044 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:40.106595993 CET | 52993 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:40.228930950 CET | 53 | 52993 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:40.229821920 CET | 49378 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:40.351950884 CET | 53 | 49378 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:40.352802992 CET | 39475 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:40.475056887 CET | 53 | 39475 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:41.874411106 CET | 57243 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:41.996661901 CET | 53 | 57243 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:41.997855902 CET | 46240 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:42.120290041 CET | 53 | 46240 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:42.121462107 CET | 57105 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:42.243662119 CET | 53 | 57105 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:42.244704008 CET | 38459 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:42.366971016 CET | 53 | 38459 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:42.368186951 CET | 42656 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:42.490447998 CET | 53 | 42656 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:42.492153883 CET | 57789 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:42.614362001 CET | 53 | 57789 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:42.615338087 CET | 35559 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:42.737544060 CET | 53 | 35559 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:42.738513947 CET | 42187 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:42.860692024 CET | 53 | 42187 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:42.861769915 CET | 40069 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:42.984020948 CET | 53 | 40069 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:42.985224009 CET | 43098 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:43.107705116 CET | 53 | 43098 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:44.494275093 CET | 37940 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:44.616513014 CET | 53 | 37940 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:44.617676020 CET | 41836 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:44.739872932 CET | 53 | 41836 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:44.740938902 CET | 54443 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:44.863116026 CET | 53 | 54443 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:44.864449978 CET | 59195 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:44.986689091 CET | 53 | 59195 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:44.987669945 CET | 55772 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:45.110001087 CET | 53 | 55772 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:45.110893011 CET | 44729 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:45.233115911 CET | 53 | 44729 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:45.234673977 CET | 37636 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:45.356888056 CET | 53 | 37636 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:45.358478069 CET | 37509 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:45.480709076 CET | 53 | 37509 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:45.482314110 CET | 36017 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:45.604511023 CET | 53 | 36017 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:45.606075048 CET | 35770 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:45.728318930 CET | 53 | 35770 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:47.115276098 CET | 55733 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:47.237473965 CET | 53 | 55733 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:47.238549948 CET | 47229 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:47.360821009 CET | 53 | 47229 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:47.362308979 CET | 60204 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:47.484683990 CET | 53 | 60204 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:47.486164093 CET | 40540 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:47.608601093 CET | 53 | 40540 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:47.609922886 CET | 58879 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:47.732152939 CET | 53 | 58879 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:47.733634949 CET | 57944 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:47.855859995 CET | 53 | 57944 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:47.857132912 CET | 41494 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:47.979310989 CET | 53 | 41494 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:47.980731964 CET | 45215 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:48.103028059 CET | 53 | 45215 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:48.104379892 CET | 53975 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:48.226552010 CET | 53 | 53975 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:48.228055954 CET | 41297 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:48.350251913 CET | 53 | 41297 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:49.738073111 CET | 41450 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:49.861498117 CET | 53 | 41450 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:49.862875938 CET | 34188 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:49.986319065 CET | 53 | 34188 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:49.987762928 CET | 54533 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:50.112962008 CET | 53 | 54533 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:50.114341974 CET | 36503 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:50.236471891 CET | 53 | 36503 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:50.237879992 CET | 48724 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:50.360183954 CET | 53 | 48724 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:50.361654043 CET | 45878 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:50.483812094 CET | 53 | 45878 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:50.485635996 CET | 33916 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:50.607748985 CET | 53 | 33916 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:50.609390020 CET | 44091 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:50.731489897 CET | 53 | 44091 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:50.732731104 CET | 42321 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:50.854885101 CET | 53 | 42321 | 8.8.8.8 | 192.168.2.23 |
Dec 26, 2024 03:34:50.856452942 CET | 41849 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 26, 2024 03:34:50.978579044 CET | 53 | 41849 | 8.8.8.8 | 192.168.2.23 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 26, 2024 03:32:47.336491108 CET | 192.168.2.23 | 8.8.8.8 | 0xf0ac | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 26, 2024 03:32:47.577804089 CET | 192.168.2.23 | 8.8.8.8 | 0x3a90 | Standard query (0) | 256 | 335 | false | |
Dec 26, 2024 03:32:47.701430082 CET | 192.168.2.23 | 8.8.8.8 | 0x3a90 | Standard query (0) | 256 | 335 | false | |
Dec 26, 2024 03:32:47.825031996 CET | 192.168.2.23 | 8.8.8.8 | 0x3a90 | Standard query (0) | 256 | 335 | false | |
Dec 26, 2024 03:32:47.948908091 CET | 192.168.2.23 | 8.8.8.8 | 0x3a90 | Standard query (0) | 256 | 336 | false | |
Dec 26, 2024 03:32:48.072720051 CET | 192.168.2.23 | 8.8.8.8 | 0x3a90 | Standard query (0) | 256 | 336 | false | |
Dec 26, 2024 03:32:50.227238894 CET | 192.168.2.23 | 8.8.8.8 | 0xf6b8 | Standard query (0) | 256 | 338 | false | |
Dec 26, 2024 03:32:50.350886106 CET | 192.168.2.23 | 8.8.8.8 | 0xf6b8 | Standard query (0) | 256 | 338 | false | |
Dec 26, 2024 03:32:50.474319935 CET | 192.168.2.23 | 8.8.8.8 | 0xf6b8 | Standard query (0) | 256 | 338 | false | |
Dec 26, 2024 03:32:50.597846985 CET | 192.168.2.23 | 8.8.8.8 | 0xf6b8 | Standard query (0) | 256 | 338 | false | |
Dec 26, 2024 03:32:50.722187996 CET | 192.168.2.23 | 8.8.8.8 | 0xf6b8 | Standard query (0) | 256 | 338 | false | |
Dec 26, 2024 03:32:52.850801945 CET | 192.168.2.23 | 8.8.8.8 | 0xf94 | Standard query (0) | 256 | 340 | false | |
Dec 26, 2024 03:32:52.975131035 CET | 192.168.2.23 | 8.8.8.8 | 0xf94 | Standard query (0) | 256 | 341 | false | |
Dec 26, 2024 03:32:53.098541975 CET | 192.168.2.23 | 8.8.8.8 | 0xf94 | Standard query (0) | 256 | 341 | false | |
Dec 26, 2024 03:32:53.222131014 CET | 192.168.2.23 | 8.8.8.8 | 0xf94 | Standard query (0) | 256 | 341 | false | |
Dec 26, 2024 03:32:53.345366001 CET | 192.168.2.23 | 8.8.8.8 | 0xf94 | Standard query (0) | 256 | 341 | false | |
Dec 26, 2024 03:34:31.994803905 CET | 192.168.2.23 | 8.8.8.8 | 0xb07c | Standard query (0) | 256 | 440 | false | |
Dec 26, 2024 03:34:32.118926048 CET | 192.168.2.23 | 8.8.8.8 | 0xb07c | Standard query (0) | 256 | 440 | false | |
Dec 26, 2024 03:34:32.242041111 CET | 192.168.2.23 | 8.8.8.8 | 0xb07c | Standard query (0) | 256 | 440 | false | |
Dec 26, 2024 03:34:32.365282059 CET | 192.168.2.23 | 8.8.8.8 | 0xb07c | Standard query (0) | 256 | 440 | false | |
Dec 26, 2024 03:34:32.488663912 CET | 192.168.2.23 | 8.8.8.8 | 0xb07c | Standard query (0) | 256 | 440 | false | |
Dec 26, 2024 03:34:34.615334988 CET | 192.168.2.23 | 8.8.8.8 | 0x3bb2 | Standard query (0) | 256 | 442 | false | |
Dec 26, 2024 03:34:34.738502979 CET | 192.168.2.23 | 8.8.8.8 | 0x3bb2 | Standard query (0) | 256 | 442 | false | |
Dec 26, 2024 03:34:34.861934900 CET | 192.168.2.23 | 8.8.8.8 | 0x3bb2 | Standard query (0) | 256 | 442 | false | |
Dec 26, 2024 03:34:34.985512972 CET | 192.168.2.23 | 8.8.8.8 | 0x3bb2 | Standard query (0) | 256 | 443 | false | |
Dec 26, 2024 03:34:35.109278917 CET | 192.168.2.23 | 8.8.8.8 | 0x3bb2 | Standard query (0) | 256 | 443 | false | |
Dec 26, 2024 03:34:37.237888098 CET | 192.168.2.23 | 8.8.8.8 | 0xbe97 | Standard query (0) | 256 | 445 | false | |
Dec 26, 2024 03:34:37.361340046 CET | 192.168.2.23 | 8.8.8.8 | 0xbe97 | Standard query (0) | 256 | 445 | false | |
Dec 26, 2024 03:34:37.484827042 CET | 192.168.2.23 | 8.8.8.8 | 0xbe97 | Standard query (0) | 256 | 445 | false | |
Dec 26, 2024 03:34:37.609105110 CET | 192.168.2.23 | 8.8.8.8 | 0xbe97 | Standard query (0) | 256 | 445 | false | |
Dec 26, 2024 03:34:37.732817888 CET | 192.168.2.23 | 8.8.8.8 | 0xbe97 | Standard query (0) | 256 | 445 | false | |
Dec 26, 2024 03:34:39.859685898 CET | 192.168.2.23 | 8.8.8.8 | 0xd9e0 | Standard query (0) | 256 | 447 | false | |
Dec 26, 2024 03:34:39.982969999 CET | 192.168.2.23 | 8.8.8.8 | 0xd9e0 | Standard query (0) | 256 | 448 | false | |
Dec 26, 2024 03:34:40.106595993 CET | 192.168.2.23 | 8.8.8.8 | 0xd9e0 | Standard query (0) | 256 | 448 | false | |
Dec 26, 2024 03:34:40.229821920 CET | 192.168.2.23 | 8.8.8.8 | 0xd9e0 | Standard query (0) | 256 | 448 | false | |
Dec 26, 2024 03:34:40.352802992 CET | 192.168.2.23 | 8.8.8.8 | 0xd9e0 | Standard query (0) | 256 | 448 | false | |
Dec 26, 2024 03:34:42.492153883 CET | 192.168.2.23 | 8.8.8.8 | 0xecaa | Standard query (0) | 256 | 450 | false | |
Dec 26, 2024 03:34:42.615338087 CET | 192.168.2.23 | 8.8.8.8 | 0xecaa | Standard query (0) | 256 | 450 | false | |
Dec 26, 2024 03:34:42.738513947 CET | 192.168.2.23 | 8.8.8.8 | 0xecaa | Standard query (0) | 256 | 450 | false | |
Dec 26, 2024 03:34:42.861769915 CET | 192.168.2.23 | 8.8.8.8 | 0xecaa | Standard query (0) | 256 | 450 | false | |
Dec 26, 2024 03:34:42.985224009 CET | 192.168.2.23 | 8.8.8.8 | 0xecaa | Standard query (0) | 256 | 451 | false | |
Dec 26, 2024 03:34:45.110893011 CET | 192.168.2.23 | 8.8.8.8 | 0x3d5e | Standard query (0) | 256 | 453 | false | |
Dec 26, 2024 03:34:45.234673977 CET | 192.168.2.23 | 8.8.8.8 | 0x3d5e | Standard query (0) | 256 | 453 | false | |
Dec 26, 2024 03:34:45.358478069 CET | 192.168.2.23 | 8.8.8.8 | 0x3d5e | Standard query (0) | 256 | 453 | false | |
Dec 26, 2024 03:34:45.482314110 CET | 192.168.2.23 | 8.8.8.8 | 0x3d5e | Standard query (0) | 256 | 453 | false | |
Dec 26, 2024 03:34:45.606075048 CET | 192.168.2.23 | 8.8.8.8 | 0x3d5e | Standard query (0) | 256 | 453 | false | |
Dec 26, 2024 03:34:47.733634949 CET | 192.168.2.23 | 8.8.8.8 | 0x6493 | Standard query (0) | 256 | 455 | false | |
Dec 26, 2024 03:34:47.857132912 CET | 192.168.2.23 | 8.8.8.8 | 0x6493 | Standard query (0) | 256 | 455 | false | |
Dec 26, 2024 03:34:47.980731964 CET | 192.168.2.23 | 8.8.8.8 | 0x6493 | Standard query (0) | 256 | 456 | false | |
Dec 26, 2024 03:34:48.104379892 CET | 192.168.2.23 | 8.8.8.8 | 0x6493 | Standard query (0) | 256 | 456 | false | |
Dec 26, 2024 03:34:48.228055954 CET | 192.168.2.23 | 8.8.8.8 | 0x6493 | Standard query (0) | 256 | 456 | false | |
Dec 26, 2024 03:34:50.361654043 CET | 192.168.2.23 | 8.8.8.8 | 0x2ca1 | Standard query (0) | 256 | 458 | false | |
Dec 26, 2024 03:34:50.485635996 CET | 192.168.2.23 | 8.8.8.8 | 0x2ca1 | Standard query (0) | 256 | 458 | false | |
Dec 26, 2024 03:34:50.609390020 CET | 192.168.2.23 | 8.8.8.8 | 0x2ca1 | Standard query (0) | 256 | 458 | false | |
Dec 26, 2024 03:34:50.732731104 CET | 192.168.2.23 | 8.8.8.8 | 0x2ca1 | Standard query (0) | 256 | 458 | false | |
Dec 26, 2024 03:34:50.856452942 CET | 192.168.2.23 | 8.8.8.8 | 0x2ca1 | Standard query (0) | 256 | 458 | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 26, 2024 03:32:47.575903893 CET | 8.8.8.8 | 192.168.2.23 | 0xf0ac | No error (0) | 178.215.238.25 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 02:32:45 |
Start date (UTC): | 26/12/2024 |
Path: | /tmp/njvwa4.elf |
Arguments: | /tmp/njvwa4.elf |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 02:32:46 |
Start date (UTC): | 26/12/2024 |
Path: | /tmp/njvwa4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 02:32:46 |
Start date (UTC): | 26/12/2024 |
Path: | /tmp/njvwa4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |