Edit tour
Linux
Analysis Report
mips.elf
Overview
General Information
Sample name: | mips.elf |
Analysis ID: | 1581450 |
MD5: | 16a4575da9194762a94e186c9c672d69 |
SHA1: | d5e3253eb795b156a044cbbc77f2e3f3a01a2e6a |
SHA256: | 2484754793dfc38e0f5508d6b01b78b0fcaaecbb93be0ee17a9c6604a5dfbaa5 |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1581450 |
Start date and time: | 2024-12-27 18:47:04 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 24s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | mips.elf |
Detection: | MAL |
Classification: | mal56.linELF@0/0@45/0 |
- VT rate limit hit for: mips.elf
Command: | /tmp/mips.elf |
PID: | 6222 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | [INFO] Project @RebirthLTD (06-01-2024) |
Standard Error: |
⊘No yara matches
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Source: | Socket: | Jump to behavior |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | DNS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | .symtab present: |
Source: | Classification label: |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | Direct Volume Access | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
21% | ReversingLabs | Linux.Backdoor.Mirai | ||
100% | Avira | EXP/ELF.Agent.J.8 |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
dns.stresse.pro | unknown | unknown | false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
91.189.91.43 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
109.202.202.202 | Get hash | malicious | Unknown | Browse |
| |
91.189.91.43 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
91.189.91.42 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse |
⊘No context
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CANONICAL-ASGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
CANONICAL-ASGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
INIT7CH | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 5.051854250633193 |
TrID: |
|
File name: | mips.elf |
File size: | 199'328 bytes |
MD5: | 16a4575da9194762a94e186c9c672d69 |
SHA1: | d5e3253eb795b156a044cbbc77f2e3f3a01a2e6a |
SHA256: | 2484754793dfc38e0f5508d6b01b78b0fcaaecbb93be0ee17a9c6604a5dfbaa5 |
SHA512: | 21d1812890386aae6a0dd915d5294706374f55f9bd98b8e6b531a9510bb22866b28bc63e1e65718d89da99b3b888f231981934c3ec76860c3b451b03b7bb9574 |
SSDEEP: | 1536:vH73xcepASDXSDPrDVY6cj+pA5rnOgg4KNkQOiN8Ksl7LMZofWDeLccslZ1bI9lc:vzxFUdy4E68Ksl74ZofIlZYwu/BhJcN |
TLSH: | 8E14B61A6E228F7EF76C873447B78A34A76923D627E1D684D1ACC1105F2035E641FFA8 |
File Content Preview: | .ELF.....................@.`...4...p.....4. ...(.............@...@.....p...p.................F...F....X.............dt.Q............................<...'.}\...!'.......................<...'.}8...!... ....'9... ......................<...'.}....!........'9. |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 198768 |
Section Header Size: | 40 |
Number of Section Headers: | 14 |
Header String Table Index: | 13 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x400094 | 0x94 | 0x8c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x400120 | 0x120 | 0x282c0 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x4283e0 | 0x283e0 | 0x5c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x428440 | 0x28440 | 0x2530 | 0x0 | 0x2 | A | 0 | 0 | 16 |
.ctors | PROGBITS | 0x46b000 | 0x2b000 | 0xc | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x46b00c | 0x2b00c | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data.rel.ro | PROGBITS | 0x46b018 | 0x2b018 | 0x4bc | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x46b4e0 | 0x2b4e0 | 0x4920 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.got | PROGBITS | 0x46fe00 | 0x2fe00 | 0xa0c | 0x4 | 0x10000003 | WAp | 0 | 0 | 16 |
.sbss | NOBITS | 0x47080c | 0x3080c | 0x40 | 0x0 | 0x10000003 | WAp | 0 | 0 | 4 |
.bss | NOBITS | 0x470850 | 0x3080c | 0x46a0 | 0x0 | 0x3 | WA | 0 | 0 | 16 |
.mdebug.abi32 | PROGBITS | 0x14ac | 0x3080c | 0x0 | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0x3080c | 0x64 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x400000 | 0x400000 | 0x2a970 | 0x2a970 | 5.4116 | 0x5 | R E | 0x10000 | .init .text .fini .rodata | |
LOAD | 0x2b000 | 0x46b000 | 0x46b000 | 0x580c | 0x9ef0 | 1.3958 | 0x6 | RW | 0x10000 | .ctors .dtors .data.rel.ro .data .got .sbss .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 27, 2024 18:47:46.164478064 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Dec 27, 2024 18:47:51.539736032 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Dec 27, 2024 18:47:53.075529099 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Dec 27, 2024 18:48:07.665458918 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Dec 27, 2024 18:48:17.904040098 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Dec 27, 2024 18:48:24.047418118 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Dec 27, 2024 18:48:48.619883060 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 27, 2024 18:47:44.191565990 CET | 52070 | 53 | 192.168.2.23 | 208.76.51.51 |
Dec 27, 2024 18:47:49.197031021 CET | 42514 | 53 | 192.168.2.23 | 208.76.51.51 |
Dec 27, 2024 18:47:54.202186108 CET | 54179 | 53 | 192.168.2.23 | 208.76.51.51 |
Dec 27, 2024 18:47:59.218801975 CET | 35413 | 53 | 192.168.2.23 | 208.76.51.51 |
Dec 27, 2024 18:48:04.223937988 CET | 50557 | 53 | 192.168.2.23 | 208.76.51.51 |
Dec 27, 2024 18:48:14.227158070 CET | 37459 | 53 | 192.168.2.23 | 8.20.247.20 |
Dec 27, 2024 18:48:14.473505974 CET | 53 | 37459 | 8.20.247.20 | 192.168.2.23 |
Dec 27, 2024 18:48:14.475101948 CET | 38808 | 53 | 192.168.2.23 | 8.20.247.20 |
Dec 27, 2024 18:48:14.729003906 CET | 53 | 38808 | 8.20.247.20 | 192.168.2.23 |
Dec 27, 2024 18:48:14.729932070 CET | 37628 | 53 | 192.168.2.23 | 8.20.247.20 |
Dec 27, 2024 18:48:14.976522923 CET | 53 | 37628 | 8.20.247.20 | 192.168.2.23 |
Dec 27, 2024 18:48:14.977401018 CET | 39161 | 53 | 192.168.2.23 | 8.20.247.20 |
Dec 27, 2024 18:48:15.234420061 CET | 53 | 39161 | 8.20.247.20 | 192.168.2.23 |
Dec 27, 2024 18:48:15.235304117 CET | 58693 | 53 | 192.168.2.23 | 8.20.247.20 |
Dec 27, 2024 18:48:15.478533983 CET | 53 | 58693 | 8.20.247.20 | 192.168.2.23 |
Dec 27, 2024 18:48:20.480865002 CET | 49846 | 53 | 192.168.2.23 | 1.1.1.1 |
Dec 27, 2024 18:48:20.952351093 CET | 53 | 49846 | 1.1.1.1 | 192.168.2.23 |
Dec 27, 2024 18:48:20.954241037 CET | 45568 | 53 | 192.168.2.23 | 1.1.1.1 |
Dec 27, 2024 18:48:21.094896078 CET | 53 | 45568 | 1.1.1.1 | 192.168.2.23 |
Dec 27, 2024 18:48:21.096569061 CET | 47470 | 53 | 192.168.2.23 | 1.1.1.1 |
Dec 27, 2024 18:48:21.237494946 CET | 53 | 47470 | 1.1.1.1 | 192.168.2.23 |
Dec 27, 2024 18:48:21.239453077 CET | 38268 | 53 | 192.168.2.23 | 1.1.1.1 |
Dec 27, 2024 18:48:21.379977942 CET | 53 | 38268 | 1.1.1.1 | 192.168.2.23 |
Dec 27, 2024 18:48:21.381769896 CET | 36489 | 53 | 192.168.2.23 | 1.1.1.1 |
Dec 27, 2024 18:48:21.520059109 CET | 53 | 36489 | 1.1.1.1 | 192.168.2.23 |
Dec 27, 2024 18:48:26.522461891 CET | 43102 | 53 | 192.168.2.23 | 51.77.149.139 |
Dec 27, 2024 18:48:26.750080109 CET | 53 | 43102 | 51.77.149.139 | 192.168.2.23 |
Dec 27, 2024 18:48:26.751873016 CET | 51212 | 53 | 192.168.2.23 | 51.77.149.139 |
Dec 27, 2024 18:48:26.979846001 CET | 53 | 51212 | 51.77.149.139 | 192.168.2.23 |
Dec 27, 2024 18:48:26.981734037 CET | 43521 | 53 | 192.168.2.23 | 51.77.149.139 |
Dec 27, 2024 18:48:27.209012985 CET | 53 | 43521 | 51.77.149.139 | 192.168.2.23 |
Dec 27, 2024 18:48:27.210788012 CET | 35916 | 53 | 192.168.2.23 | 51.77.149.139 |
Dec 27, 2024 18:48:27.450455904 CET | 53 | 35916 | 51.77.149.139 | 192.168.2.23 |
Dec 27, 2024 18:48:27.452316999 CET | 38619 | 53 | 192.168.2.23 | 51.77.149.139 |
Dec 27, 2024 18:48:27.682179928 CET | 53 | 38619 | 51.77.149.139 | 192.168.2.23 |
Dec 27, 2024 18:48:32.684890985 CET | 50350 | 53 | 192.168.2.23 | 208.67.220.220 |
Dec 27, 2024 18:48:33.002685070 CET | 53 | 50350 | 208.67.220.220 | 192.168.2.23 |
Dec 27, 2024 18:48:33.004285097 CET | 52144 | 53 | 192.168.2.23 | 208.67.220.220 |
Dec 27, 2024 18:48:33.218602896 CET | 53 | 52144 | 208.67.220.220 | 192.168.2.23 |
Dec 27, 2024 18:48:33.220170975 CET | 48144 | 53 | 192.168.2.23 | 208.67.220.220 |
Dec 27, 2024 18:48:33.340176105 CET | 53 | 48144 | 208.67.220.220 | 192.168.2.23 |
Dec 27, 2024 18:48:33.341546059 CET | 36711 | 53 | 192.168.2.23 | 208.67.220.220 |
Dec 27, 2024 18:48:33.462452888 CET | 53 | 36711 | 208.67.220.220 | 192.168.2.23 |
Dec 27, 2024 18:48:33.464293003 CET | 50930 | 53 | 192.168.2.23 | 208.67.220.220 |
Dec 27, 2024 18:48:33.584984064 CET | 53 | 50930 | 208.67.220.220 | 192.168.2.23 |
Dec 27, 2024 18:48:38.587393999 CET | 35885 | 53 | 192.168.2.23 | 194.36.144.87 |
Dec 27, 2024 18:48:38.826987028 CET | 53 | 35885 | 194.36.144.87 | 192.168.2.23 |
Dec 27, 2024 18:48:38.827961922 CET | 56982 | 53 | 192.168.2.23 | 194.36.144.87 |
Dec 27, 2024 18:48:39.075525999 CET | 53 | 56982 | 194.36.144.87 | 192.168.2.23 |
Dec 27, 2024 18:48:39.076627970 CET | 46901 | 53 | 192.168.2.23 | 194.36.144.87 |
Dec 27, 2024 18:48:39.316663027 CET | 53 | 46901 | 194.36.144.87 | 192.168.2.23 |
Dec 27, 2024 18:48:39.317714930 CET | 51415 | 53 | 192.168.2.23 | 194.36.144.87 |
Dec 27, 2024 18:48:39.561625957 CET | 53 | 51415 | 194.36.144.87 | 192.168.2.23 |
Dec 27, 2024 18:48:39.562588930 CET | 44511 | 53 | 192.168.2.23 | 194.36.144.87 |
Dec 27, 2024 18:48:39.815504074 CET | 53 | 44511 | 194.36.144.87 | 192.168.2.23 |
Dec 27, 2024 18:48:44.817899942 CET | 53971 | 53 | 192.168.2.23 | 208.76.50.50 |
Dec 27, 2024 18:48:49.824016094 CET | 35477 | 53 | 192.168.2.23 | 208.76.50.50 |
Dec 27, 2024 18:48:54.829801083 CET | 33781 | 53 | 192.168.2.23 | 208.76.50.50 |
Dec 27, 2024 18:48:59.835325003 CET | 53981 | 53 | 192.168.2.23 | 208.76.50.50 |
Dec 27, 2024 18:49:04.840910912 CET | 39627 | 53 | 192.168.2.23 | 208.76.50.50 |
Dec 27, 2024 18:49:14.848197937 CET | 51965 | 53 | 192.168.2.23 | 8.26.56.26 |
Dec 27, 2024 18:49:15.096733093 CET | 53 | 51965 | 8.26.56.26 | 192.168.2.23 |
Dec 27, 2024 18:49:15.098273039 CET | 54029 | 53 | 192.168.2.23 | 8.26.56.26 |
Dec 27, 2024 18:49:15.343915939 CET | 53 | 54029 | 8.26.56.26 | 192.168.2.23 |
Dec 27, 2024 18:49:15.345370054 CET | 46989 | 53 | 192.168.2.23 | 8.26.56.26 |
Dec 27, 2024 18:49:15.592367887 CET | 53 | 46989 | 8.26.56.26 | 192.168.2.23 |
Dec 27, 2024 18:49:15.593966007 CET | 34185 | 53 | 192.168.2.23 | 8.26.56.26 |
Dec 27, 2024 18:49:15.845223904 CET | 53 | 34185 | 8.26.56.26 | 192.168.2.23 |
Dec 27, 2024 18:49:15.846981049 CET | 32986 | 53 | 192.168.2.23 | 8.26.56.26 |
Dec 27, 2024 18:49:16.094880104 CET | 53 | 32986 | 8.26.56.26 | 192.168.2.23 |
Dec 27, 2024 18:49:21.097295046 CET | 33403 | 53 | 192.168.2.23 | 208.76.51.51 |
Dec 27, 2024 18:49:26.103322029 CET | 38379 | 53 | 192.168.2.23 | 208.76.51.51 |
Dec 27, 2024 18:49:31.109258890 CET | 40460 | 53 | 192.168.2.23 | 208.76.51.51 |
Dec 27, 2024 18:49:36.115101099 CET | 40112 | 53 | 192.168.2.23 | 208.76.51.51 |
Dec 27, 2024 18:49:41.121179104 CET | 58798 | 53 | 192.168.2.23 | 208.76.51.51 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 27, 2024 18:47:44.191565990 CET | 192.168.2.23 | 208.76.51.51 | 0x55e6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:47:49.197031021 CET | 192.168.2.23 | 208.76.51.51 | 0x55e6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:47:54.202186108 CET | 192.168.2.23 | 208.76.51.51 | 0x55e6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:47:59.218801975 CET | 192.168.2.23 | 208.76.51.51 | 0x55e6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:04.223937988 CET | 192.168.2.23 | 208.76.51.51 | 0x55e6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:14.227158070 CET | 192.168.2.23 | 8.20.247.20 | 0xbf02 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:14.475101948 CET | 192.168.2.23 | 8.20.247.20 | 0xbf02 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:14.729932070 CET | 192.168.2.23 | 8.20.247.20 | 0xbf02 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:14.977401018 CET | 192.168.2.23 | 8.20.247.20 | 0xbf02 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:15.235304117 CET | 192.168.2.23 | 8.20.247.20 | 0xbf02 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:20.480865002 CET | 192.168.2.23 | 1.1.1.1 | 0x24d0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:20.954241037 CET | 192.168.2.23 | 1.1.1.1 | 0x24d0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:21.096569061 CET | 192.168.2.23 | 1.1.1.1 | 0x24d0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:21.239453077 CET | 192.168.2.23 | 1.1.1.1 | 0x24d0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:21.381769896 CET | 192.168.2.23 | 1.1.1.1 | 0x24d0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:26.522461891 CET | 192.168.2.23 | 51.77.149.139 | 0xebd8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:26.751873016 CET | 192.168.2.23 | 51.77.149.139 | 0xebd8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:26.981734037 CET | 192.168.2.23 | 51.77.149.139 | 0xebd8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:27.210788012 CET | 192.168.2.23 | 51.77.149.139 | 0xebd8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:27.452316999 CET | 192.168.2.23 | 51.77.149.139 | 0xebd8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:32.684890985 CET | 192.168.2.23 | 208.67.220.220 | 0xd080 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:33.004285097 CET | 192.168.2.23 | 208.67.220.220 | 0xd080 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:33.220170975 CET | 192.168.2.23 | 208.67.220.220 | 0xd080 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:33.341546059 CET | 192.168.2.23 | 208.67.220.220 | 0xd080 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:33.464293003 CET | 192.168.2.23 | 208.67.220.220 | 0xd080 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:38.587393999 CET | 192.168.2.23 | 194.36.144.87 | 0xcb6f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:38.827961922 CET | 192.168.2.23 | 194.36.144.87 | 0xcb6f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:39.076627970 CET | 192.168.2.23 | 194.36.144.87 | 0xcb6f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:39.317714930 CET | 192.168.2.23 | 194.36.144.87 | 0xcb6f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:39.562588930 CET | 192.168.2.23 | 194.36.144.87 | 0xcb6f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:44.817899942 CET | 192.168.2.23 | 208.76.50.50 | 0x61dc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:49.824016094 CET | 192.168.2.23 | 208.76.50.50 | 0x61dc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:54.829801083 CET | 192.168.2.23 | 208.76.50.50 | 0x61dc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:59.835325003 CET | 192.168.2.23 | 208.76.50.50 | 0x61dc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:49:04.840910912 CET | 192.168.2.23 | 208.76.50.50 | 0x61dc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:49:14.848197937 CET | 192.168.2.23 | 8.26.56.26 | 0x2e9f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:49:15.098273039 CET | 192.168.2.23 | 8.26.56.26 | 0x2e9f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:49:15.345370054 CET | 192.168.2.23 | 8.26.56.26 | 0x2e9f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:49:15.593966007 CET | 192.168.2.23 | 8.26.56.26 | 0x2e9f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:49:15.846981049 CET | 192.168.2.23 | 8.26.56.26 | 0x2e9f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:49:21.097295046 CET | 192.168.2.23 | 208.76.51.51 | 0xeca2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:49:26.103322029 CET | 192.168.2.23 | 208.76.51.51 | 0xeca2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:49:31.109258890 CET | 192.168.2.23 | 208.76.51.51 | 0xeca2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:49:36.115101099 CET | 192.168.2.23 | 208.76.51.51 | 0xeca2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:49:41.121179104 CET | 192.168.2.23 | 208.76.51.51 | 0xeca2 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 27, 2024 18:48:14.473505974 CET | 8.20.247.20 | 192.168.2.23 | 0xbf02 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:14.729003906 CET | 8.20.247.20 | 192.168.2.23 | 0xbf02 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:14.976522923 CET | 8.20.247.20 | 192.168.2.23 | 0xbf02 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:15.234420061 CET | 8.20.247.20 | 192.168.2.23 | 0xbf02 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:15.478533983 CET | 8.20.247.20 | 192.168.2.23 | 0xbf02 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:20.952351093 CET | 1.1.1.1 | 192.168.2.23 | 0x24d0 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:21.094896078 CET | 1.1.1.1 | 192.168.2.23 | 0x24d0 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:21.237494946 CET | 1.1.1.1 | 192.168.2.23 | 0x24d0 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:21.379977942 CET | 1.1.1.1 | 192.168.2.23 | 0x24d0 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:21.520059109 CET | 1.1.1.1 | 192.168.2.23 | 0x24d0 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:26.750080109 CET | 51.77.149.139 | 192.168.2.23 | 0xebd8 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:26.979846001 CET | 51.77.149.139 | 192.168.2.23 | 0xebd8 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:27.209012985 CET | 51.77.149.139 | 192.168.2.23 | 0xebd8 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:27.450455904 CET | 51.77.149.139 | 192.168.2.23 | 0xebd8 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:27.682179928 CET | 51.77.149.139 | 192.168.2.23 | 0xebd8 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:33.002685070 CET | 208.67.220.220 | 192.168.2.23 | 0xd080 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:33.218602896 CET | 208.67.220.220 | 192.168.2.23 | 0xd080 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:33.340176105 CET | 208.67.220.220 | 192.168.2.23 | 0xd080 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:33.462452888 CET | 208.67.220.220 | 192.168.2.23 | 0xd080 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:33.584984064 CET | 208.67.220.220 | 192.168.2.23 | 0xd080 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:38.826987028 CET | 194.36.144.87 | 192.168.2.23 | 0xcb6f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:39.075525999 CET | 194.36.144.87 | 192.168.2.23 | 0xcb6f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:39.316663027 CET | 194.36.144.87 | 192.168.2.23 | 0xcb6f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:39.561625957 CET | 194.36.144.87 | 192.168.2.23 | 0xcb6f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:48:39.815504074 CET | 194.36.144.87 | 192.168.2.23 | 0xcb6f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:49:15.096733093 CET | 8.26.56.26 | 192.168.2.23 | 0x2e9f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:49:15.343915939 CET | 8.26.56.26 | 192.168.2.23 | 0x2e9f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:49:15.592367887 CET | 8.26.56.26 | 192.168.2.23 | 0x2e9f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:49:15.845223904 CET | 8.26.56.26 | 192.168.2.23 | 0x2e9f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 18:49:16.094880104 CET | 8.26.56.26 | 192.168.2.23 | 0x2e9f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 17:47:43 |
Start date (UTC): | 27/12/2024 |
Path: | /tmp/mips.elf |
Arguments: | /tmp/mips.elf |
File size: | 5777432 bytes |
MD5 hash: | 0083f1f0e77be34ad27f849842bbb00c |
Start time (UTC): | 17:47:43 |
Start date (UTC): | 27/12/2024 |
Path: | /tmp/mips.elf |
Arguments: | - |
File size: | 5777432 bytes |
MD5 hash: | 0083f1f0e77be34ad27f849842bbb00c |
Start time (UTC): | 17:47:43 |
Start date (UTC): | 27/12/2024 |
Path: | /tmp/mips.elf |
Arguments: | - |
File size: | 5777432 bytes |
MD5 hash: | 0083f1f0e77be34ad27f849842bbb00c |