Edit tour
Linux
Analysis Report
mpsl.elf
Overview
General Information
Sample name: | mpsl.elf |
Analysis ID: | 1581478 |
MD5: | 1486509aaee4935fead5397140adc696 |
SHA1: | ca896bcb122acc0ce35cc9abb876cf102e2b4cca |
SHA256: | 2e9958508e56357ca8d0e43bf843a93df3c315d229cb1c4d82261876c90e7afa |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Multi AV Scanner detection for submitted file
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1581478 |
Start date and time: | 2024-12-27 21:07:06 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 29s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | mpsl.elf |
Detection: | MAL |
Classification: | mal48.linELF@0/0@41/0 |
- VT rate limit hit for: mpsl.elf
Command: | /tmp/mpsl.elf |
PID: | 6234 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | [INFO] Project @RebirthLTD (06-01-2024) |
Standard Error: |
⊘No yara matches
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | ReversingLabs: |
Source: | Socket: | Jump to behavior |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | DNS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | .symtab present: |
Source: | Classification label: |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | Direct Volume Access | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
21% | ReversingLabs | Linux.Backdoor.Mirai |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
dns.stresse.pro | unknown | unknown | false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
91.189.91.43 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
109.202.202.202 | Get hash | malicious | Unknown | Browse |
| |
91.189.91.43 | Get hash | malicious | HTMLPhisher | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Unknown | Browse | |||
91.189.91.42 | Get hash | malicious | HTMLPhisher | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Unknown | Browse |
⊘No context
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CANONICAL-ASGB | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
CANONICAL-ASGB | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
INIT7CH | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 5.046220257894713 |
TrID: |
|
File name: | mpsl.elf |
File size: | 203'424 bytes |
MD5: | 1486509aaee4935fead5397140adc696 |
SHA1: | ca896bcb122acc0ce35cc9abb876cf102e2b4cca |
SHA256: | 2e9958508e56357ca8d0e43bf843a93df3c315d229cb1c4d82261876c90e7afa |
SHA512: | 04c85892b1cd903b706e56246203133a4ddf01ba5ef4ef94d3b9c59a80d72dc92dd590341e9cf78a5ddf3786880bd4b8d680973044c90cd09288520d662d4e78 |
SSDEEP: | 3072:d7IhOzVDmMUe5/qAHNSRDMYRj7QQoRgBMFjY:dlzVBUezNWMI3QzMuj |
TLSH: | 0B14C709AF550FFBD86FDE3702E90B0529CCA51722A43B3A3674D528F54A94F49E3C68 |
File Content Preview: | .ELF....................`.@.4...p.......4. ...(...............@...@...........................F...F..X..............Q.td...............................<\..'!......'.......................<8..'!... .........9'.. ........................<...'!.............9 |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 202864 |
Section Header Size: | 40 |
Number of Section Headers: | 14 |
Header String Table Index: | 13 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x400094 | 0x94 | 0x8c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x400120 | 0x120 | 0x28ed0 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x428ff0 | 0x28ff0 | 0x5c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x429050 | 0x29050 | 0x2530 | 0x0 | 0x2 | A | 0 | 0 | 16 |
.ctors | PROGBITS | 0x46c000 | 0x2c000 | 0xc | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x46c00c | 0x2c00c | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data.rel.ro | PROGBITS | 0x46c018 | 0x2c018 | 0x4bc | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x46c4e0 | 0x2c4e0 | 0x4920 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.got | PROGBITS | 0x470e00 | 0x30e00 | 0xa0c | 0x4 | 0x10000003 | WAp | 0 | 0 | 16 |
.sbss | NOBITS | 0x47180c | 0x3180c | 0x40 | 0x0 | 0x10000003 | WAp | 0 | 0 | 4 |
.bss | NOBITS | 0x471850 | 0x3180c | 0x46a0 | 0x0 | 0x3 | WA | 0 | 0 | 16 |
.mdebug.abi32 | PROGBITS | 0x14ac | 0x3180c | 0x0 | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0x3180c | 0x64 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x400000 | 0x400000 | 0x2b580 | 0x2b580 | 5.4159 | 0x5 | R E | 0x10000 | .init .text .fini .rodata | |
LOAD | 0x2c000 | 0x46c000 | 0x46c000 | 0x580c | 0x9ef0 | 1.3960 | 0x6 | RW | 0x10000 | .ctors .dtors .data.rel.ro .data .got .sbss .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 27, 2024 21:07:52.028362989 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Dec 27, 2024 21:07:57.403584957 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Dec 27, 2024 21:07:59.195338964 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Dec 27, 2024 21:08:11.993551970 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Dec 27, 2024 21:08:24.279846907 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Dec 27, 2024 21:08:30.423156023 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Dec 27, 2024 21:08:52.948008060 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 27, 2024 21:07:50.178582907 CET | 41243 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 27, 2024 21:07:50.534722090 CET | 53 | 41243 | 8.8.8.8 | 192.168.2.23 |
Dec 27, 2024 21:07:50.535881042 CET | 35093 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 27, 2024 21:07:50.815603971 CET | 53 | 35093 | 8.8.8.8 | 192.168.2.23 |
Dec 27, 2024 21:07:50.817625999 CET | 36675 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 27, 2024 21:07:51.316262007 CET | 53 | 36675 | 8.8.8.8 | 192.168.2.23 |
Dec 27, 2024 21:07:51.317948103 CET | 47779 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 27, 2024 21:07:51.451838970 CET | 53 | 47779 | 8.8.8.8 | 192.168.2.23 |
Dec 27, 2024 21:07:51.454224110 CET | 39918 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 27, 2024 21:07:51.588515997 CET | 53 | 39918 | 8.8.8.8 | 192.168.2.23 |
Dec 27, 2024 21:07:56.590050936 CET | 43956 | 53 | 192.168.2.23 | 51.77.149.139 |
Dec 27, 2024 21:07:56.821784973 CET | 53 | 43956 | 51.77.149.139 | 192.168.2.23 |
Dec 27, 2024 21:07:56.822459936 CET | 35812 | 53 | 192.168.2.23 | 51.77.149.139 |
Dec 27, 2024 21:07:57.631477118 CET | 53 | 35812 | 51.77.149.139 | 192.168.2.23 |
Dec 27, 2024 21:07:57.632191896 CET | 34979 | 53 | 192.168.2.23 | 51.77.149.139 |
Dec 27, 2024 21:07:58.019835949 CET | 53 | 34979 | 51.77.149.139 | 192.168.2.23 |
Dec 27, 2024 21:07:58.020518064 CET | 34910 | 53 | 192.168.2.23 | 51.77.149.139 |
Dec 27, 2024 21:07:58.284337044 CET | 53 | 34910 | 51.77.149.139 | 192.168.2.23 |
Dec 27, 2024 21:07:58.285051107 CET | 49097 | 53 | 192.168.2.23 | 51.77.149.139 |
Dec 27, 2024 21:07:58.564064026 CET | 53 | 49097 | 51.77.149.139 | 192.168.2.23 |
Dec 27, 2024 21:08:03.564713001 CET | 48964 | 53 | 192.168.2.23 | 208.76.51.51 |
Dec 27, 2024 21:08:08.565582991 CET | 33233 | 53 | 192.168.2.23 | 208.76.51.51 |
Dec 27, 2024 21:08:13.570573092 CET | 51592 | 53 | 192.168.2.23 | 208.76.51.51 |
Dec 27, 2024 21:08:18.575550079 CET | 37305 | 53 | 192.168.2.23 | 208.76.51.51 |
Dec 27, 2024 21:08:23.580513954 CET | 33402 | 53 | 192.168.2.23 | 208.76.51.51 |
Dec 27, 2024 21:08:33.587368965 CET | 45062 | 53 | 192.168.2.23 | 8.26.56.26 |
Dec 27, 2024 21:08:33.831547976 CET | 53 | 45062 | 8.26.56.26 | 192.168.2.23 |
Dec 27, 2024 21:08:33.832910061 CET | 53935 | 53 | 192.168.2.23 | 8.26.56.26 |
Dec 27, 2024 21:08:34.077846050 CET | 53 | 53935 | 8.26.56.26 | 192.168.2.23 |
Dec 27, 2024 21:08:34.079287052 CET | 52129 | 53 | 192.168.2.23 | 8.26.56.26 |
Dec 27, 2024 21:08:34.325156927 CET | 53 | 52129 | 8.26.56.26 | 192.168.2.23 |
Dec 27, 2024 21:08:34.326432943 CET | 59799 | 53 | 192.168.2.23 | 8.26.56.26 |
Dec 27, 2024 21:08:34.574742079 CET | 53 | 59799 | 8.26.56.26 | 192.168.2.23 |
Dec 27, 2024 21:08:34.576112986 CET | 59231 | 53 | 192.168.2.23 | 8.26.56.26 |
Dec 27, 2024 21:08:34.825372934 CET | 53 | 59231 | 8.26.56.26 | 192.168.2.23 |
Dec 27, 2024 21:08:39.827516079 CET | 52105 | 53 | 192.168.2.23 | 208.76.50.50 |
Dec 27, 2024 21:08:44.833374977 CET | 38871 | 53 | 192.168.2.23 | 208.76.50.50 |
Dec 27, 2024 21:08:49.838773012 CET | 34250 | 53 | 192.168.2.23 | 208.76.50.50 |
Dec 27, 2024 21:08:54.840713024 CET | 43198 | 53 | 192.168.2.23 | 208.76.50.50 |
Dec 27, 2024 21:08:59.846246958 CET | 49637 | 53 | 192.168.2.23 | 208.76.50.50 |
Dec 27, 2024 21:09:09.851979971 CET | 57905 | 53 | 192.168.2.23 | 208.76.51.51 |
Dec 27, 2024 21:09:14.855982065 CET | 59139 | 53 | 192.168.2.23 | 208.76.51.51 |
Dec 27, 2024 21:09:19.860580921 CET | 33600 | 53 | 192.168.2.23 | 208.76.51.51 |
Dec 27, 2024 21:09:24.866219044 CET | 41008 | 53 | 192.168.2.23 | 208.76.51.51 |
Dec 27, 2024 21:09:29.867636919 CET | 38822 | 53 | 192.168.2.23 | 208.76.51.51 |
Dec 27, 2024 21:09:39.875191927 CET | 39412 | 53 | 192.168.2.23 | 194.36.144.87 |
Dec 27, 2024 21:09:40.120007992 CET | 53 | 39412 | 194.36.144.87 | 192.168.2.23 |
Dec 27, 2024 21:09:40.121730089 CET | 58540 | 53 | 192.168.2.23 | 194.36.144.87 |
Dec 27, 2024 21:09:40.366425037 CET | 53 | 58540 | 194.36.144.87 | 192.168.2.23 |
Dec 27, 2024 21:09:40.368180037 CET | 56350 | 53 | 192.168.2.23 | 194.36.144.87 |
Dec 27, 2024 21:09:40.608937025 CET | 53 | 56350 | 194.36.144.87 | 192.168.2.23 |
Dec 27, 2024 21:09:40.610455990 CET | 49941 | 53 | 192.168.2.23 | 194.36.144.87 |
Dec 27, 2024 21:09:40.857656956 CET | 53 | 49941 | 194.36.144.87 | 192.168.2.23 |
Dec 27, 2024 21:09:40.859093904 CET | 43292 | 53 | 192.168.2.23 | 194.36.144.87 |
Dec 27, 2024 21:09:41.109091997 CET | 53 | 43292 | 194.36.144.87 | 192.168.2.23 |
Dec 27, 2024 21:09:46.111310005 CET | 50153 | 53 | 192.168.2.23 | 194.36.144.87 |
Dec 27, 2024 21:09:46.357880116 CET | 53 | 50153 | 194.36.144.87 | 192.168.2.23 |
Dec 27, 2024 21:09:46.359317064 CET | 44506 | 53 | 192.168.2.23 | 194.36.144.87 |
Dec 27, 2024 21:09:46.602221966 CET | 53 | 44506 | 194.36.144.87 | 192.168.2.23 |
Dec 27, 2024 21:09:46.603604078 CET | 46650 | 53 | 192.168.2.23 | 194.36.144.87 |
Dec 27, 2024 21:09:46.856178999 CET | 53 | 46650 | 194.36.144.87 | 192.168.2.23 |
Dec 27, 2024 21:09:46.857598066 CET | 47743 | 53 | 192.168.2.23 | 194.36.144.87 |
Dec 27, 2024 21:09:47.102444887 CET | 53 | 47743 | 194.36.144.87 | 192.168.2.23 |
Dec 27, 2024 21:09:47.103696108 CET | 34714 | 53 | 192.168.2.23 | 194.36.144.87 |
Dec 27, 2024 21:09:47.344180107 CET | 53 | 34714 | 194.36.144.87 | 192.168.2.23 |
Dec 27, 2024 21:09:52.346577883 CET | 42678 | 53 | 192.168.2.23 | 208.76.50.50 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 27, 2024 21:07:50.178582907 CET | 192.168.2.23 | 8.8.8.8 | 0xf8e7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:07:50.535881042 CET | 192.168.2.23 | 8.8.8.8 | 0xf8e7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:07:50.817625999 CET | 192.168.2.23 | 8.8.8.8 | 0xf8e7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:07:51.317948103 CET | 192.168.2.23 | 8.8.8.8 | 0xf8e7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:07:51.454224110 CET | 192.168.2.23 | 8.8.8.8 | 0xf8e7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:07:56.590050936 CET | 192.168.2.23 | 51.77.149.139 | 0xa372 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:07:56.822459936 CET | 192.168.2.23 | 51.77.149.139 | 0xa372 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:07:57.632191896 CET | 192.168.2.23 | 51.77.149.139 | 0xa372 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:07:58.020518064 CET | 192.168.2.23 | 51.77.149.139 | 0xa372 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:07:58.285051107 CET | 192.168.2.23 | 51.77.149.139 | 0xa372 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:08:03.564713001 CET | 192.168.2.23 | 208.76.51.51 | 0x2645 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:08:08.565582991 CET | 192.168.2.23 | 208.76.51.51 | 0x2645 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:08:13.570573092 CET | 192.168.2.23 | 208.76.51.51 | 0x2645 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:08:18.575550079 CET | 192.168.2.23 | 208.76.51.51 | 0x2645 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:08:23.580513954 CET | 192.168.2.23 | 208.76.51.51 | 0x2645 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:08:33.587368965 CET | 192.168.2.23 | 8.26.56.26 | 0x7fe2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:08:33.832910061 CET | 192.168.2.23 | 8.26.56.26 | 0x7fe2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:08:34.079287052 CET | 192.168.2.23 | 8.26.56.26 | 0x7fe2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:08:34.326432943 CET | 192.168.2.23 | 8.26.56.26 | 0x7fe2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:08:34.576112986 CET | 192.168.2.23 | 8.26.56.26 | 0x7fe2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:08:39.827516079 CET | 192.168.2.23 | 208.76.50.50 | 0x7914 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:08:44.833374977 CET | 192.168.2.23 | 208.76.50.50 | 0x7914 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:08:49.838773012 CET | 192.168.2.23 | 208.76.50.50 | 0x7914 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:08:54.840713024 CET | 192.168.2.23 | 208.76.50.50 | 0x7914 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:08:59.846246958 CET | 192.168.2.23 | 208.76.50.50 | 0x7914 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:09:09.851979971 CET | 192.168.2.23 | 208.76.51.51 | 0x7fb8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:09:14.855982065 CET | 192.168.2.23 | 208.76.51.51 | 0x7fb8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:09:19.860580921 CET | 192.168.2.23 | 208.76.51.51 | 0x7fb8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:09:24.866219044 CET | 192.168.2.23 | 208.76.51.51 | 0x7fb8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:09:29.867636919 CET | 192.168.2.23 | 208.76.51.51 | 0x7fb8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:09:39.875191927 CET | 192.168.2.23 | 194.36.144.87 | 0x1395 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:09:40.121730089 CET | 192.168.2.23 | 194.36.144.87 | 0x1395 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:09:40.368180037 CET | 192.168.2.23 | 194.36.144.87 | 0x1395 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:09:40.610455990 CET | 192.168.2.23 | 194.36.144.87 | 0x1395 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:09:40.859093904 CET | 192.168.2.23 | 194.36.144.87 | 0x1395 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:09:46.111310005 CET | 192.168.2.23 | 194.36.144.87 | 0x2d87 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:09:46.359317064 CET | 192.168.2.23 | 194.36.144.87 | 0x2d87 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:09:46.603604078 CET | 192.168.2.23 | 194.36.144.87 | 0x2d87 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:09:46.857598066 CET | 192.168.2.23 | 194.36.144.87 | 0x2d87 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:09:47.103696108 CET | 192.168.2.23 | 194.36.144.87 | 0x2d87 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:09:52.346577883 CET | 192.168.2.23 | 208.76.50.50 | 0x7d35 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 27, 2024 21:07:50.534722090 CET | 8.8.8.8 | 192.168.2.23 | 0xf8e7 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:07:50.815603971 CET | 8.8.8.8 | 192.168.2.23 | 0xf8e7 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:07:51.316262007 CET | 8.8.8.8 | 192.168.2.23 | 0xf8e7 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:07:51.451838970 CET | 8.8.8.8 | 192.168.2.23 | 0xf8e7 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:07:51.588515997 CET | 8.8.8.8 | 192.168.2.23 | 0xf8e7 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:07:56.821784973 CET | 51.77.149.139 | 192.168.2.23 | 0xa372 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:07:57.631477118 CET | 51.77.149.139 | 192.168.2.23 | 0xa372 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:07:58.019835949 CET | 51.77.149.139 | 192.168.2.23 | 0xa372 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:07:58.284337044 CET | 51.77.149.139 | 192.168.2.23 | 0xa372 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:07:58.564064026 CET | 51.77.149.139 | 192.168.2.23 | 0xa372 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:08:33.831547976 CET | 8.26.56.26 | 192.168.2.23 | 0x7fe2 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:08:34.077846050 CET | 8.26.56.26 | 192.168.2.23 | 0x7fe2 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:08:34.325156927 CET | 8.26.56.26 | 192.168.2.23 | 0x7fe2 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:08:34.574742079 CET | 8.26.56.26 | 192.168.2.23 | 0x7fe2 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:08:34.825372934 CET | 8.26.56.26 | 192.168.2.23 | 0x7fe2 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:09:40.120007992 CET | 194.36.144.87 | 192.168.2.23 | 0x1395 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:09:40.366425037 CET | 194.36.144.87 | 192.168.2.23 | 0x1395 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:09:40.608937025 CET | 194.36.144.87 | 192.168.2.23 | 0x1395 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:09:40.857656956 CET | 194.36.144.87 | 192.168.2.23 | 0x1395 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:09:41.109091997 CET | 194.36.144.87 | 192.168.2.23 | 0x1395 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:09:46.357880116 CET | 194.36.144.87 | 192.168.2.23 | 0x2d87 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:09:46.602221966 CET | 194.36.144.87 | 192.168.2.23 | 0x2d87 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:09:46.856178999 CET | 194.36.144.87 | 192.168.2.23 | 0x2d87 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:09:47.102444887 CET | 194.36.144.87 | 192.168.2.23 | 0x2d87 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 21:09:47.344180107 CET | 194.36.144.87 | 192.168.2.23 | 0x2d87 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 20:07:49 |
Start date (UTC): | 27/12/2024 |
Path: | /tmp/mpsl.elf |
Arguments: | /tmp/mpsl.elf |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 20:07:49 |
Start date (UTC): | 27/12/2024 |
Path: | /tmp/mpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 20:07:49 |
Start date (UTC): | 27/12/2024 |
Path: | /tmp/mpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |