Edit tour
Linux
Analysis Report
arm4.elf
Overview
General Information
Sample name: | arm4.elf |
Analysis ID: | 1581721 |
MD5: | dd9a42698dca610231689f27555191d6 |
SHA1: | 673ff276330f84d7e7c8eec5a42570a68635c00b |
SHA256: | d48b53691ba5b09d6e7f94fb628e6490dce9a83dea2de9acbedc04c18216cddb |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Gafgyt
Score: | 60 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Multi AV Scanner detection for submitted file
Yara detected Gafgyt
Executes the "iptables" command to insert, remove and/or manipulate rules
Detected TCP or UDP traffic on non-standard ports
Executes commands using a shell command-line interpreter
Executes the "iptables" command used for managing IP filtering and manipulation
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1581721 |
Start date and time: | 2024-12-28 20:31:07 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 39s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | arm4.elf |
Detection: | MAL |
Classification: | mal60.troj.linELF@0/0@32/0 |
Command: | /tmp/arm4.elf |
PID: | 6258 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | listening dn0 |
Standard Error: |
- system is lnxubuntu20
- arm4.elf New Fork (PID: 6260, Parent: 6258)
- arm4.elf New Fork (PID: 6262, Parent: 6260)
- arm4.elf New Fork (PID: 6264, Parent: 6262)
- sh New Fork (PID: 6268, Parent: 6264)
- arm4.elf New Fork (PID: 6274, Parent: 6262)
- sh New Fork (PID: 6278, Parent: 6274)
- arm4.elf New Fork (PID: 6279, Parent: 6262)
- sh New Fork (PID: 6283, Parent: 6279)
- arm4.elf New Fork (PID: 6284, Parent: 6262)
- sh New Fork (PID: 6289, Parent: 6284)
- arm4.elf New Fork (PID: 6290, Parent: 6262)
- sh New Fork (PID: 6295, Parent: 6290)
- arm4.elf New Fork (PID: 6266, Parent: 6260)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Bashlite, Gafgyt | Bashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS). Originally it was also known under the name Bashdoor, but this term now refers to the exploit method used by the malware. It has been used to launch attacks of up to 400 Gbps. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Gafgyt | Yara detected Gafgyt | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Gafgyt | Yara detected Gafgyt | Joe Security | ||
JoeSecurity_Gafgyt | Yara detected Gafgyt | Joe Security |
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | ReversingLabs: |
Networking |
---|
Source: | Iptables executable using switch for changing the iptables rules: | Jump to behavior |
Source: | TCP traffic: |
Source: | Iptables executable: | Jump to behavior |
Source: | Socket: | Jump to behavior | ||
Source: | Socket: | Jump to behavior |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: |
Source: | .symtab present: |
Source: | Classification label: |
Persistence and Installation Behavior |
---|
Source: | Iptables executable using switch for changing the iptables rules: | Jump to behavior |
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior |
Source: | Iptables executable: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | Windows Management Instrumentation | 1 Scripting | Path Interception | Direct Volume Access | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | 1 System Network Configuration Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 2 Application Layer Protocol | Traffic Duplication | Data Destruction |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
30% | ReversingLabs | Linux.Backdoor.Mirai |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
secure-network-rebirthltd.ru | 83.222.191.146 | true | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
83.222.191.146 | secure-network-rebirthltd.ru | Bulgaria | 43561 | NET1-ASBG | false | |
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
91.189.91.43 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
83.222.191.146 | Get hash | malicious | Gafgyt | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Gafgyt | Browse | |||
Get hash | malicious | Gafgyt | Browse | |||
Get hash | malicious | Gafgyt | Browse | |||
Get hash | malicious | Gafgyt | Browse | |||
Get hash | malicious | Gafgyt | Browse | |||
Get hash | malicious | Gafgyt | Browse | |||
Get hash | malicious | Gafgyt | Browse | |||
Get hash | malicious | Unknown | Browse | |||
109.202.202.202 | Get hash | malicious | Unknown | Browse |
| |
91.189.91.43 | Get hash | malicious | Mirai | Browse | ||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Gafgyt | Browse | |||
Get hash | malicious | Gafgyt | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Gafgyt | Browse | |||
91.189.91.42 | Get hash | malicious | Mirai | Browse | ||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Gafgyt | Browse | |||
Get hash | malicious | Gafgyt | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Gafgyt | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
secure-network-rebirthltd.ru | Get hash | malicious | Gafgyt | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CANONICAL-ASGB | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
CANONICAL-ASGB | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
INIT7CH | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
NET1-ASBG | Get hash | malicious | Gafgyt | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 5.560247696696513 |
TrID: |
|
File name: | arm4.elf |
File size: | 158'592 bytes |
MD5: | dd9a42698dca610231689f27555191d6 |
SHA1: | 673ff276330f84d7e7c8eec5a42570a68635c00b |
SHA256: | d48b53691ba5b09d6e7f94fb628e6490dce9a83dea2de9acbedc04c18216cddb |
SHA512: | 114ab111dc4e40cf192bbce26991f818860e30f32b2b1c7a121691e873f2a33702e9aedaffefb63f9d6db4c8981384ad230317ba3df5e62dcea903d8f15fd853 |
SSDEEP: | 1536:UCXbcDIWl/4GaOTfCxRxzvjqqp6f9rUj3P35tlADvsnTJVPUagVqOwX+MGRaw5TU:UmYR/PTfCh+1UrJAwn7PUhzX55Vlm |
TLSH: | D7F31A85FC509F26C6D7127BFB4E428D372A07A8D3EE720789255F25378A89B0E77142 |
File Content Preview: | .ELF...a..........(.........4....i......4. ...(.......................................... ... ... ...I..............Q.td..................................-...L."...({..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 158192 |
Section Header Size: | 40 |
Number of Section Headers: | 10 |
Header String Table Index: | 9 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x8094 | 0x94 | 0x18 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x80b0 | 0xb0 | 0x1ecd8 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x26d88 | 0x1ed88 | 0x14 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x26d9c | 0x1ed9c | 0x2738 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ctors | PROGBITS | 0x32000 | 0x22000 | 0xc | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x3200c | 0x2200c | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x32020 | 0x22020 | 0x4990 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.bss | NOBITS | 0x369b0 | 0x269b0 | 0x4540 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.shstrtab | STRTAB | 0x0 | 0x269b0 | 0x3e | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8000 | 0x8000 | 0x214d4 | 0x214d4 | 6.0652 | 0x5 | R E | 0x8000 | .init .text .fini .rodata | |
LOAD | 0x22000 | 0x32000 | 0x32000 | 0x49b0 | 0x8ef0 | 0.4518 | 0x6 | RW | 0x8000 | .ctors .dtors .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 28, 2024 20:31:55.595588923 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Dec 28, 2024 20:31:58.159148932 CET | 57766 | 2222 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:31:58.278961897 CET | 2222 | 57766 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:31:58.279216051 CET | 57766 | 2222 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:31:58.280174971 CET | 57766 | 2222 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:31:58.280174971 CET | 57766 | 2222 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:31:58.399732113 CET | 2222 | 57766 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:31:58.440582991 CET | 2222 | 57766 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:00.576730013 CET | 2222 | 57766 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:00.577171087 CET | 57766 | 2222 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:00.718614101 CET | 52630 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:00.838538885 CET | 35342 | 52630 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:00.838799953 CET | 52630 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:00.838989973 CET | 52630 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:00.960369110 CET | 35342 | 52630 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:00.960541010 CET | 52630 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:00.970789909 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Dec 28, 2024 20:32:01.082397938 CET | 35342 | 52630 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:02.186562061 CET | 35342 | 52630 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:02.186897993 CET | 52630 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:02.250629902 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Dec 28, 2024 20:32:02.313409090 CET | 35342 | 52630 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:03.603975058 CET | 52632 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:03.726753950 CET | 35342 | 52632 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:03.726833105 CET | 52632 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:03.726875067 CET | 52632 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:03.848792076 CET | 35342 | 52632 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:03.848870993 CET | 52632 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:03.968813896 CET | 35342 | 52632 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:05.081248999 CET | 35342 | 52632 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:05.081404924 CET | 52632 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:05.201081038 CET | 35342 | 52632 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:06.674094915 CET | 52634 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:06.794312000 CET | 35342 | 52634 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:06.794502020 CET | 52634 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:06.794598103 CET | 52634 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:06.914222956 CET | 35342 | 52634 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:06.914392948 CET | 52634 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:07.034209013 CET | 35342 | 52634 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:08.096658945 CET | 35342 | 52634 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:08.096908092 CET | 52634 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:08.216403008 CET | 35342 | 52634 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:11.038196087 CET | 52636 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:11.158710957 CET | 35342 | 52636 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:11.158765078 CET | 52636 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:11.158797026 CET | 52636 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:11.279385090 CET | 35342 | 52636 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:11.279454947 CET | 52636 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:11.400006056 CET | 35342 | 52636 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:12.511825085 CET | 35342 | 52636 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:12.512100935 CET | 52636 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:12.631875038 CET | 35342 | 52636 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:13.514020920 CET | 52638 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:13.637586117 CET | 35342 | 52638 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:13.637658119 CET | 52638 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:13.637696981 CET | 52638 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:13.757244110 CET | 35342 | 52638 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:13.757318974 CET | 52638 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:13.877085924 CET | 35342 | 52638 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:14.983414888 CET | 35342 | 52638 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:14.983618021 CET | 52638 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:15.103185892 CET | 35342 | 52638 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:16.125498056 CET | 52640 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:16.245085955 CET | 35342 | 52640 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:16.245378017 CET | 52640 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:16.245395899 CET | 52640 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:16.365012884 CET | 35342 | 52640 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:16.365314960 CET | 52640 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:16.489506960 CET | 35342 | 52640 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:17.352502108 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Dec 28, 2024 20:32:17.591813087 CET | 35342 | 52640 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:17.592087030 CET | 52640 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:17.711766005 CET | 35342 | 52640 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:27.591099024 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Dec 28, 2024 20:32:31.686606884 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Dec 28, 2024 20:32:43.623749018 CET | 52642 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:43.743277073 CET | 35342 | 52642 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:43.743498087 CET | 52642 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:43.743748903 CET | 52642 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:43.863317966 CET | 35342 | 52642 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:43.863560915 CET | 52642 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:44.228806973 CET | 52642 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:44.264920950 CET | 35342 | 52642 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:44.349174023 CET | 35342 | 52642 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:45.044333935 CET | 35342 | 52642 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:45.044821978 CET | 52642 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:45.164499044 CET | 35342 | 52642 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:46.047363997 CET | 52644 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:46.167033911 CET | 35342 | 52644 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:46.167187929 CET | 52644 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:46.167346001 CET | 52644 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:46.287058115 CET | 35342 | 52644 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:46.287206888 CET | 52644 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:46.406965017 CET | 35342 | 52644 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:47.512926102 CET | 35342 | 52644 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:47.513221979 CET | 52644 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:47.633618116 CET | 35342 | 52644 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:49.137022018 CET | 52646 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:49.257117033 CET | 35342 | 52646 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:49.257286072 CET | 52646 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:49.257452011 CET | 52646 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:49.377134085 CET | 35342 | 52646 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:49.377263069 CET | 52646 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:49.497035980 CET | 35342 | 52646 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:50.624946117 CET | 35342 | 52646 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:50.625442982 CET | 52646 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:32:50.744960070 CET | 35342 | 52646 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:32:58.306871891 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Dec 28, 2024 20:33:16.652793884 CET | 52648 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:16.772296906 CET | 35342 | 52648 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:16.772418976 CET | 52648 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:16.772521973 CET | 52648 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:16.892890930 CET | 35342 | 52648 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:16.893141031 CET | 52648 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:17.012855053 CET | 35342 | 52648 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:18.170418978 CET | 35342 | 52648 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:18.170665979 CET | 52648 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:18.291393995 CET | 35342 | 52648 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:19.172446966 CET | 52650 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:19.292020082 CET | 35342 | 52650 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:19.292107105 CET | 52650 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:19.292175055 CET | 52650 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:19.411588907 CET | 35342 | 52650 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:19.411746979 CET | 52650 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:19.531275988 CET | 35342 | 52650 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:21.076992989 CET | 35342 | 52650 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:21.077235937 CET | 35342 | 52650 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:21.077310085 CET | 52650 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:21.077337980 CET | 52650 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:21.197666883 CET | 35342 | 52650 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:22.079051971 CET | 52652 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:22.198559046 CET | 35342 | 52652 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:22.198719978 CET | 52652 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:22.198719978 CET | 52652 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:22.318223953 CET | 35342 | 52652 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:22.318295956 CET | 52652 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:22.437836885 CET | 35342 | 52652 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:23.590943098 CET | 35342 | 52652 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:23.591320038 CET | 52652 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:23.591370106 CET | 52652 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:23.710825920 CET | 35342 | 52652 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:49.622023106 CET | 52654 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:49.741512060 CET | 35342 | 52654 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:49.741844893 CET | 52654 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:49.741935015 CET | 52654 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:49.861426115 CET | 35342 | 52654 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:49.861566067 CET | 52654 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:49.981241941 CET | 35342 | 52654 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:51.134329081 CET | 35342 | 52654 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:51.134608030 CET | 52654 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:51.259257078 CET | 35342 | 52654 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:52.537735939 CET | 52656 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:52.662739992 CET | 35342 | 52656 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:52.662861109 CET | 52656 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:52.662966967 CET | 52656 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:52.782555103 CET | 35342 | 52656 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:52.782717943 CET | 52656 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:52.902192116 CET | 35342 | 52656 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:54.055125952 CET | 35342 | 52656 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:54.055417061 CET | 52656 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:54.174956083 CET | 35342 | 52656 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:55.306216002 CET | 52658 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:55.426115990 CET | 35342 | 52658 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:55.426340103 CET | 52658 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:55.426354885 CET | 52658 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:55.546119928 CET | 35342 | 52658 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:55.546283007 CET | 52658 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:55.666826963 CET | 35342 | 52658 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:56.777256966 CET | 35342 | 52658 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:33:56.777642012 CET | 52658 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:33:56.897258043 CET | 35342 | 52658 | 83.222.191.146 | 192.168.2.23 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 28, 2024 20:31:57.610728025 CET | 52570 | 53 | 192.168.2.23 | 202.136.162.11 |
Dec 28, 2024 20:32:00.717025995 CET | 53 | 52570 | 202.136.162.11 | 192.168.2.23 |
Dec 28, 2024 20:32:03.189126015 CET | 60029 | 53 | 192.168.2.23 | 1.1.1.1 |
Dec 28, 2024 20:32:03.603096008 CET | 53 | 60029 | 1.1.1.1 | 192.168.2.23 |
Dec 28, 2024 20:32:06.083168030 CET | 60078 | 53 | 192.168.2.23 | 210.220.163.82 |
Dec 28, 2024 20:32:06.673335075 CET | 53 | 60078 | 210.220.163.82 | 192.168.2.23 |
Dec 28, 2024 20:32:09.098975897 CET | 40527 | 53 | 192.168.2.23 | 196.216.2.1 |
Dec 28, 2024 20:32:09.488405943 CET | 53 | 40527 | 196.216.2.1 | 192.168.2.23 |
Dec 28, 2024 20:32:09.489501953 CET | 39639 | 53 | 192.168.2.23 | 196.216.2.1 |
Dec 28, 2024 20:32:09.876648903 CET | 53 | 39639 | 196.216.2.1 | 192.168.2.23 |
Dec 28, 2024 20:32:09.877643108 CET | 34025 | 53 | 192.168.2.23 | 196.216.2.1 |
Dec 28, 2024 20:32:10.261264086 CET | 53 | 34025 | 196.216.2.1 | 192.168.2.23 |
Dec 28, 2024 20:32:10.262347937 CET | 57079 | 53 | 192.168.2.23 | 196.216.2.1 |
Dec 28, 2024 20:32:10.646627903 CET | 53 | 57079 | 196.216.2.1 | 192.168.2.23 |
Dec 28, 2024 20:32:10.647833109 CET | 58962 | 53 | 192.168.2.23 | 196.216.2.1 |
Dec 28, 2024 20:32:11.037512064 CET | 53 | 58962 | 196.216.2.1 | 192.168.2.23 |
Dec 28, 2024 20:32:15.985925913 CET | 50148 | 53 | 192.168.2.23 | 1.1.1.1 |
Dec 28, 2024 20:32:16.124757051 CET | 53 | 50148 | 1.1.1.1 | 192.168.2.23 |
Dec 28, 2024 20:32:18.594634056 CET | 43611 | 53 | 192.168.2.23 | 185.121.177.177 |
Dec 28, 2024 20:32:23.600425005 CET | 54493 | 53 | 192.168.2.23 | 185.121.177.177 |
Dec 28, 2024 20:32:28.606564045 CET | 47049 | 53 | 192.168.2.23 | 185.121.177.177 |
Dec 28, 2024 20:32:33.612272024 CET | 41580 | 53 | 192.168.2.23 | 185.121.177.177 |
Dec 28, 2024 20:32:38.618391037 CET | 47572 | 53 | 192.168.2.23 | 185.121.177.177 |
Dec 28, 2024 20:32:48.516448021 CET | 58264 | 53 | 192.168.2.23 | 9.9.9.9 |
Dec 28, 2024 20:32:48.637789965 CET | 53 | 58264 | 9.9.9.9 | 192.168.2.23 |
Dec 28, 2024 20:32:48.639492035 CET | 57884 | 53 | 192.168.2.23 | 9.9.9.9 |
Dec 28, 2024 20:32:48.759673119 CET | 53 | 57884 | 9.9.9.9 | 192.168.2.23 |
Dec 28, 2024 20:32:48.761199951 CET | 47324 | 53 | 192.168.2.23 | 9.9.9.9 |
Dec 28, 2024 20:32:48.884107113 CET | 53 | 47324 | 9.9.9.9 | 192.168.2.23 |
Dec 28, 2024 20:32:48.885983944 CET | 53484 | 53 | 192.168.2.23 | 9.9.9.9 |
Dec 28, 2024 20:32:49.010890007 CET | 53 | 53484 | 9.9.9.9 | 192.168.2.23 |
Dec 28, 2024 20:32:49.012799025 CET | 46216 | 53 | 192.168.2.23 | 9.9.9.9 |
Dec 28, 2024 20:32:49.135893106 CET | 53 | 46216 | 9.9.9.9 | 192.168.2.23 |
Dec 28, 2024 20:32:51.628900051 CET | 36431 | 53 | 192.168.2.23 | 200.69.193.1 |
Dec 28, 2024 20:32:56.632308960 CET | 53097 | 53 | 192.168.2.23 | 200.69.193.1 |
Dec 28, 2024 20:33:01.638040066 CET | 32868 | 53 | 192.168.2.23 | 200.69.193.1 |
Dec 28, 2024 20:33:06.643886089 CET | 51613 | 53 | 192.168.2.23 | 200.69.193.1 |
Dec 28, 2024 20:33:11.649866104 CET | 46137 | 53 | 192.168.2.23 | 200.69.193.1 |
Dec 28, 2024 20:33:24.594281912 CET | 50675 | 53 | 192.168.2.23 | 212.49.64.1 |
Dec 28, 2024 20:33:29.599175930 CET | 43671 | 53 | 192.168.2.23 | 212.49.64.1 |
Dec 28, 2024 20:33:34.605026007 CET | 46510 | 53 | 192.168.2.23 | 212.49.64.1 |
Dec 28, 2024 20:33:39.610739946 CET | 40907 | 53 | 192.168.2.23 | 212.49.64.1 |
Dec 28, 2024 20:33:44.616560936 CET | 40905 | 53 | 192.168.2.23 | 212.49.64.1 |
Dec 28, 2024 20:33:52.137212038 CET | 53370 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 20:33:52.536741018 CET | 53 | 53370 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 20:33:55.057360888 CET | 56434 | 53 | 192.168.2.23 | 194.36.144.87 |
Dec 28, 2024 20:33:55.305372953 CET | 53 | 56434 | 194.36.144.87 | 192.168.2.23 |
Dec 28, 2024 20:33:57.780014992 CET | 48270 | 53 | 192.168.2.23 | 176.103.130.130 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Dec 28, 2024 20:33:24.965621948 CET | 62.24.110.2 | 192.168.2.23 | 48f1 | (Time to live exceeded in transit) | Time Exceeded |
Dec 28, 2024 20:33:29.979898930 CET | 62.24.110.2 | 192.168.2.23 | 48f1 | (Time to live exceeded in transit) | Time Exceeded |
Dec 28, 2024 20:33:34.983778000 CET | 62.24.110.2 | 192.168.2.23 | 48f1 | (Time to live exceeded in transit) | Time Exceeded |
Dec 28, 2024 20:33:40.003988981 CET | 62.24.110.2 | 192.168.2.23 | 48f1 | (Time to live exceeded in transit) | Time Exceeded |
Dec 28, 2024 20:33:44.999737024 CET | 62.24.110.2 | 192.168.2.23 | 48f1 | (Time to live exceeded in transit) | Time Exceeded |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 28, 2024 20:31:57.610728025 CET | 192.168.2.23 | 202.136.162.11 | 0x16f0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:03.189126015 CET | 192.168.2.23 | 1.1.1.1 | 0x5737 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:06.083168030 CET | 192.168.2.23 | 210.220.163.82 | 0x73ae | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:09.098975897 CET | 192.168.2.23 | 196.216.2.1 | 0x6a03 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:09.489501953 CET | 192.168.2.23 | 196.216.2.1 | 0x6a03 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:09.877643108 CET | 192.168.2.23 | 196.216.2.1 | 0x6a03 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:10.262347937 CET | 192.168.2.23 | 196.216.2.1 | 0x6a03 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:10.647833109 CET | 192.168.2.23 | 196.216.2.1 | 0x6a03 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:15.985925913 CET | 192.168.2.23 | 1.1.1.1 | 0x9dc7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:18.594634056 CET | 192.168.2.23 | 185.121.177.177 | 0x8862 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:23.600425005 CET | 192.168.2.23 | 185.121.177.177 | 0x8862 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:28.606564045 CET | 192.168.2.23 | 185.121.177.177 | 0x8862 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:33.612272024 CET | 192.168.2.23 | 185.121.177.177 | 0x8862 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:38.618391037 CET | 192.168.2.23 | 185.121.177.177 | 0x8862 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:48.516448021 CET | 192.168.2.23 | 9.9.9.9 | 0xf679 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:48.639492035 CET | 192.168.2.23 | 9.9.9.9 | 0xf679 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:48.761199951 CET | 192.168.2.23 | 9.9.9.9 | 0xf679 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:48.885983944 CET | 192.168.2.23 | 9.9.9.9 | 0xf679 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:49.012799025 CET | 192.168.2.23 | 9.9.9.9 | 0xf679 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:51.628900051 CET | 192.168.2.23 | 200.69.193.1 | 0xdb00 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:56.632308960 CET | 192.168.2.23 | 200.69.193.1 | 0xdb00 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:33:01.638040066 CET | 192.168.2.23 | 200.69.193.1 | 0xdb00 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:33:06.643886089 CET | 192.168.2.23 | 200.69.193.1 | 0xdb00 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:33:11.649866104 CET | 192.168.2.23 | 200.69.193.1 | 0xdb00 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:33:24.594281912 CET | 192.168.2.23 | 212.49.64.1 | 0xc93a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:33:29.599175930 CET | 192.168.2.23 | 212.49.64.1 | 0xc93a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:33:34.605026007 CET | 192.168.2.23 | 212.49.64.1 | 0xc93a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:33:39.610739946 CET | 192.168.2.23 | 212.49.64.1 | 0xc93a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:33:44.616560936 CET | 192.168.2.23 | 212.49.64.1 | 0xc93a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:33:52.137212038 CET | 192.168.2.23 | 8.8.8.8 | 0x9181 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:33:55.057360888 CET | 192.168.2.23 | 194.36.144.87 | 0xb895 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:33:57.780014992 CET | 192.168.2.23 | 176.103.130.130 | 0xbbea | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 28, 2024 20:32:00.717025995 CET | 202.136.162.11 | 192.168.2.23 | 0x16f0 | No error (0) | 83.222.191.146 | A (IP address) | IN (0x0001) | false | ||
Dec 28, 2024 20:32:03.603096008 CET | 1.1.1.1 | 192.168.2.23 | 0x5737 | No error (0) | 83.222.191.146 | A (IP address) | IN (0x0001) | false | ||
Dec 28, 2024 20:32:06.673335075 CET | 210.220.163.82 | 192.168.2.23 | 0x73ae | No error (0) | 83.222.191.146 | A (IP address) | IN (0x0001) | false | ||
Dec 28, 2024 20:32:09.488405943 CET | 196.216.2.1 | 192.168.2.23 | 0x6a03 | Refused (5) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:09.876648903 CET | 196.216.2.1 | 192.168.2.23 | 0x6a03 | Refused (5) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:10.261264086 CET | 196.216.2.1 | 192.168.2.23 | 0x6a03 | Refused (5) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:10.646627903 CET | 196.216.2.1 | 192.168.2.23 | 0x6a03 | Refused (5) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:11.037512064 CET | 196.216.2.1 | 192.168.2.23 | 0x6a03 | Refused (5) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:16.124757051 CET | 1.1.1.1 | 192.168.2.23 | 0x9dc7 | No error (0) | 83.222.191.146 | A (IP address) | IN (0x0001) | false | ||
Dec 28, 2024 20:32:48.637789965 CET | 9.9.9.9 | 192.168.2.23 | 0xf679 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:48.759673119 CET | 9.9.9.9 | 192.168.2.23 | 0xf679 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:48.884107113 CET | 9.9.9.9 | 192.168.2.23 | 0xf679 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:49.010890007 CET | 9.9.9.9 | 192.168.2.23 | 0xf679 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:32:49.135893106 CET | 9.9.9.9 | 192.168.2.23 | 0xf679 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:33:52.536741018 CET | 8.8.8.8 | 192.168.2.23 | 0x9181 | No error (0) | 83.222.191.146 | A (IP address) | IN (0x0001) | false | ||
Dec 28, 2024 20:33:55.305372953 CET | 194.36.144.87 | 192.168.2.23 | 0xb895 | No error (0) | 83.222.191.146 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 19:31:54 |
Start date (UTC): | 28/12/2024 |
Path: | /tmp/arm4.elf |
Arguments: | /tmp/arm4.elf |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 19:31:54 |
Start date (UTC): | 28/12/2024 |
Path: | /tmp/arm4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 19:31:56 |
Start date (UTC): | 28/12/2024 |
Path: | /tmp/arm4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 19:31:56 |
Start date (UTC): | 28/12/2024 |
Path: | /tmp/arm4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 19:31:56 |
Start date (UTC): | 28/12/2024 |
Path: | /bin/sh |
Arguments: | sh -c "iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 19:31:56 |
Start date (UTC): | 28/12/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 19:31:56 |
Start date (UTC): | 28/12/2024 |
Path: | /usr/sbin/iptables |
Arguments: | iptables -A INPUT -p tcp --dport 26721 -j ACCEPT |
File size: | 99296 bytes |
MD5 hash: | 1ab05fef765b6342cdfadaa5275b33af |
Start time (UTC): | 19:31:56 |
Start date (UTC): | 28/12/2024 |
Path: | /tmp/arm4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 19:31:56 |
Start date (UTC): | 28/12/2024 |
Path: | /bin/sh |
Arguments: | sh -c "/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 19:31:56 |
Start date (UTC): | 28/12/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 19:31:56 |
Start date (UTC): | 28/12/2024 |
Path: | /bin/busybox |
Arguments: | /bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT |
File size: | 2172376 bytes |
MD5 hash: | 70584dffe9cb0309eb22ba78aa54bcdc |
Start time (UTC): | 19:31:56 |
Start date (UTC): | 28/12/2024 |
Path: | /tmp/arm4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 19:31:56 |
Start date (UTC): | 28/12/2024 |
Path: | /bin/sh |
Arguments: | sh -c "/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 19:31:56 |
Start date (UTC): | 28/12/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 19:31:56 |
Start date (UTC): | 28/12/2024 |
Path: | /tmp/arm4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 19:31:56 |
Start date (UTC): | 28/12/2024 |
Path: | /bin/sh |
Arguments: | sh -c "/usr/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 19:31:56 |
Start date (UTC): | 28/12/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 19:31:56 |
Start date (UTC): | 28/12/2024 |
Path: | /tmp/arm4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 19:31:56 |
Start date (UTC): | 28/12/2024 |
Path: | /bin/sh |
Arguments: | sh -c "busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 19:31:56 |
Start date (UTC): | 28/12/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 19:31:56 |
Start date (UTC): | 28/12/2024 |
Path: | /usr/bin/busybox |
Arguments: | busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT |
File size: | 2172376 bytes |
MD5 hash: | 70584dffe9cb0309eb22ba78aa54bcdc |
Start time (UTC): | 19:31:56 |
Start date (UTC): | 28/12/2024 |
Path: | /tmp/arm4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |