Edit tour
Linux
Analysis Report
mpsl.elf
Overview
General Information
Detection
Gafgyt
Score: | 64 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Multi AV Scanner detection for submitted file
Yara detected Gafgyt
Connects to many ports of the same IP (likely port scanning)
Executes the "iptables" command to insert, remove and/or manipulate rules
Detected TCP or UDP traffic on non-standard ports
Executes commands using a shell command-line interpreter
Executes the "iptables" command used for managing IP filtering and manipulation
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1581725 |
Start date and time: | 2024-12-28 20:56:06 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 27s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | mpsl.elf |
Detection: | MAL |
Classification: | mal64.troj.linELF@0/0@29/0 |
Command: | /tmp/mpsl.elf |
PID: | 6240 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | listening dn0 |
Standard Error: |
- system is lnxubuntu20
- mpsl.elf New Fork (PID: 6242, Parent: 6240)
- mpsl.elf New Fork (PID: 6246, Parent: 6242)
- mpsl.elf New Fork (PID: 6248, Parent: 6246)
- sh New Fork (PID: 6252, Parent: 6248)
- mpsl.elf New Fork (PID: 6258, Parent: 6246)
- sh New Fork (PID: 6264, Parent: 6258)
- mpsl.elf New Fork (PID: 6265, Parent: 6246)
- sh New Fork (PID: 6270, Parent: 6265)
- mpsl.elf New Fork (PID: 6271, Parent: 6246)
- sh New Fork (PID: 6276, Parent: 6271)
- mpsl.elf New Fork (PID: 6277, Parent: 6246)
- sh New Fork (PID: 6282, Parent: 6277)
- mpsl.elf New Fork (PID: 6250, Parent: 6242)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Bashlite, Gafgyt | Bashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS). Originally it was also known under the name Bashdoor, but this term now refers to the exploit method used by the malware. It has been used to launch attacks of up to 400 Gbps. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Gafgyt | Yara detected Gafgyt | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Gafgyt | Yara detected Gafgyt | Joe Security | ||
JoeSecurity_Gafgyt | Yara detected Gafgyt | Joe Security |
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | ReversingLabs: |
Networking |
---|
Source: | TCP traffic: |
Source: | Iptables executable using switch for changing the iptables rules: | Jump to behavior |
Source: | TCP traffic: |
Source: | Iptables executable: | Jump to behavior |
Source: | Socket: | Jump to behavior | ||
Source: | Socket: | Jump to behavior |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: |
Source: | .symtab present: |
Source: | Classification label: |
Persistence and Installation Behavior |
---|
Source: | Iptables executable using switch for changing the iptables rules: | Jump to behavior |
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior |
Source: | Iptables executable: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | Windows Management Instrumentation | 1 Scripting | Path Interception | Direct Volume Access | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | 1 System Network Configuration Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 2 Application Layer Protocol | Traffic Duplication | Data Destruction |
⊘No configs have been found
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
22% | ReversingLabs | Linux.Backdoor.Mirai |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
secure-network-rebirthltd.ru | 83.222.191.146 | true | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
83.222.191.146 | secure-network-rebirthltd.ru | Bulgaria | 43561 | NET1-ASBG | false | |
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
91.189.91.43 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
83.222.191.146 | Get hash | malicious | Gafgyt | Browse | ||
Get hash | malicious | Gafgyt | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Gafgyt | Browse | |||
Get hash | malicious | Gafgyt | Browse | |||
Get hash | malicious | Gafgyt | Browse | |||
Get hash | malicious | Gafgyt | Browse | |||
Get hash | malicious | Gafgyt | Browse | |||
Get hash | malicious | Gafgyt | Browse | |||
Get hash | malicious | Gafgyt | Browse | |||
109.202.202.202 | Get hash | malicious | Unknown | Browse |
| |
91.189.91.43 | Get hash | malicious | Gafgyt | Browse | ||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Gafgyt | Browse | |||
Get hash | malicious | Gafgyt | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
91.189.91.42 | Get hash | malicious | Gafgyt | Browse | ||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Gafgyt | Browse | |||
Get hash | malicious | Gafgyt | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
secure-network-rebirthltd.ru | Get hash | malicious | Gafgyt | Browse |
| |
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CANONICAL-ASGB | Get hash | malicious | Gafgyt | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
CANONICAL-ASGB | Get hash | malicious | Gafgyt | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
INIT7CH | Get hash | malicious | Gafgyt | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
NET1-ASBG | Get hash | malicious | Gafgyt | Browse |
| |
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 5.1245900032735445 |
TrID: |
|
File name: | mpsl.elf |
File size: | 210'688 bytes |
MD5: | d4156b7b325d0ecb6cdc2272e0a99f76 |
SHA1: | db21714f40edfcc64951c7f723745935f88b24a0 |
SHA256: | 5b39dff0c76c5fe2a237e3b6c5553b8d2f36bf9f65709deeb6cbfaed32c692cd |
SHA512: | b86a2064a7af349b5f13d79d9aa2c14b782be56e3790a8c0dcd9b09432de1ba10096d33008e498172b9f544261f575f3cb96c497077d98328eeaf7cd62dfd1da |
SSDEEP: | 3072:1KLRbhwavoCvLVm9E8wQOVemcy2/4rbR1QHun:1KLBhwavoCjVz8LOVbHXR1QO |
TLSH: | 0024D81AAF650FBBDC6FDE3702E90B4525CC650722A43B7A3674C928F54A50F49E3C68 |
File Content Preview: | .ELF....................`.@.4....4......4. ...(...............@...@...........................F...F.xY..............Q.td...............................<...'!......'.......................<h..'!... .........9'.. ........................<8..'!.............9 |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 210128 |
Section Header Size: | 40 |
Number of Section Headers: | 14 |
Header String Table Index: | 13 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x400094 | 0x94 | 0x8c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x400120 | 0x120 | 0x2b230 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x42b350 | 0x2b350 | 0x5c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x42b3b0 | 0x2b3b0 | 0x2740 | 0x0 | 0x2 | A | 0 | 0 | 16 |
.ctors | PROGBITS | 0x46daf4 | 0x2daf4 | 0xc | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x46db00 | 0x2db00 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data.rel.ro | PROGBITS | 0x46db0c | 0x2db0c | 0x4ec | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x46e000 | 0x2e000 | 0x4a30 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.got | PROGBITS | 0x472a30 | 0x32a30 | 0xa3c | 0x4 | 0x10000003 | WAp | 0 | 0 | 16 |
.sbss | NOBITS | 0x47346c | 0x3346c | 0x3c | 0x0 | 0x10000003 | WAp | 0 | 0 | 4 |
.bss | NOBITS | 0x4734b0 | 0x3346c | 0x46d0 | 0x0 | 0x3 | WA | 0 | 0 | 16 |
.mdebug.abi32 | PROGBITS | 0x14e2 | 0x3346c | 0x0 | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0x3346c | 0x64 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x400000 | 0x400000 | 0x2daf0 | 0x2daf0 | 5.4304 | 0x5 | R E | 0x10000 | .init .text .fini .rodata | |
LOAD | 0x2daf4 | 0x46daf4 | 0x46daf4 | 0x5978 | 0xa08c | 1.4668 | 0x6 | RW | 0x10000 | .ctors .dtors .data.rel.ro .data .got .sbss .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 28, 2024 20:56:46.574246883 CET | 52620 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:46.694179058 CET | 35342 | 52620 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:46.694268942 CET | 52620 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:46.694641113 CET | 52620 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:46.816164970 CET | 35342 | 52620 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:46.816344976 CET | 52620 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:46.825872898 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Dec 28, 2024 20:56:46.936357975 CET | 35342 | 52620 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:47.073158026 CET | 57760 | 2222 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:47.193248987 CET | 2222 | 57760 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:47.193455935 CET | 57760 | 2222 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:47.194067955 CET | 57760 | 2222 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:47.194137096 CET | 57760 | 2222 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:47.313976049 CET | 2222 | 57760 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:47.353861094 CET | 2222 | 57760 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:47.995788097 CET | 35342 | 52620 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:47.996135950 CET | 52620 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:48.115677118 CET | 35342 | 52620 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:49.251424074 CET | 52624 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:49.371387959 CET | 35342 | 52624 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:49.371660948 CET | 52624 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:49.371660948 CET | 52624 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:49.451827049 CET | 2222 | 57760 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:49.451992035 CET | 57760 | 2222 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:49.491230965 CET | 35342 | 52624 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:49.491394997 CET | 52624 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:49.610903025 CET | 35342 | 52624 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:50.717994928 CET | 35342 | 52624 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:50.718122005 CET | 52624 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:50.837786913 CET | 35342 | 52624 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:51.719348907 CET | 52626 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:51.839109898 CET | 35342 | 52626 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:51.839202881 CET | 52626 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:51.839231014 CET | 52626 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:51.959068060 CET | 35342 | 52626 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:51.959249973 CET | 52626 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:52.078931093 CET | 35342 | 52626 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:52.201168060 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Dec 28, 2024 20:56:53.141805887 CET | 35342 | 52626 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:53.141948938 CET | 52626 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:53.261703014 CET | 35342 | 52626 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:53.736958981 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Dec 28, 2024 20:56:54.442749023 CET | 52628 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:54.562279940 CET | 35342 | 52628 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:54.562365055 CET | 52628 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:54.562504053 CET | 52628 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:54.684325933 CET | 35342 | 52628 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:54.684381008 CET | 52628 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:54.803939104 CET | 35342 | 52628 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:55.954411983 CET | 35342 | 52628 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:55.954607010 CET | 52628 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:56.074129105 CET | 35342 | 52628 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:57.499469995 CET | 52630 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:57.619031906 CET | 35342 | 52630 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:57.619132042 CET | 52630 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:57.619307995 CET | 52630 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:57.738805056 CET | 35342 | 52630 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:57.738867998 CET | 52630 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:57.858427048 CET | 35342 | 52630 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:58.966984034 CET | 35342 | 52630 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:58.967154026 CET | 52630 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:56:59.086750984 CET | 35342 | 52630 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:56:59.969104052 CET | 52632 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:00.490941048 CET | 35342 | 52632 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:00.491295099 CET | 52632 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:00.491296053 CET | 52632 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:00.610924959 CET | 35342 | 52632 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:00.611120939 CET | 52632 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:00.731503010 CET | 35342 | 52632 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:01.900006056 CET | 35342 | 52632 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:01.900507927 CET | 52632 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:02.020281076 CET | 35342 | 52632 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:03.050759077 CET | 52634 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:03.170447111 CET | 35342 | 52634 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:03.170536041 CET | 52634 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:03.170654058 CET | 52634 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:03.290234089 CET | 35342 | 52634 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:03.290316105 CET | 52634 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:03.409920931 CET | 35342 | 52634 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:04.564981937 CET | 35342 | 52634 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:04.565663099 CET | 52634 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:04.685247898 CET | 35342 | 52634 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:07.815234900 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Dec 28, 2024 20:57:18.053836107 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Dec 28, 2024 20:57:24.196850061 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Dec 28, 2024 20:57:30.599442005 CET | 52636 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:30.719434977 CET | 35342 | 52636 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:30.719769955 CET | 52636 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:30.719937086 CET | 52636 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:30.839823008 CET | 35342 | 52636 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:30.840203047 CET | 52636 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:30.959923029 CET | 35342 | 52636 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:32.115745068 CET | 35342 | 52636 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:32.116142035 CET | 52636 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:32.236135006 CET | 35342 | 52636 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:33.118366957 CET | 52638 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:33.238035917 CET | 35342 | 52638 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:33.238272905 CET | 52638 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:33.238353014 CET | 52638 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:33.358342886 CET | 35342 | 52638 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:33.358572006 CET | 52638 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:33.478188992 CET | 35342 | 52638 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:34.538886070 CET | 35342 | 52638 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:34.539047003 CET | 52638 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:34.658713102 CET | 35342 | 52638 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:35.970068932 CET | 52640 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:36.089832067 CET | 35342 | 52640 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:36.090024948 CET | 52640 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:36.090085030 CET | 52640 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:36.209724903 CET | 35342 | 52640 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:36.209938049 CET | 52640 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:36.329734087 CET | 35342 | 52640 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:37.436434984 CET | 35342 | 52640 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:37.436733961 CET | 52640 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:37.556463957 CET | 35342 | 52640 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:38.439277887 CET | 52642 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:38.584229946 CET | 35342 | 52642 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:38.584492922 CET | 52642 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:38.584620953 CET | 52642 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:38.704272985 CET | 35342 | 52642 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:38.704603910 CET | 52642 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:38.824321985 CET | 35342 | 52642 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:39.884406090 CET | 35342 | 52642 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:39.884675026 CET | 52642 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:40.004260063 CET | 35342 | 52642 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:40.886914015 CET | 52644 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:41.006670952 CET | 35342 | 52644 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:41.006859064 CET | 52644 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:41.006958008 CET | 52644 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:41.126502037 CET | 35342 | 52644 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:41.126640081 CET | 52644 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:41.246206999 CET | 35342 | 52644 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:42.399190903 CET | 35342 | 52644 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:42.399432898 CET | 52644 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:42.519197941 CET | 35342 | 52644 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:43.401931047 CET | 52646 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:43.522288084 CET | 35342 | 52646 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:43.522661924 CET | 52646 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:43.522768974 CET | 52646 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:43.642473936 CET | 35342 | 52646 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:43.642738104 CET | 52646 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:43.762526035 CET | 35342 | 52646 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:44.869066000 CET | 35342 | 52646 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:44.869385004 CET | 52646 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:44.989128113 CET | 35342 | 52646 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:45.871953964 CET | 52648 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:45.991717100 CET | 35342 | 52648 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:45.992007017 CET | 52648 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:45.992105961 CET | 52648 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:46.111844063 CET | 35342 | 52648 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:46.111977100 CET | 52648 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:46.231615067 CET | 35342 | 52648 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:47.350054026 CET | 35342 | 52648 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:47.350296021 CET | 52648 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:47.469939947 CET | 35342 | 52648 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:48.352633953 CET | 52650 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:48.472425938 CET | 35342 | 52650 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:48.472583055 CET | 52650 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:48.472690105 CET | 52650 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:48.592242002 CET | 35342 | 52650 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:48.592597961 CET | 52650 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:48.712160110 CET | 35342 | 52650 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:48.769524097 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Dec 28, 2024 20:57:49.867712975 CET | 35342 | 52650 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:57:49.868227005 CET | 52650 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:57:49.989062071 CET | 35342 | 52650 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:09.246706963 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Dec 28, 2024 20:58:15.899960995 CET | 52652 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:16.019850016 CET | 35342 | 52652 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:16.020147085 CET | 52652 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:16.020313978 CET | 52652 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:16.139977932 CET | 35342 | 52652 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:16.140259981 CET | 52652 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:16.259788036 CET | 35342 | 52652 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:17.320291996 CET | 35342 | 52652 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:17.320688009 CET | 52652 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:17.440464020 CET | 35342 | 52652 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:20.269974947 CET | 52654 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:20.389559984 CET | 35342 | 52654 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:20.389789104 CET | 52654 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:20.389899015 CET | 52654 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:20.509506941 CET | 35342 | 52654 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:20.509784937 CET | 52654 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:20.630069017 CET | 35342 | 52654 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:21.738451004 CET | 35342 | 52654 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:21.738950014 CET | 52654 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:21.861236095 CET | 35342 | 52654 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:24.684784889 CET | 52656 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:24.804471016 CET | 35342 | 52656 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:24.804662943 CET | 52656 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:24.804760933 CET | 52656 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:24.924314022 CET | 35342 | 52656 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:24.924607038 CET | 52656 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:25.044331074 CET | 35342 | 52656 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:26.151056051 CET | 35342 | 52656 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:26.151412964 CET | 52656 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:26.271034002 CET | 35342 | 52656 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:27.153400898 CET | 52658 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:27.273098946 CET | 35342 | 52658 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:27.273279905 CET | 52658 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:27.273360014 CET | 52658 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:27.392899990 CET | 35342 | 52658 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:27.393054962 CET | 52658 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:27.512959003 CET | 35342 | 52658 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:28.666230917 CET | 35342 | 52658 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:28.666579008 CET | 52658 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:28.786744118 CET | 35342 | 52658 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:34.873807907 CET | 52660 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:34.993392944 CET | 35342 | 52660 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:34.993556976 CET | 52660 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:34.993700981 CET | 52660 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:35.113393068 CET | 35342 | 52660 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:35.113586903 CET | 52660 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:35.233311892 CET | 35342 | 52660 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:36.340702057 CET | 35342 | 52660 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:36.341015100 CET | 52660 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:36.460639954 CET | 35342 | 52660 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:37.342958927 CET | 52662 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:37.462636948 CET | 35342 | 52662 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:37.462780952 CET | 52662 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:37.462949991 CET | 52662 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:37.582437038 CET | 35342 | 52662 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:37.582631111 CET | 52662 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:37.702146053 CET | 35342 | 52662 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:38.763396025 CET | 35342 | 52662 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:38.763731956 CET | 52662 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:38.884001017 CET | 35342 | 52662 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:39.765424967 CET | 52664 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:39.885098934 CET | 35342 | 52664 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:39.885209084 CET | 52664 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:39.885412931 CET | 52664 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:40.004937887 CET | 35342 | 52664 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:40.005011082 CET | 52664 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:40.124818087 CET | 35342 | 52664 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:41.283400059 CET | 35342 | 52664 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 20:58:41.283674955 CET | 52664 | 35342 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 20:58:41.403321028 CET | 35342 | 52664 | 83.222.191.146 | 192.168.2.23 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 28, 2024 20:56:48.998517990 CET | 44523 | 53 | 192.168.2.23 | 185.228.168.168 |
Dec 28, 2024 20:56:49.250529051 CET | 53 | 44523 | 185.228.168.168 | 192.168.2.23 |
Dec 28, 2024 20:56:54.144364119 CET | 48064 | 53 | 192.168.2.23 | 77.88.8.8 |
Dec 28, 2024 20:56:54.441925049 CET | 53 | 48064 | 77.88.8.8 | 192.168.2.23 |
Dec 28, 2024 20:56:56.956398964 CET | 45721 | 53 | 192.168.2.23 | 202.46.34.75 |
Dec 28, 2024 20:56:57.498729944 CET | 53 | 45721 | 202.46.34.75 | 192.168.2.23 |
Dec 28, 2024 20:57:02.903114080 CET | 52471 | 53 | 192.168.2.23 | 1.1.1.1 |
Dec 28, 2024 20:57:03.049745083 CET | 53 | 52471 | 1.1.1.1 | 192.168.2.23 |
Dec 28, 2024 20:57:05.568922997 CET | 60901 | 53 | 192.168.2.23 | 203.112.2.4 |
Dec 28, 2024 20:57:10.575249910 CET | 34809 | 53 | 192.168.2.23 | 203.112.2.4 |
Dec 28, 2024 20:57:15.581533909 CET | 35321 | 53 | 192.168.2.23 | 203.112.2.4 |
Dec 28, 2024 20:57:20.587517977 CET | 43467 | 53 | 192.168.2.23 | 203.112.2.4 |
Dec 28, 2024 20:57:25.593403101 CET | 39845 | 53 | 192.168.2.23 | 203.112.2.4 |
Dec 28, 2024 20:57:35.541913033 CET | 59339 | 53 | 192.168.2.23 | 208.67.222.222 |
Dec 28, 2024 20:57:35.969420910 CET | 53 | 59339 | 208.67.222.222 | 192.168.2.23 |
Dec 28, 2024 20:57:50.871753931 CET | 38392 | 53 | 192.168.2.23 | 94.16.114.254 |
Dec 28, 2024 20:57:55.877969980 CET | 59862 | 53 | 192.168.2.23 | 94.16.114.254 |
Dec 28, 2024 20:58:00.884031057 CET | 47865 | 53 | 192.168.2.23 | 94.16.114.254 |
Dec 28, 2024 20:58:05.889281034 CET | 36682 | 53 | 192.168.2.23 | 94.16.114.254 |
Dec 28, 2024 20:58:10.894496918 CET | 56528 | 53 | 192.168.2.23 | 94.16.114.254 |
Dec 28, 2024 20:58:18.323788881 CET | 35401 | 53 | 192.168.2.23 | 196.216.2.1 |
Dec 28, 2024 20:58:18.710963011 CET | 53 | 35401 | 196.216.2.1 | 192.168.2.23 |
Dec 28, 2024 20:58:18.712630987 CET | 36696 | 53 | 192.168.2.23 | 196.216.2.1 |
Dec 28, 2024 20:58:19.100074053 CET | 53 | 36696 | 196.216.2.1 | 192.168.2.23 |
Dec 28, 2024 20:58:19.100929976 CET | 39766 | 53 | 192.168.2.23 | 196.216.2.1 |
Dec 28, 2024 20:58:19.488908052 CET | 53 | 39766 | 196.216.2.1 | 192.168.2.23 |
Dec 28, 2024 20:58:19.489902973 CET | 36421 | 53 | 192.168.2.23 | 196.216.2.1 |
Dec 28, 2024 20:58:19.879884958 CET | 53 | 36421 | 196.216.2.1 | 192.168.2.23 |
Dec 28, 2024 20:58:19.880908966 CET | 60980 | 53 | 192.168.2.23 | 196.216.2.1 |
Dec 28, 2024 20:58:20.268927097 CET | 53 | 60980 | 196.216.2.1 | 192.168.2.23 |
Dec 28, 2024 20:58:22.741277933 CET | 48292 | 53 | 192.168.2.23 | 196.216.2.1 |
Dec 28, 2024 20:58:23.133382082 CET | 53 | 48292 | 196.216.2.1 | 192.168.2.23 |
Dec 28, 2024 20:58:23.134622097 CET | 33436 | 53 | 192.168.2.23 | 196.216.2.1 |
Dec 28, 2024 20:58:23.520804882 CET | 53 | 33436 | 196.216.2.1 | 192.168.2.23 |
Dec 28, 2024 20:58:23.522473097 CET | 43407 | 53 | 192.168.2.23 | 196.216.2.1 |
Dec 28, 2024 20:58:23.908193111 CET | 53 | 43407 | 196.216.2.1 | 192.168.2.23 |
Dec 28, 2024 20:58:23.909832001 CET | 51600 | 53 | 192.168.2.23 | 196.216.2.1 |
Dec 28, 2024 20:58:24.294802904 CET | 53 | 51600 | 196.216.2.1 | 192.168.2.23 |
Dec 28, 2024 20:58:24.296565056 CET | 49985 | 53 | 192.168.2.23 | 196.216.2.1 |
Dec 28, 2024 20:58:24.683585882 CET | 53 | 49985 | 196.216.2.1 | 192.168.2.23 |
Dec 28, 2024 20:58:29.668788910 CET | 51974 | 53 | 192.168.2.23 | 178.22.122.100 |
Dec 28, 2024 20:58:34.674280882 CET | 39583 | 53 | 192.168.2.23 | 178.22.122.100 |
Dec 28, 2024 20:58:34.873092890 CET | 53 | 39583 | 178.22.122.100 | 192.168.2.23 |
Dec 28, 2024 20:58:42.286166906 CET | 38818 | 53 | 192.168.2.23 | 198.101.242.72 |
Dec 28, 2024 20:58:47.291991949 CET | 53126 | 53 | 192.168.2.23 | 198.101.242.72 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 28, 2024 20:56:48.998517990 CET | 192.168.2.23 | 185.228.168.168 | 0x1a10 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:56:54.144364119 CET | 192.168.2.23 | 77.88.8.8 | 0xbc92 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:56:56.956398964 CET | 192.168.2.23 | 202.46.34.75 | 0xe166 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:57:02.903114080 CET | 192.168.2.23 | 1.1.1.1 | 0xc5a9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:57:05.568922997 CET | 192.168.2.23 | 203.112.2.4 | 0x6376 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:57:10.575249910 CET | 192.168.2.23 | 203.112.2.4 | 0x6376 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:57:15.581533909 CET | 192.168.2.23 | 203.112.2.4 | 0x6376 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:57:20.587517977 CET | 192.168.2.23 | 203.112.2.4 | 0x6376 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:57:25.593403101 CET | 192.168.2.23 | 203.112.2.4 | 0x6376 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:57:35.541913033 CET | 192.168.2.23 | 208.67.222.222 | 0x2e95 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:57:50.871753931 CET | 192.168.2.23 | 94.16.114.254 | 0xf719 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:57:55.877969980 CET | 192.168.2.23 | 94.16.114.254 | 0xf719 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:58:00.884031057 CET | 192.168.2.23 | 94.16.114.254 | 0xf719 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:58:05.889281034 CET | 192.168.2.23 | 94.16.114.254 | 0xf719 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:58:10.894496918 CET | 192.168.2.23 | 94.16.114.254 | 0xf719 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:58:18.323788881 CET | 192.168.2.23 | 196.216.2.1 | 0xed4b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:58:18.712630987 CET | 192.168.2.23 | 196.216.2.1 | 0xed4b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:58:19.100929976 CET | 192.168.2.23 | 196.216.2.1 | 0xed4b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:58:19.489902973 CET | 192.168.2.23 | 196.216.2.1 | 0xed4b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:58:19.880908966 CET | 192.168.2.23 | 196.216.2.1 | 0xed4b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:58:22.741277933 CET | 192.168.2.23 | 196.216.2.1 | 0xe3b0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:58:23.134622097 CET | 192.168.2.23 | 196.216.2.1 | 0xe3b0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:58:23.522473097 CET | 192.168.2.23 | 196.216.2.1 | 0xe3b0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:58:23.909832001 CET | 192.168.2.23 | 196.216.2.1 | 0xe3b0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:58:24.296565056 CET | 192.168.2.23 | 196.216.2.1 | 0xe3b0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:58:29.668788910 CET | 192.168.2.23 | 178.22.122.100 | 0x9751 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:58:34.674280882 CET | 192.168.2.23 | 178.22.122.100 | 0x9751 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:58:42.286166906 CET | 192.168.2.23 | 198.101.242.72 | 0xc395 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:58:47.291991949 CET | 192.168.2.23 | 198.101.242.72 | 0xc395 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 28, 2024 20:56:49.250529051 CET | 185.228.168.168 | 192.168.2.23 | 0x1a10 | No error (0) | 83.222.191.146 | A (IP address) | IN (0x0001) | false | ||
Dec 28, 2024 20:56:54.441925049 CET | 77.88.8.8 | 192.168.2.23 | 0xbc92 | No error (0) | 83.222.191.146 | A (IP address) | IN (0x0001) | false | ||
Dec 28, 2024 20:56:57.498729944 CET | 202.46.34.75 | 192.168.2.23 | 0xe166 | No error (0) | 83.222.191.146 | A (IP address) | IN (0x0001) | false | ||
Dec 28, 2024 20:57:03.049745083 CET | 1.1.1.1 | 192.168.2.23 | 0xc5a9 | No error (0) | 83.222.191.146 | A (IP address) | IN (0x0001) | false | ||
Dec 28, 2024 20:57:35.969420910 CET | 208.67.222.222 | 192.168.2.23 | 0x2e95 | No error (0) | 83.222.191.146 | A (IP address) | IN (0x0001) | false | ||
Dec 28, 2024 20:58:18.710963011 CET | 196.216.2.1 | 192.168.2.23 | 0xed4b | Refused (5) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:58:19.100074053 CET | 196.216.2.1 | 192.168.2.23 | 0xed4b | Refused (5) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:58:19.488908052 CET | 196.216.2.1 | 192.168.2.23 | 0xed4b | Refused (5) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:58:19.879884958 CET | 196.216.2.1 | 192.168.2.23 | 0xed4b | Refused (5) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:58:20.268927097 CET | 196.216.2.1 | 192.168.2.23 | 0xed4b | Refused (5) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:58:23.133382082 CET | 196.216.2.1 | 192.168.2.23 | 0xe3b0 | Refused (5) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:58:23.520804882 CET | 196.216.2.1 | 192.168.2.23 | 0xe3b0 | Refused (5) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:58:23.908193111 CET | 196.216.2.1 | 192.168.2.23 | 0xe3b0 | Refused (5) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:58:24.294802904 CET | 196.216.2.1 | 192.168.2.23 | 0xe3b0 | Refused (5) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:58:24.683585882 CET | 196.216.2.1 | 192.168.2.23 | 0xe3b0 | Refused (5) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 20:58:34.873092890 CET | 178.22.122.100 | 192.168.2.23 | 0x9751 | No error (0) | 83.222.191.146 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 19:56:43 |
Start date (UTC): | 28/12/2024 |
Path: | /tmp/mpsl.elf |
Arguments: | /tmp/mpsl.elf |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 19:56:44 |
Start date (UTC): | 28/12/2024 |
Path: | /tmp/mpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 19:56:46 |
Start date (UTC): | 28/12/2024 |
Path: | /tmp/mpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 19:56:46 |
Start date (UTC): | 28/12/2024 |
Path: | /tmp/mpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 19:56:46 |
Start date (UTC): | 28/12/2024 |
Path: | /bin/sh |
Arguments: | sh -c "iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 19:56:46 |
Start date (UTC): | 28/12/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 19:56:46 |
Start date (UTC): | 28/12/2024 |
Path: | /usr/sbin/iptables |
Arguments: | iptables -A INPUT -p tcp --dport 26721 -j ACCEPT |
File size: | 99296 bytes |
MD5 hash: | 1ab05fef765b6342cdfadaa5275b33af |
Start time (UTC): | 19:56:46 |
Start date (UTC): | 28/12/2024 |
Path: | /tmp/mpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 19:56:46 |
Start date (UTC): | 28/12/2024 |
Path: | /bin/sh |
Arguments: | sh -c "/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 19:56:46 |
Start date (UTC): | 28/12/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 19:56:46 |
Start date (UTC): | 28/12/2024 |
Path: | /bin/busybox |
Arguments: | /bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT |
File size: | 2172376 bytes |
MD5 hash: | 70584dffe9cb0309eb22ba78aa54bcdc |
Start time (UTC): | 19:56:46 |
Start date (UTC): | 28/12/2024 |
Path: | /tmp/mpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 19:56:46 |
Start date (UTC): | 28/12/2024 |
Path: | /bin/sh |
Arguments: | sh -c "/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 19:56:46 |
Start date (UTC): | 28/12/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 19:56:46 |
Start date (UTC): | 28/12/2024 |
Path: | /tmp/mpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 19:56:46 |
Start date (UTC): | 28/12/2024 |
Path: | /bin/sh |
Arguments: | sh -c "/usr/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 19:56:46 |
Start date (UTC): | 28/12/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 19:56:46 |
Start date (UTC): | 28/12/2024 |
Path: | /tmp/mpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 19:56:46 |
Start date (UTC): | 28/12/2024 |
Path: | /bin/sh |
Arguments: | sh -c "busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 19:56:46 |
Start date (UTC): | 28/12/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 19:56:46 |
Start date (UTC): | 28/12/2024 |
Path: | /usr/bin/busybox |
Arguments: | busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT |
File size: | 2172376 bytes |
MD5 hash: | 70584dffe9cb0309eb22ba78aa54bcdc |
Start time (UTC): | 19:56:46 |
Start date (UTC): | 28/12/2024 |
Path: | /tmp/mpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |