Edit tour
Linux
Analysis Report
mips.elf
Overview
General Information
Detection
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1581770 |
Start date and time: | 2024-12-28 23:41:08 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 27s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | mips.elf |
Detection: | MAL |
Classification: | mal56.linELF@0/0@3/0 |
- VT rate limit hit for: mips.elf
Command: | /tmp/mips.elf |
PID: | 6213 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | have onna deez nutz |
Standard Error: |
⊘No yara matches
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | .symtab present: |
Source: | Classification label: |
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | 1 File Deletion | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 2 Application Layer Protocol | Traffic Duplication | Data Destruction |
⊘No configs have been found
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
24% | ReversingLabs | Linux.Trojan.Mirai | ||
100% | Avira | EXP/ELF.Mirai.W |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
secure-network-rebirthltd.ru | 83.222.191.146 | true | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
83.222.191.146 | secure-network-rebirthltd.ru | Bulgaria | 43561 | NET1-ASBG | false | |
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
91.189.91.43 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
83.222.191.146 | Get hash | malicious | Gafgyt | Browse |
| |
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
109.202.202.202 | Get hash | malicious | Unknown | Browse |
| |
91.189.91.43 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
secure-network-rebirthltd.ru | Get hash | malicious | Gafgyt | Browse |
| |
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CANONICAL-ASGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Nanominer, Xmrig | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
CANONICAL-ASGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Nanominer, Xmrig | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
INIT7CH | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
NET1-ASBG | Get hash | malicious | Gafgyt | Browse |
| |
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 5.497654885804482 |
TrID: |
|
File name: | mips.elf |
File size: | 69'096 bytes |
MD5: | 967d2516f1bb6814570f270bf114e779 |
SHA1: | f1ad99cb8844433ef78fed7b05326f55094cec9e |
SHA256: | 1a277c37236c7f81798518774b8a503060f075c2f5f80d8891737f099568b0cd |
SHA512: | 265b74f2fb14470f649919d258c6e451b2e5ef31a61815244cf4c25c6ed248bb4123f475ac321acf0a53ab7f0a00843b0e1c58a9e935d8e43b871f8658b39426 |
SSDEEP: | 1536:BLKz2yczcVjADOCzfLbILbONbqzrgM7PKw9UeYVWOz:0z2yczciDOCaN7PKw8WI |
TLSH: | BD63B71A6E219FECF768873147B78E21A398339527E1C785E15CD6002E7034D686FFA8 |
File Content Preview: | .ELF.....................@.`...4.........4. ...(.............@...@.....P...P...............T.E.T.E.T......(.........dt.Q............................<...'......!'.......................<...'......!... ....'9... ......................<...'..x...!........'9. |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 68536 |
Section Header Size: | 40 |
Number of Section Headers: | 14 |
Header String Table Index: | 13 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x400094 | 0x94 | 0x8c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x400120 | 0x120 | 0xf070 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x40f190 | 0xf190 | 0x5c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x40f1f0 | 0xf1f0 | 0x1260 | 0x0 | 0x2 | A | 0 | 0 | 16 |
.ctors | PROGBITS | 0x450454 | 0x10454 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x45045c | 0x1045c | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data.rel.ro | PROGBITS | 0x450468 | 0x10468 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x450470 | 0x10470 | 0x300 | 0x0 | 0x3 | WA | 0 | 0 | 16 |
.got | PROGBITS | 0x450770 | 0x10770 | 0x3e4 | 0x4 | 0x10000003 | WAp | 0 | 0 | 16 |
.sbss | NOBITS | 0x450b54 | 0x10b54 | 0x10 | 0x0 | 0x10000003 | WAp | 0 | 0 | 4 |
.bss | NOBITS | 0x450b70 | 0x10b54 | 0x2198 | 0x0 | 0x3 | WA | 0 | 0 | 16 |
.mdebug.abi32 | PROGBITS | 0x924 | 0x10b54 | 0x0 | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0x10b54 | 0x64 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x400000 | 0x400000 | 0x10450 | 0x10450 | 5.5383 | 0x5 | R E | 0x10000 | .init .text .fini .rodata | |
LOAD | 0x10454 | 0x450454 | 0x450454 | 0x700 | 0x28b4 | 3.4027 | 0x6 | RW | 0x10000 | .ctors .dtors .data.rel.ro .data .got .sbss .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 28, 2024 23:41:45.787364006 CET | 56504 | 33211 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 23:41:45.906913996 CET | 33211 | 56504 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 23:41:45.907082081 CET | 56504 | 33211 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 23:41:45.907766104 CET | 56504 | 33211 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 23:41:46.027280092 CET | 33211 | 56504 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 23:41:46.027369022 CET | 56504 | 33211 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 23:41:46.147058964 CET | 33211 | 56504 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 23:41:46.240710974 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Dec 28, 2024 23:41:47.265808105 CET | 33211 | 56504 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 23:41:47.266133070 CET | 56504 | 33211 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 23:41:47.266257048 CET | 56504 | 33211 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 23:41:48.507428885 CET | 56506 | 33211 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 23:41:48.627115965 CET | 33211 | 56506 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 23:41:48.627280951 CET | 56506 | 33211 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 23:41:48.628001928 CET | 56506 | 33211 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 23:41:48.747664928 CET | 33211 | 56506 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 23:41:48.747854948 CET | 56506 | 33211 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 23:41:48.867400885 CET | 33211 | 56506 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 23:41:50.019432068 CET | 33211 | 56506 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 23:41:50.019716024 CET | 56506 | 33211 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 23:41:50.019716978 CET | 56506 | 33211 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 23:41:51.260937929 CET | 56508 | 33211 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 23:41:51.380573988 CET | 33211 | 56508 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 23:41:51.380639076 CET | 56508 | 33211 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 23:41:51.381613970 CET | 56508 | 33211 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 23:41:51.501127958 CET | 33211 | 56508 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 23:41:51.501301050 CET | 56508 | 33211 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 23:41:51.615860939 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Dec 28, 2024 23:41:51.620791912 CET | 33211 | 56508 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 23:41:53.407644987 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Dec 28, 2024 23:42:01.390680075 CET | 56508 | 33211 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 23:42:01.510642052 CET | 33211 | 56508 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 23:42:01.830864906 CET | 33211 | 56508 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 23:42:01.831121922 CET | 56508 | 33211 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 23:42:07.485699892 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Dec 28, 2024 23:42:17.724237919 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Dec 28, 2024 23:42:23.867259026 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Dec 28, 2024 23:42:48.439862013 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Dec 28, 2024 23:43:01.882183075 CET | 56508 | 33211 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 23:43:02.230014086 CET | 56508 | 33211 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 23:43:02.270328045 CET | 33211 | 56508 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 23:43:02.349574089 CET | 33211 | 56508 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 23:43:02.581082106 CET | 33211 | 56508 | 83.222.191.146 | 192.168.2.23 |
Dec 28, 2024 23:43:02.581157923 CET | 56508 | 33211 | 192.168.2.23 | 83.222.191.146 |
Dec 28, 2024 23:43:08.917038918 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 28, 2024 23:41:45.547727108 CET | 34189 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:41:45.786328077 CET | 53 | 34189 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:41:48.268460035 CET | 51740 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:41:48.506772041 CET | 53 | 51740 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:41:51.021333933 CET | 59773 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:41:51.259921074 CET | 53 | 59773 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:10.603794098 CET | 45380 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:10.726094961 CET | 53 | 45380 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:10.727502108 CET | 35742 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:10.849734068 CET | 53 | 35742 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:10.851090908 CET | 49626 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:10.973453999 CET | 53 | 49626 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:10.974771023 CET | 42531 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:11.097091913 CET | 53 | 42531 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:11.098424911 CET | 47922 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:11.220858097 CET | 53 | 47922 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:15.234822035 CET | 38984 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:15.357738018 CET | 53 | 38984 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:15.359164953 CET | 43513 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:15.481600046 CET | 53 | 43513 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:15.483192921 CET | 36818 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:15.605431080 CET | 53 | 36818 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:15.606831074 CET | 41876 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:15.729053974 CET | 53 | 41876 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:15.730367899 CET | 47044 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:15.852493048 CET | 53 | 47044 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:19.856113911 CET | 48149 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:19.978384972 CET | 53 | 48149 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:19.979681969 CET | 33036 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:20.103149891 CET | 53 | 33036 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:20.103986979 CET | 51483 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:20.226283073 CET | 53 | 51483 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:20.230767965 CET | 51230 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:20.352896929 CET | 53 | 51230 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:20.354293108 CET | 46951 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:20.476432085 CET | 53 | 46951 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:23.480092049 CET | 54302 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:23.602407932 CET | 53 | 54302 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:23.603759050 CET | 45084 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:23.726162910 CET | 53 | 45084 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:23.727503061 CET | 46193 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:23.849682093 CET | 53 | 46193 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:23.850812912 CET | 46327 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:23.972990036 CET | 53 | 46327 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:23.974129915 CET | 55814 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:24.096272945 CET | 53 | 55814 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:34.098248005 CET | 41757 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:34.220748901 CET | 53 | 41757 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:34.221752882 CET | 55853 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:34.344062090 CET | 53 | 55853 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:34.344820976 CET | 55852 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:34.467128038 CET | 53 | 55852 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:34.467901945 CET | 58686 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:34.590817928 CET | 53 | 58686 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:34.591900110 CET | 44667 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:34.714302063 CET | 53 | 44667 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:35.717650890 CET | 38151 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:35.840255976 CET | 53 | 38151 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:35.841423988 CET | 59023 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:35.963685036 CET | 53 | 59023 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:35.964819908 CET | 38977 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:36.087213039 CET | 53 | 38977 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:36.088709116 CET | 44802 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:36.211153984 CET | 53 | 44802 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:36.212373018 CET | 50829 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:36.334580898 CET | 53 | 50829 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:43.337156057 CET | 52086 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:43.459441900 CET | 53 | 52086 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:43.460690022 CET | 46218 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:43.583039045 CET | 53 | 46218 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:43.584361076 CET | 49740 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:43.706541061 CET | 53 | 49740 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:43.707825899 CET | 55021 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:43.829957962 CET | 53 | 55021 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:43.831408978 CET | 53617 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:43.953598022 CET | 53 | 53617 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:51.955599070 CET | 44923 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:52.077985048 CET | 53 | 44923 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:52.079263926 CET | 57834 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:52.201580048 CET | 53 | 57834 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:52.202903986 CET | 54755 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:52.325104952 CET | 53 | 54755 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:52.326211929 CET | 48095 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:52.448400021 CET | 53 | 48095 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:42:52.449336052 CET | 36517 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:42:52.571547985 CET | 53 | 36517 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:01.574048042 CET | 57384 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:01.698883057 CET | 53 | 57384 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:01.699923992 CET | 45074 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:01.822118998 CET | 53 | 45074 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:01.823158979 CET | 45460 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:01.945594072 CET | 53 | 45460 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:01.946655989 CET | 36543 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:02.273147106 CET | 53 | 36543 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:02.274585962 CET | 45333 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:02.398380995 CET | 53 | 45333 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:08.401312113 CET | 48702 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:08.523480892 CET | 53 | 48702 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:08.524749994 CET | 43975 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:08.646928072 CET | 53 | 43975 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:08.648360014 CET | 44666 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:08.770705938 CET | 53 | 44666 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:08.772106886 CET | 48315 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:08.894710064 CET | 53 | 48315 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:08.896061897 CET | 57195 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:09.018215895 CET | 53 | 57195 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:13.021382093 CET | 33072 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:13.143949032 CET | 53 | 33072 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:13.145158052 CET | 48326 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:13.267364025 CET | 53 | 48326 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:13.268538952 CET | 55411 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:13.390744925 CET | 53 | 55411 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:13.392090082 CET | 33909 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:13.514405966 CET | 53 | 33909 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:13.515825987 CET | 36353 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:13.637989044 CET | 53 | 36353 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:22.640724897 CET | 47187 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:22.762865067 CET | 53 | 47187 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:22.764241934 CET | 40665 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:22.889365911 CET | 53 | 40665 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:22.890614986 CET | 51019 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:23.013144016 CET | 53 | 51019 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:23.014509916 CET | 40557 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:23.136816978 CET | 53 | 40557 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:23.138056040 CET | 34610 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:23.260325909 CET | 53 | 34610 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:33.263206005 CET | 48371 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:33.385432959 CET | 53 | 48371 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:33.386920929 CET | 38041 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:33.509157896 CET | 53 | 38041 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:33.510292053 CET | 57936 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:33.632687092 CET | 53 | 57936 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:33.634013891 CET | 54824 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:33.756277084 CET | 53 | 54824 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:33.757554054 CET | 39776 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:33.879765034 CET | 53 | 39776 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:41.883189917 CET | 44990 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:42.005444050 CET | 53 | 44990 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:42.006897926 CET | 49947 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:42.129329920 CET | 53 | 49947 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:42.130889893 CET | 37453 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:42.253233910 CET | 53 | 37453 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:42.254798889 CET | 47719 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:42.378619909 CET | 53 | 47719 | 8.8.8.8 | 192.168.2.23 |
Dec 28, 2024 23:43:42.380006075 CET | 50120 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 28, 2024 23:43:42.502249956 CET | 53 | 50120 | 8.8.8.8 | 192.168.2.23 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 28, 2024 23:41:45.547727108 CET | 192.168.2.23 | 8.8.8.8 | 0xde65 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 23:41:48.268460035 CET | 192.168.2.23 | 8.8.8.8 | 0x5e0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 28, 2024 23:41:51.021333933 CET | 192.168.2.23 | 8.8.8.8 | 0xb8e7 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 28, 2024 23:41:45.786328077 CET | 8.8.8.8 | 192.168.2.23 | 0xde65 | No error (0) | 83.222.191.146 | A (IP address) | IN (0x0001) | false | ||
Dec 28, 2024 23:41:48.506772041 CET | 8.8.8.8 | 192.168.2.23 | 0x5e0 | No error (0) | 83.222.191.146 | A (IP address) | IN (0x0001) | false | ||
Dec 28, 2024 23:41:51.259921074 CET | 8.8.8.8 | 192.168.2.23 | 0xb8e7 | No error (0) | 83.222.191.146 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 22:41:36 |
Start date (UTC): | 28/12/2024 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 22:41:36 |
Start date (UTC): | 28/12/2024 |
Path: | /usr/bin/rm |
Arguments: | rm -f /tmp/tmp.F02Dsps0eM /tmp/tmp.P3cl1kNhyB /tmp/tmp.24MARRrsp0 |
File size: | 72056 bytes |
MD5 hash: | aa2b5496fdbfd88e38791ab81f90b95b |
Start time (UTC): | 22:41:36 |
Start date (UTC): | 28/12/2024 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 22:41:36 |
Start date (UTC): | 28/12/2024 |
Path: | /usr/bin/rm |
Arguments: | rm -f /tmp/tmp.F02Dsps0eM /tmp/tmp.P3cl1kNhyB /tmp/tmp.24MARRrsp0 |
File size: | 72056 bytes |
MD5 hash: | aa2b5496fdbfd88e38791ab81f90b95b |
Start time (UTC): | 22:41:44 |
Start date (UTC): | 28/12/2024 |
Path: | /tmp/mips.elf |
Arguments: | /tmp/mips.elf |
File size: | 5777432 bytes |
MD5 hash: | 0083f1f0e77be34ad27f849842bbb00c |
Start time (UTC): | 22:41:44 |
Start date (UTC): | 28/12/2024 |
Path: | /tmp/mips.elf |
Arguments: | - |
File size: | 5777432 bytes |
MD5 hash: | 0083f1f0e77be34ad27f849842bbb00c |
Start time (UTC): | 22:41:44 |
Start date (UTC): | 28/12/2024 |
Path: | /tmp/mips.elf |
Arguments: | - |
File size: | 5777432 bytes |
MD5 hash: | 0083f1f0e77be34ad27f849842bbb00c |