Edit tour
Linux
Analysis Report
83.222.191.146-mips-2024-12-28T00_37_43.elf
Overview
General Information
Detection
Gafgyt
Score: | 72 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Yara detected Gafgyt
Connects to many ports of the same IP (likely port scanning)
Executes the "iptables" command to insert, remove and/or manipulate rules
Detected TCP or UDP traffic on non-standard ports
Executes commands using a shell command-line interpreter
Executes the "iptables" command used for managing IP filtering and manipulation
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1581814 |
Start date and time: | 2024-12-29 02:10:10 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 23s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | 83.222.191.146-mips-2024-12-28T00_37_43.elf |
Detection: | MAL |
Classification: | mal72.troj.linELF@0/0@20/0 |
Command: | /tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf |
PID: | 5432 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | listening dn0 |
Standard Error: |
- system is lnxubuntu20
- 83.222.191.146-mips-2024-12-28T00_37_43.elf New Fork (PID: 5434, Parent: 5432)
- 83.222.191.146-mips-2024-12-28T00_37_43.elf New Fork (PID: 5436, Parent: 5434)
- 83.222.191.146-mips-2024-12-28T00_37_43.elf New Fork (PID: 5438, Parent: 5436)
- sh New Fork (PID: 5444, Parent: 5438)
- 83.222.191.146-mips-2024-12-28T00_37_43.elf New Fork (PID: 5450, Parent: 5436)
- sh New Fork (PID: 5455, Parent: 5450)
- 83.222.191.146-mips-2024-12-28T00_37_43.elf New Fork (PID: 5456, Parent: 5436)
- sh New Fork (PID: 5461, Parent: 5456)
- 83.222.191.146-mips-2024-12-28T00_37_43.elf New Fork (PID: 5462, Parent: 5436)
- sh New Fork (PID: 5467, Parent: 5462)
- 83.222.191.146-mips-2024-12-28T00_37_43.elf New Fork (PID: 5468, Parent: 5436)
- sh New Fork (PID: 5473, Parent: 5468)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Bashlite, Gafgyt | Bashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS). Originally it was also known under the name Bashdoor, but this term now refers to the exploit method used by the malware. It has been used to launch attacks of up to 400 Gbps. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Gafgyt | Yara detected Gafgyt | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Gafgyt | Yara detected Gafgyt | Joe Security |
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Networking |
---|
Source: | TCP traffic: |
Source: | Iptables executable using switch for changing the iptables rules: | Jump to behavior |
Source: | TCP traffic: |
Source: | Iptables executable: | Jump to behavior |
Source: | Socket: | Jump to behavior | ||
Source: | Socket: | Jump to behavior |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: |
Source: | .symtab present: |
Source: | Classification label: |
Persistence and Installation Behavior |
---|
Source: | Iptables executable using switch for changing the iptables rules: | Jump to behavior |
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior |
Source: | Iptables executable: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | Windows Management Instrumentation | 1 Scripting | Path Interception | Direct Volume Access | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Non-Standard Port | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | 1 System Network Configuration Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
29% | ReversingLabs | Linux.Backdoor.Mirai | ||
100% | Avira | EXP/ELF.Agent.J.8 |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
secure-network-rebirthltd.ru | 83.222.191.146 | true | false | high | |
SECURE-NETWORK-REBIRTHLTD.RU | 83.222.191.146 | true | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
83.222.191.146 | secure-network-rebirthltd.ru | Bulgaria | 43561 | NET1-ASBG | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
83.222.191.146 | Get hash | malicious | Gafgyt | Browse |
| |
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
secure-network-rebirthltd.ru | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
SECURE-NETWORK-REBIRTHLTD.RU | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
NET1-ASBG | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 5.091403215701722 |
TrID: |
|
File name: | 83.222.191.146-mips-2024-12-28T00_37_43.elf |
File size: | 203'576 bytes |
MD5: | 4fae376f359f2e5514bbd7d28b42139c |
SHA1: | 0e5b1a2f630719a8102f0a8130403308387be219 |
SHA256: | 86ca658b2aad4022ede6aea02e8de3e30312bcf37be4429adac11efa77cc44df |
SHA512: | e7c0f54882e2451f524690293c985570fc54818c66367db17e48803cd1298d108b9d9ad8e19dc646d89797c19025290925954491c003569747133654aa4e3066 |
SSDEEP: | 3072:+xNydN4Ovn1NYu/HH3wdgjhVn50nvE8nTWdGHitw:+xNydNL/1NJ/HsgFl5D8idGCtw |
TLSH: | 6614A61E6E228F7EF76C873047B74E34A76923D627E1D684E1ACD1105F2029E541FBA8 |
File Content Preview: | .ELF.....................@.`...4.........4. ...(.............@...@...........................F...F....W.............dt.Q............................<...'......!'.......................<...'......!... ....'9... ......................<...'......!........'9. |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 203016 |
Section Header Size: | 40 |
Number of Section Headers: | 14 |
Header String Table Index: | 13 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x400094 | 0x94 | 0x8c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x400120 | 0x120 | 0x29a50 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x429b70 | 0x29b70 | 0x5c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x429bd0 | 0x29bd0 | 0x24f0 | 0x0 | 0x2 | A | 0 | 0 | 16 |
.ctors | PROGBITS | 0x46c0c4 | 0x2c0c4 | 0xc | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x46c0d0 | 0x2c0d0 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data.rel.ro | PROGBITS | 0x46c0dc | 0x2c0dc | 0x46c | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x46c560 | 0x2c560 | 0x4930 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.got | PROGBITS | 0x470e90 | 0x30e90 | 0xa14 | 0x4 | 0x10000003 | WAp | 0 | 0 | 16 |
.sbss | NOBITS | 0x4718a4 | 0x318a4 | 0x3c | 0x0 | 0x10000003 | WAp | 0 | 0 | 4 |
.bss | NOBITS | 0x4718e0 | 0x318a4 | 0x46c0 | 0x0 | 0x3 | WA | 0 | 0 | 16 |
.mdebug.abi32 | PROGBITS | 0x1440 | 0x318a4 | 0x0 | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0x318a4 | 0x64 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x400000 | 0x400000 | 0x2c0c0 | 0x2c0c0 | 5.4096 | 0x5 | R E | 0x10000 | .init .text .fini .rodata | |
LOAD | 0x2c0c4 | 0x46c0c4 | 0x46c0c4 | 0x57e0 | 0x9edc | 1.3782 | 0x6 | RW | 0x10000 | .ctors .dtors .data.rel.ro .data .got .sbss .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 29, 2024 02:10:54.653343916 CET | 41976 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:10:54.773019075 CET | 35342 | 41976 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:10:54.773080111 CET | 41976 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:10:54.773751974 CET | 41976 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:10:54.894232035 CET | 35342 | 41976 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:10:54.894285917 CET | 41976 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:10:55.014043093 CET | 35342 | 41976 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:10:55.025716066 CET | 53314 | 2222 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:10:55.145406008 CET | 2222 | 53314 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:10:55.145698071 CET | 53314 | 2222 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:10:55.146698952 CET | 53314 | 2222 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:10:55.146752119 CET | 53314 | 2222 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:10:55.266217947 CET | 2222 | 53314 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:10:55.308063984 CET | 2222 | 53314 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:10:56.992845058 CET | 35342 | 41976 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:10:56.993313074 CET | 41976 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:10:57.113116980 CET | 35342 | 41976 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:10:57.383040905 CET | 2222 | 53314 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:10:57.383266926 CET | 53314 | 2222 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:10:58.241916895 CET | 41980 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:10:58.361459017 CET | 35342 | 41980 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:10:58.361541986 CET | 41980 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:10:58.361582994 CET | 41980 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:10:58.481128931 CET | 35342 | 41980 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:10:58.481225967 CET | 41980 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:10:58.600719929 CET | 35342 | 41980 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:00.626630068 CET | 35342 | 41980 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:00.626796007 CET | 41980 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:00.746393919 CET | 35342 | 41980 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:01.628125906 CET | 41982 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:01.747824907 CET | 35342 | 41982 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:01.747917891 CET | 41982 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:01.748126984 CET | 41982 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:01.867554903 CET | 35342 | 41982 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:01.867638111 CET | 41982 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:01.988042116 CET | 35342 | 41982 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:03.976918936 CET | 35342 | 41982 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:03.977076054 CET | 41982 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:04.096774101 CET | 35342 | 41982 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:04.978435993 CET | 41984 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:05.098149061 CET | 35342 | 41984 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:05.098252058 CET | 41984 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:05.098423004 CET | 41984 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:05.217987061 CET | 35342 | 41984 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:05.218075991 CET | 41984 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:05.337676048 CET | 35342 | 41984 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:07.345077991 CET | 35342 | 41984 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:07.345494032 CET | 41984 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:07.465181112 CET | 35342 | 41984 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:08.595659018 CET | 41986 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:08.715410948 CET | 35342 | 41986 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:08.715579033 CET | 41986 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:08.715579033 CET | 41986 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:08.835195065 CET | 35342 | 41986 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:08.835450888 CET | 41986 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:08.955137014 CET | 35342 | 41986 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:10.998619080 CET | 35342 | 41986 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:10.998877048 CET | 41986 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:11.118580103 CET | 35342 | 41986 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:12.001106024 CET | 41988 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:12.120939970 CET | 35342 | 41988 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:12.121198893 CET | 41988 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:12.121289968 CET | 41988 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:12.240875006 CET | 35342 | 41988 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:12.241134882 CET | 41988 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:12.360699892 CET | 35342 | 41988 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:14.357717037 CET | 35342 | 41988 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:14.357927084 CET | 41988 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:14.477468967 CET | 35342 | 41988 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:15.359280109 CET | 41990 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:15.479123116 CET | 35342 | 41990 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:15.479279995 CET | 41990 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:15.479378939 CET | 41990 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:15.599087000 CET | 35342 | 41990 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:15.599206924 CET | 41990 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:15.718841076 CET | 35342 | 41990 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:17.763219118 CET | 35342 | 41990 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:17.763375044 CET | 41990 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:17.883035898 CET | 35342 | 41990 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:19.015708923 CET | 41992 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:19.135554075 CET | 35342 | 41992 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:19.135641098 CET | 41992 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:19.135663986 CET | 41992 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:19.255275965 CET | 35342 | 41992 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:19.255350113 CET | 41992 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:19.375664949 CET | 35342 | 41992 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:21.451433897 CET | 35342 | 41992 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:21.451677084 CET | 41992 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:21.571330070 CET | 35342 | 41992 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:47.484870911 CET | 41994 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:47.605005980 CET | 35342 | 41994 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:47.605227947 CET | 41994 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:47.605227947 CET | 41994 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:47.724872112 CET | 35342 | 41994 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:47.725069046 CET | 41994 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:47.844611883 CET | 35342 | 41994 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:49.921009064 CET | 35342 | 41994 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:49.921554089 CET | 41994 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:50.041204929 CET | 35342 | 41994 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:54.302298069 CET | 41996 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:54.421950102 CET | 35342 | 41996 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:54.422219992 CET | 41996 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:54.422339916 CET | 41996 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:54.541816950 CET | 35342 | 41996 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:54.542043924 CET | 41996 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:54.661799908 CET | 35342 | 41996 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:56.662477970 CET | 35342 | 41996 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:56.662878990 CET | 41996 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:56.782453060 CET | 35342 | 41996 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:57.895819902 CET | 41998 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:58.015599966 CET | 35342 | 41998 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:58.015757084 CET | 41998 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:58.016015053 CET | 41998 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:58.135520935 CET | 35342 | 41998 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:11:58.135612965 CET | 41998 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:11:58.255398989 CET | 35342 | 41998 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:12:00.296461105 CET | 35342 | 41998 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:12:00.296920061 CET | 41998 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:12:00.416618109 CET | 35342 | 41998 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:12:01.528938055 CET | 42000 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:12:01.648653984 CET | 35342 | 42000 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:12:01.648806095 CET | 42000 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:12:01.648917913 CET | 42000 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:12:01.768496990 CET | 35342 | 42000 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:12:01.768693924 CET | 42000 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:12:01.888552904 CET | 35342 | 42000 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:12:03.896425009 CET | 35342 | 42000 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:12:03.896923065 CET | 42000 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:12:04.016701937 CET | 35342 | 42000 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:12:18.099004030 CET | 42002 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:12:18.218878984 CET | 35342 | 42002 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:12:18.219012976 CET | 42002 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:12:18.219083071 CET | 42002 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:12:18.338651896 CET | 35342 | 42002 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:12:18.338732958 CET | 42002 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:12:18.458374977 CET | 35342 | 42002 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:12:20.475038052 CET | 35342 | 42002 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:12:20.475249052 CET | 42002 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:12:20.594963074 CET | 35342 | 42002 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:12:46.503654957 CET | 42004 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:12:46.623456001 CET | 35342 | 42004 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:12:46.623581886 CET | 42004 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:12:46.623626947 CET | 42004 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:12:46.743240118 CET | 35342 | 42004 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:12:46.743331909 CET | 42004 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:12:46.863029003 CET | 35342 | 42004 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:12:48.887895107 CET | 35342 | 42004 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:12:48.888051033 CET | 42004 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:12:49.007637024 CET | 35342 | 42004 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:12:49.889616966 CET | 42006 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:12:50.009454966 CET | 35342 | 42006 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:12:50.009531975 CET | 42006 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:12:50.009557962 CET | 42006 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:12:50.129385948 CET | 35342 | 42006 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:12:50.129451990 CET | 42006 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:12:50.249077082 CET | 35342 | 42006 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:12:52.293901920 CET | 35342 | 42006 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:12:52.294148922 CET | 42006 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:12:52.413863897 CET | 35342 | 42006 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:12:53.295357943 CET | 42008 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:12:53.415237904 CET | 35342 | 42008 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:12:53.415323019 CET | 42008 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:12:53.415357113 CET | 42008 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:12:53.535026073 CET | 35342 | 42008 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:12:53.535120010 CET | 42008 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:12:53.654709101 CET | 35342 | 42008 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:12:55.675334930 CET | 35342 | 42008 | 83.222.191.146 | 192.168.2.13 |
Dec 29, 2024 02:12:55.675445080 CET | 42008 | 35342 | 192.168.2.13 | 83.222.191.146 |
Dec 29, 2024 02:12:55.795088053 CET | 35342 | 42008 | 83.222.191.146 | 192.168.2.13 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 29, 2024 02:10:57.995721102 CET | 33165 | 53 | 192.168.2.13 | 194.36.144.87 |
Dec 29, 2024 02:10:58.240596056 CET | 53 | 33165 | 194.36.144.87 | 192.168.2.13 |
Dec 29, 2024 02:11:08.348295927 CET | 43151 | 53 | 192.168.2.13 | 51.158.108.203 |
Dec 29, 2024 02:11:08.594934940 CET | 53 | 43151 | 51.158.108.203 | 192.168.2.13 |
Dec 29, 2024 02:11:18.765136003 CET | 47264 | 53 | 192.168.2.13 | 51.158.108.203 |
Dec 29, 2024 02:11:19.015228987 CET | 53 | 47264 | 51.158.108.203 | 192.168.2.13 |
Dec 29, 2024 02:11:22.454236984 CET | 56919 | 53 | 192.168.2.13 | 178.254.22.166 |
Dec 29, 2024 02:11:27.460922003 CET | 41430 | 53 | 192.168.2.13 | 178.254.22.166 |
Dec 29, 2024 02:11:32.467212915 CET | 44167 | 53 | 192.168.2.13 | 178.254.22.166 |
Dec 29, 2024 02:11:37.473124981 CET | 53074 | 53 | 192.168.2.13 | 178.254.22.166 |
Dec 29, 2024 02:11:42.479147911 CET | 51230 | 53 | 192.168.2.13 | 178.254.22.166 |
Dec 29, 2024 02:11:50.924520016 CET | 50654 | 53 | 192.168.2.13 | 51.77.149.139 |
Dec 29, 2024 02:11:54.300889015 CET | 53 | 50654 | 51.77.149.139 | 192.168.2.13 |
Dec 29, 2024 02:11:57.665663004 CET | 34656 | 53 | 192.168.2.13 | 195.10.195.195 |
Dec 29, 2024 02:11:57.894932032 CET | 53 | 34656 | 195.10.195.195 | 192.168.2.13 |
Dec 29, 2024 02:12:01.299707890 CET | 56276 | 53 | 192.168.2.13 | 195.10.195.195 |
Dec 29, 2024 02:12:01.528115034 CET | 53 | 56276 | 195.10.195.195 | 192.168.2.13 |
Dec 29, 2024 02:12:04.899559021 CET | 36565 | 53 | 192.168.2.13 | 51.77.149.139 |
Dec 29, 2024 02:12:09.905422926 CET | 37598 | 53 | 192.168.2.13 | 51.77.149.139 |
Dec 29, 2024 02:12:14.911082029 CET | 37000 | 53 | 192.168.2.13 | 51.77.149.139 |
Dec 29, 2024 02:12:18.098251104 CET | 53 | 37000 | 51.77.149.139 | 192.168.2.13 |
Dec 29, 2024 02:12:21.476902008 CET | 57955 | 53 | 192.168.2.13 | 51.254.162.59 |
Dec 29, 2024 02:12:26.483335972 CET | 57901 | 53 | 192.168.2.13 | 51.254.162.59 |
Dec 29, 2024 02:12:31.489737988 CET | 55476 | 53 | 192.168.2.13 | 51.254.162.59 |
Dec 29, 2024 02:12:36.496157885 CET | 39887 | 53 | 192.168.2.13 | 51.254.162.59 |
Dec 29, 2024 02:12:41.498141050 CET | 54717 | 53 | 192.168.2.13 | 51.254.162.59 |
Dec 29, 2024 02:12:56.676954985 CET | 37335 | 53 | 192.168.2.13 | 94.16.114.254 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 29, 2024 02:10:57.995721102 CET | 192.168.2.13 | 194.36.144.87 | 0x50d3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 29, 2024 02:11:08.348295927 CET | 192.168.2.13 | 51.158.108.203 | 0xf0f9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 29, 2024 02:11:18.765136003 CET | 192.168.2.13 | 51.158.108.203 | 0x75c9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 29, 2024 02:11:22.454236984 CET | 192.168.2.13 | 178.254.22.166 | 0xca87 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 29, 2024 02:11:27.460922003 CET | 192.168.2.13 | 178.254.22.166 | 0xca87 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 29, 2024 02:11:32.467212915 CET | 192.168.2.13 | 178.254.22.166 | 0xca87 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 29, 2024 02:11:37.473124981 CET | 192.168.2.13 | 178.254.22.166 | 0xca87 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 29, 2024 02:11:42.479147911 CET | 192.168.2.13 | 178.254.22.166 | 0xca87 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 29, 2024 02:11:50.924520016 CET | 192.168.2.13 | 51.77.149.139 | 0x1eb8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 29, 2024 02:11:57.665663004 CET | 192.168.2.13 | 195.10.195.195 | 0xe31e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 29, 2024 02:12:01.299707890 CET | 192.168.2.13 | 195.10.195.195 | 0xa11e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 29, 2024 02:12:04.899559021 CET | 192.168.2.13 | 51.77.149.139 | 0xbd94 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 29, 2024 02:12:09.905422926 CET | 192.168.2.13 | 51.77.149.139 | 0xbd94 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 29, 2024 02:12:14.911082029 CET | 192.168.2.13 | 51.77.149.139 | 0xbd94 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 29, 2024 02:12:21.476902008 CET | 192.168.2.13 | 51.254.162.59 | 0xffbd | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 29, 2024 02:12:26.483335972 CET | 192.168.2.13 | 51.254.162.59 | 0xffbd | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 29, 2024 02:12:31.489737988 CET | 192.168.2.13 | 51.254.162.59 | 0xffbd | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 29, 2024 02:12:36.496157885 CET | 192.168.2.13 | 51.254.162.59 | 0xffbd | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 29, 2024 02:12:41.498141050 CET | 192.168.2.13 | 51.254.162.59 | 0xffbd | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 29, 2024 02:12:56.676954985 CET | 192.168.2.13 | 94.16.114.254 | 0x58a8 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 29, 2024 02:10:58.240596056 CET | 194.36.144.87 | 192.168.2.13 | 0x50d3 | No error (0) | 83.222.191.146 | A (IP address) | IN (0x0001) | false | ||
Dec 29, 2024 02:11:08.594934940 CET | 51.158.108.203 | 192.168.2.13 | 0xf0f9 | No error (0) | 83.222.191.146 | A (IP address) | IN (0x0001) | false | ||
Dec 29, 2024 02:11:19.015228987 CET | 51.158.108.203 | 192.168.2.13 | 0x75c9 | No error (0) | 83.222.191.146 | A (IP address) | IN (0x0001) | false | ||
Dec 29, 2024 02:11:54.300889015 CET | 51.77.149.139 | 192.168.2.13 | 0x1eb8 | No error (0) | 83.222.191.146 | A (IP address) | IN (0x0001) | false | ||
Dec 29, 2024 02:11:57.894932032 CET | 195.10.195.195 | 192.168.2.13 | 0xe31e | No error (0) | 83.222.191.146 | A (IP address) | IN (0x0001) | false | ||
Dec 29, 2024 02:12:01.528115034 CET | 195.10.195.195 | 192.168.2.13 | 0xa11e | No error (0) | 83.222.191.146 | A (IP address) | IN (0x0001) | false | ||
Dec 29, 2024 02:12:18.098251104 CET | 51.77.149.139 | 192.168.2.13 | 0xbd94 | No error (0) | 83.222.191.146 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 01:10:52 |
Start date (UTC): | 29/12/2024 |
Path: | /tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf |
Arguments: | /tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf |
File size: | 5777432 bytes |
MD5 hash: | 0083f1f0e77be34ad27f849842bbb00c |
Start time (UTC): | 01:10:52 |
Start date (UTC): | 29/12/2024 |
Path: | /tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf |
Arguments: | - |
File size: | 5777432 bytes |
MD5 hash: | 0083f1f0e77be34ad27f849842bbb00c |
Start time (UTC): | 01:10:54 |
Start date (UTC): | 29/12/2024 |
Path: | /tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf |
Arguments: | - |
File size: | 5777432 bytes |
MD5 hash: | 0083f1f0e77be34ad27f849842bbb00c |
Start time (UTC): | 01:10:54 |
Start date (UTC): | 29/12/2024 |
Path: | /tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf |
Arguments: | - |
File size: | 5777432 bytes |
MD5 hash: | 0083f1f0e77be34ad27f849842bbb00c |
Start time (UTC): | 01:10:54 |
Start date (UTC): | 29/12/2024 |
Path: | /bin/sh |
Arguments: | sh -c "iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 01:10:54 |
Start date (UTC): | 29/12/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 01:10:54 |
Start date (UTC): | 29/12/2024 |
Path: | /usr/sbin/iptables |
Arguments: | iptables -A INPUT -p tcp --dport 26721 -j ACCEPT |
File size: | 99296 bytes |
MD5 hash: | 1ab05fef765b6342cdfadaa5275b33af |
Start time (UTC): | 01:10:54 |
Start date (UTC): | 29/12/2024 |
Path: | /tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf |
Arguments: | - |
File size: | 5777432 bytes |
MD5 hash: | 0083f1f0e77be34ad27f849842bbb00c |
Start time (UTC): | 01:10:54 |
Start date (UTC): | 29/12/2024 |
Path: | /bin/sh |
Arguments: | sh -c "/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 01:10:54 |
Start date (UTC): | 29/12/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 01:10:54 |
Start date (UTC): | 29/12/2024 |
Path: | /bin/busybox |
Arguments: | /bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT |
File size: | 2172376 bytes |
MD5 hash: | 70584dffe9cb0309eb22ba78aa54bcdc |
Start time (UTC): | 01:10:54 |
Start date (UTC): | 29/12/2024 |
Path: | /tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf |
Arguments: | - |
File size: | 5777432 bytes |
MD5 hash: | 0083f1f0e77be34ad27f849842bbb00c |
Start time (UTC): | 01:10:54 |
Start date (UTC): | 29/12/2024 |
Path: | /bin/sh |
Arguments: | sh -c "/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 01:10:54 |
Start date (UTC): | 29/12/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 01:10:54 |
Start date (UTC): | 29/12/2024 |
Path: | /tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf |
Arguments: | - |
File size: | 5777432 bytes |
MD5 hash: | 0083f1f0e77be34ad27f849842bbb00c |
Start time (UTC): | 01:10:54 |
Start date (UTC): | 29/12/2024 |
Path: | /bin/sh |
Arguments: | sh -c "/usr/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 01:10:54 |
Start date (UTC): | 29/12/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 01:10:54 |
Start date (UTC): | 29/12/2024 |
Path: | /tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf |
Arguments: | - |
File size: | 5777432 bytes |
MD5 hash: | 0083f1f0e77be34ad27f849842bbb00c |
Start time (UTC): | 01:10:54 |
Start date (UTC): | 29/12/2024 |
Path: | /bin/sh |
Arguments: | sh -c "busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 01:10:54 |
Start date (UTC): | 29/12/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 01:10:54 |
Start date (UTC): | 29/12/2024 |
Path: | /usr/bin/busybox |
Arguments: | busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT |
File size: | 2172376 bytes |
MD5 hash: | 70584dffe9cb0309eb22ba78aa54bcdc |