Edit tour
Linux
Analysis Report
Aqua.i686.elf
Overview
General Information
Sample name: | Aqua.i686.elf |
Analysis ID: | 1581825 |
MD5: | e9eccfb9834ec789ab345b0e6e62e16a |
SHA1: | 5ddc158f3bf417469945cc18c97259b67a9f1c08 |
SHA256: | d2eb57a740a285202cb4224d7453334fd5c0b3d170288575a5eb91fb191bd5b3 |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Score: | 68 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Machine Learning detection for sample
Sample deletes itself
Sends malformed DNS queries
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Yara signature match
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1581825 |
Start date and time: | 2024-12-29 02:57:08 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 37s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | Aqua.i686.elf |
Detection: | MAL |
Classification: | mal68.troj.evad.linELF@0/0@36/0 |
Command: | /tmp/Aqua.i686.elf |
PID: | 6237 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | about to cum inside a femboy btw |
Standard Error: |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Linux_Trojan_Mirai_268aac0b | unknown | unknown |
| |
Linux_Trojan_Mirai_0cb1699c | unknown | unknown |
| |
Linux_Trojan_Mirai_70ef58f1 | unknown | unknown |
| |
Linux_Trojan_Mirai_3a85a418 | unknown | unknown |
| |
Linux_Trojan_Mirai_2e3f67a9 | unknown | unknown |
| |
Click to see the 2 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Linux_Trojan_Mirai_268aac0b | unknown | unknown |
| |
Linux_Trojan_Mirai_0cb1699c | unknown | unknown |
| |
Linux_Trojan_Mirai_70ef58f1 | unknown | unknown |
| |
Linux_Trojan_Mirai_3a85a418 | unknown | unknown |
| |
Linux_Trojan_Mirai_2e3f67a9 | unknown | unknown |
| |
Click to see the 2 entries |
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Joe Sandbox ML: |
Networking |
---|
Source: | DNS traffic detected: |
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | .symtab present: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | 1 File Deletion | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 2 Application Layer Protocol | Traffic Duplication | Data Destruction |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
27% | Virustotal | Browse | ||
24% | ReversingLabs | Linux.Backdoor.Mirai | ||
100% | Joe Sandbox ML |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
raw.intenseapi.com | 193.200.78.37 | true | false | high | |
raw.intenseapi.com. [malformed] | unknown | unknown | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.200.78.37 | raw.intenseapi.com | Switzerland | 29496 | LINK-SERVICE-ASUA | false | |
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
91.189.91.43 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.200.78.37 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
109.202.202.202 | Get hash | malicious | Unknown | Browse |
| |
91.189.91.43 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
91.189.91.42 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
raw.intenseapi.com | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CANONICAL-ASGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
CANONICAL-ASGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
INIT7CH | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
LINK-SERVICE-ASUA | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 6.291388629720281 |
TrID: |
|
File name: | Aqua.i686.elf |
File size: | 50'352 bytes |
MD5: | e9eccfb9834ec789ab345b0e6e62e16a |
SHA1: | 5ddc158f3bf417469945cc18c97259b67a9f1c08 |
SHA256: | d2eb57a740a285202cb4224d7453334fd5c0b3d170288575a5eb91fb191bd5b3 |
SHA512: | 9263ccddf423780a1d61cd458dc5e60ae4de6e714c28de12c19f600473125fdcfc10ca5956d3f0555af20c3aaa7317c85b1045284166c3bd653fd08b99b19db8 |
SSDEEP: | 1536:j7WsI7YXIRWH+MK+77eVDzJxrRWsw3wgGbnPwC7FQEDc:j7W37Y4RAK+77eVDzXwdAgGLPbRHD |
TLSH: | 2A332AC1F54F84F9D95B49304063F33FCF32D5294275CAAEEF99AE36DA23541821A298 |
File Content Preview: | .ELF....................h...4... .......4. ...(.....................\...\....................@...@.......(..........Q.td............................U..S.......w....h........[]...$.............U......=.B...t..1....$@.....$@......u........t...$\?..........B |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 49952 |
Section Header Size: | 40 |
Number of Section Headers: | 10 |
Header String Table Index: | 9 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x8048094 | 0x94 | 0x1c | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.text | PROGBITS | 0x80480b0 | 0xb0 | 0xaac1 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x8052b71 | 0xab71 | 0x17 | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.rodata | PROGBITS | 0x8052ba0 | 0xaba0 | 0x13bc | 0x0 | 0x2 | A | 0 | 0 | 32 |
.ctors | PROGBITS | 0x8054000 | 0xc000 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x8054008 | 0xc008 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x8054020 | 0xc020 | 0x2c0 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.bss | NOBITS | 0x80542e0 | 0xc2e0 | 0x2520 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.shstrtab | STRTAB | 0x0 | 0xc2e0 | 0x3e | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8048000 | 0x8048000 | 0xbf5c | 0xbf5c | 6.3386 | 0x5 | R E | 0x1000 | .init .text .fini .rodata | |
LOAD | 0xc000 | 0x8054000 | 0x8054000 | 0x2e0 | 0x2800 | 3.9481 | 0x6 | RW | 0x1000 | .ctors .dtors .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 29, 2024 02:57:54.988851070 CET | 40836 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:57:55.089659929 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Dec 29, 2024 02:57:55.108531952 CET | 33966 | 40836 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:57:55.108591080 CET | 40836 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:57:55.108608961 CET | 40836 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:57:55.228076935 CET | 33966 | 40836 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:57:55.228137970 CET | 40836 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:57:55.347686052 CET | 33966 | 40836 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:57:56.444045067 CET | 33966 | 40836 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:57:56.444205046 CET | 40836 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:57:56.444205046 CET | 40836 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:57:57.674477100 CET | 40838 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:57:57.794014931 CET | 33966 | 40838 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:57:57.794189930 CET | 40838 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:57:57.794189930 CET | 40838 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:57:57.913779020 CET | 33966 | 40838 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:57:57.913995028 CET | 40838 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:57:58.033570051 CET | 33966 | 40838 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:57:59.037472010 CET | 33966 | 40838 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:57:59.037708998 CET | 40838 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:57:59.037708998 CET | 40838 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:00.261076927 CET | 40840 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:00.380609035 CET | 33966 | 40840 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:58:00.380789042 CET | 40840 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:00.380829096 CET | 40840 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:00.464907885 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Dec 29, 2024 02:58:00.500260115 CET | 33966 | 40840 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:58:00.500427961 CET | 40840 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:00.619894028 CET | 33966 | 40840 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:58:01.709032059 CET | 33966 | 40840 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:58:01.709374905 CET | 40840 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:01.709374905 CET | 40840 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:02.000857115 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Dec 29, 2024 02:58:02.936068058 CET | 40842 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:03.055670977 CET | 33966 | 40842 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:58:03.056010962 CET | 40842 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:03.056073904 CET | 40842 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:03.175518990 CET | 33966 | 40842 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:58:03.175734043 CET | 40842 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:03.295248985 CET | 33966 | 40842 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:58:04.391900063 CET | 33966 | 40842 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:58:04.392167091 CET | 40842 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:04.392168045 CET | 40842 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:05.620140076 CET | 40844 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:05.739665031 CET | 33966 | 40844 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:58:05.739996910 CET | 40844 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:05.740837097 CET | 40844 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:05.860251904 CET | 33966 | 40844 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:58:05.860646009 CET | 40844 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:05.980089903 CET | 33966 | 40844 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:58:07.043420076 CET | 33966 | 40844 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:58:07.043606997 CET | 40844 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:07.043606997 CET | 40844 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:08.268016100 CET | 40846 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:08.387670040 CET | 33966 | 40846 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:58:08.387849092 CET | 40846 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:08.387849092 CET | 40846 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:08.507579088 CET | 33966 | 40846 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:58:08.507853031 CET | 40846 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:08.627355099 CET | 33966 | 40846 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:58:09.716531038 CET | 33966 | 40846 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:58:09.716727018 CET | 40846 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:09.716727018 CET | 40846 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:10.943166018 CET | 40848 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:11.062701941 CET | 33966 | 40848 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:58:11.062946081 CET | 40848 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:11.063081026 CET | 40848 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:11.182624102 CET | 33966 | 40848 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:58:11.182779074 CET | 40848 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:58:11.302347898 CET | 33966 | 40848 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:58:16.078845024 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Dec 29, 2024 02:58:26.317382097 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Dec 29, 2024 02:58:32.460591078 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Dec 29, 2024 02:58:57.033247948 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Dec 29, 2024 02:59:17.510376930 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Dec 29, 2024 02:59:21.113862991 CET | 40848 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:59:21.265503883 CET | 33966 | 40848 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:59:21.539585114 CET | 33966 | 40848 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:59:21.539655924 CET | 40848 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:59:31.538837910 CET | 40848 | 33966 | 192.168.2.23 | 193.200.78.37 |
Dec 29, 2024 02:59:31.658411980 CET | 33966 | 40848 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:59:31.931781054 CET | 33966 | 40848 | 193.200.78.37 | 192.168.2.23 |
Dec 29, 2024 02:59:31.931953907 CET | 40848 | 33966 | 192.168.2.23 | 193.200.78.37 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 29, 2024 02:57:54.243110895 CET | 48649 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:57:54.376955986 CET | 53 | 48649 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:57:54.377044916 CET | 54997 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:57:54.499362946 CET | 53 | 54997 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:57:54.499453068 CET | 44069 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:57:54.621676922 CET | 53 | 44069 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:57:54.621731997 CET | 45421 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:57:54.744172096 CET | 53 | 45421 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:57:54.744259119 CET | 50480 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:57:54.866473913 CET | 53 | 50480 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:57:54.866543055 CET | 47787 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:57:54.988761902 CET | 53 | 47787 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:57:56.444215059 CET | 42487 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:57:56.567673922 CET | 53 | 42487 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:57:56.567816019 CET | 59686 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:57:56.690118074 CET | 53 | 59686 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:57:56.690196991 CET | 33250 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:57:56.813422918 CET | 53 | 33250 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:57:56.813575983 CET | 38321 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:57:56.935794115 CET | 53 | 38321 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:57:56.935870886 CET | 33718 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:57:57.059281111 CET | 53 | 33718 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:57:57.059375048 CET | 58084 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:57:57.181688070 CET | 53 | 58084 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:57:57.181754112 CET | 57444 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:57:57.306365013 CET | 53 | 57444 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:57:57.306446075 CET | 54514 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:57:57.428694010 CET | 53 | 54514 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:57:57.428843975 CET | 46495 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:57:57.551002026 CET | 53 | 46495 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:57:57.551191092 CET | 44232 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:57:57.674215078 CET | 53 | 44232 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:57:59.037704945 CET | 38747 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:57:59.160034895 CET | 53 | 38747 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:57:59.160243988 CET | 36443 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:57:59.282385111 CET | 53 | 36443 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:57:59.282627106 CET | 58568 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:57:59.404769897 CET | 53 | 58568 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:57:59.404984951 CET | 39360 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:57:59.527097940 CET | 53 | 39360 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:57:59.527297974 CET | 42069 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:57:59.649416924 CET | 53 | 42069 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:57:59.649538040 CET | 45157 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:57:59.771632910 CET | 53 | 45157 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:57:59.771727085 CET | 47203 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:57:59.893805981 CET | 53 | 47203 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:57:59.893985987 CET | 37950 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:00.016043901 CET | 53 | 37950 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:00.016246080 CET | 57811 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:00.138546944 CET | 53 | 57811 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:00.138720989 CET | 57637 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:00.260831118 CET | 53 | 57637 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:01.709369898 CET | 59068 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:01.831785917 CET | 53 | 59068 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:01.832146883 CET | 52775 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:01.954322100 CET | 53 | 52775 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:01.954616070 CET | 39698 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:02.076865911 CET | 53 | 39698 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:02.077044010 CET | 54275 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:02.199218988 CET | 53 | 54275 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:02.199434996 CET | 46609 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:02.322398901 CET | 53 | 46609 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:02.322647095 CET | 37395 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:02.445604086 CET | 53 | 37395 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:02.446043015 CET | 37782 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:02.568165064 CET | 53 | 37782 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:02.568576097 CET | 35849 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:02.690826893 CET | 53 | 35849 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:02.691184998 CET | 60525 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:02.813374043 CET | 53 | 60525 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:02.813472986 CET | 36213 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:02.935753107 CET | 53 | 36213 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:04.392162085 CET | 43850 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:04.514461040 CET | 53 | 43850 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:04.514942884 CET | 53337 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:04.638290882 CET | 53 | 53337 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:04.638645887 CET | 32873 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:04.760837078 CET | 53 | 32873 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:04.761140108 CET | 33037 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:04.884921074 CET | 53 | 33037 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:04.885116100 CET | 49566 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:05.007308960 CET | 53 | 49566 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:05.007499933 CET | 60646 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:05.129618883 CET | 53 | 60646 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:05.129983902 CET | 55814 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:05.252113104 CET | 53 | 55814 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:05.252552986 CET | 33735 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:05.374691010 CET | 53 | 33735 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:05.375042915 CET | 39515 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:05.497198105 CET | 53 | 39515 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:05.497688055 CET | 48919 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:05.619808912 CET | 53 | 48919 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:07.043637991 CET | 50049 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:07.165777922 CET | 53 | 50049 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:07.166085005 CET | 52737 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:07.288206100 CET | 53 | 52737 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:07.288479090 CET | 42136 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:07.410660028 CET | 53 | 42136 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:07.410883904 CET | 33687 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:07.533037901 CET | 53 | 33687 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:07.533242941 CET | 49626 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:07.655397892 CET | 53 | 49626 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:07.655628920 CET | 47062 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:07.777801037 CET | 53 | 47062 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:07.778007030 CET | 51781 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:07.900152922 CET | 53 | 51781 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:07.900366068 CET | 35931 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:08.022610903 CET | 53 | 35931 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:08.022938967 CET | 33951 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:08.145082951 CET | 53 | 33951 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:08.145306110 CET | 40206 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:08.267679930 CET | 53 | 40206 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:09.716732025 CET | 35139 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:09.839042902 CET | 53 | 35139 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:09.839454889 CET | 55890 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:09.961790085 CET | 53 | 55890 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:09.962274075 CET | 55694 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:10.084487915 CET | 53 | 55694 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:10.084904909 CET | 44942 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:10.207171917 CET | 53 | 44942 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:10.207564116 CET | 54017 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:10.329855919 CET | 53 | 54017 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:10.330240011 CET | 59539 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:10.452363014 CET | 53 | 59539 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:10.452739000 CET | 40422 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:10.575021029 CET | 53 | 40422 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:10.575404882 CET | 53043 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:10.697707891 CET | 53 | 53043 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:10.698106050 CET | 59174 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:10.820333004 CET | 53 | 59174 | 8.8.8.8 | 192.168.2.23 |
Dec 29, 2024 02:58:10.820633888 CET | 50949 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 29, 2024 02:58:10.942765951 CET | 53 | 50949 | 8.8.8.8 | 192.168.2.23 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 29, 2024 02:57:54.243110895 CET | 192.168.2.23 | 8.8.8.8 | 0x4094 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 29, 2024 02:57:54.377044916 CET | 192.168.2.23 | 8.8.8.8 | 0x63be | Standard query (0) | 256 | 418 | false | |
Dec 29, 2024 02:57:54.499453068 CET | 192.168.2.23 | 8.8.8.8 | 0x63be | Standard query (0) | 256 | 418 | false | |
Dec 29, 2024 02:57:54.621731997 CET | 192.168.2.23 | 8.8.8.8 | 0x63be | Standard query (0) | 256 | 418 | false | |
Dec 29, 2024 02:57:54.744259119 CET | 192.168.2.23 | 8.8.8.8 | 0x63be | Standard query (0) | 256 | 418 | false | |
Dec 29, 2024 02:57:54.866543055 CET | 192.168.2.23 | 8.8.8.8 | 0x63be | Standard query (0) | 256 | 418 | false | |
Dec 29, 2024 02:57:57.059375048 CET | 192.168.2.23 | 8.8.8.8 | 0xc6fb | Standard query (0) | 256 | 421 | false | |
Dec 29, 2024 02:57:57.181754112 CET | 192.168.2.23 | 8.8.8.8 | 0xc6fb | Standard query (0) | 256 | 421 | false | |
Dec 29, 2024 02:57:57.306446075 CET | 192.168.2.23 | 8.8.8.8 | 0xc6fb | Standard query (0) | 256 | 421 | false | |
Dec 29, 2024 02:57:57.428843975 CET | 192.168.2.23 | 8.8.8.8 | 0xc6fb | Standard query (0) | 256 | 421 | false | |
Dec 29, 2024 02:57:57.551191092 CET | 192.168.2.23 | 8.8.8.8 | 0xc6fb | Standard query (0) | 256 | 421 | false | |
Dec 29, 2024 02:57:59.649538040 CET | 192.168.2.23 | 8.8.8.8 | 0xaf8 | Standard query (0) | 256 | 423 | false | |
Dec 29, 2024 02:57:59.771727085 CET | 192.168.2.23 | 8.8.8.8 | 0xaf8 | Standard query (0) | 256 | 423 | false | |
Dec 29, 2024 02:57:59.893985987 CET | 192.168.2.23 | 8.8.8.8 | 0xaf8 | Standard query (0) | 256 | 424 | false | |
Dec 29, 2024 02:58:00.016246080 CET | 192.168.2.23 | 8.8.8.8 | 0xaf8 | Standard query (0) | 256 | 424 | false | |
Dec 29, 2024 02:58:00.138720989 CET | 192.168.2.23 | 8.8.8.8 | 0xaf8 | Standard query (0) | 256 | 424 | false | |
Dec 29, 2024 02:58:02.322647095 CET | 192.168.2.23 | 8.8.8.8 | 0x3e33 | Standard query (0) | 256 | 426 | false | |
Dec 29, 2024 02:58:02.446043015 CET | 192.168.2.23 | 8.8.8.8 | 0x3e33 | Standard query (0) | 256 | 426 | false | |
Dec 29, 2024 02:58:02.568576097 CET | 192.168.2.23 | 8.8.8.8 | 0x3e33 | Standard query (0) | 256 | 426 | false | |
Dec 29, 2024 02:58:02.691184998 CET | 192.168.2.23 | 8.8.8.8 | 0x3e33 | Standard query (0) | 256 | 426 | false | |
Dec 29, 2024 02:58:02.813472986 CET | 192.168.2.23 | 8.8.8.8 | 0x3e33 | Standard query (0) | 256 | 426 | false | |
Dec 29, 2024 02:58:05.007499933 CET | 192.168.2.23 | 8.8.8.8 | 0x2818 | Standard query (0) | 256 | 429 | false | |
Dec 29, 2024 02:58:05.129983902 CET | 192.168.2.23 | 8.8.8.8 | 0x2818 | Standard query (0) | 256 | 429 | false | |
Dec 29, 2024 02:58:05.252552986 CET | 192.168.2.23 | 8.8.8.8 | 0x2818 | Standard query (0) | 256 | 429 | false | |
Dec 29, 2024 02:58:05.375042915 CET | 192.168.2.23 | 8.8.8.8 | 0x2818 | Standard query (0) | 256 | 429 | false | |
Dec 29, 2024 02:58:05.497688055 CET | 192.168.2.23 | 8.8.8.8 | 0x2818 | Standard query (0) | 256 | 429 | false | |
Dec 29, 2024 02:58:07.655628920 CET | 192.168.2.23 | 8.8.8.8 | 0xb365 | Standard query (0) | 256 | 431 | false | |
Dec 29, 2024 02:58:07.778007030 CET | 192.168.2.23 | 8.8.8.8 | 0xb365 | Standard query (0) | 256 | 431 | false | |
Dec 29, 2024 02:58:07.900366068 CET | 192.168.2.23 | 8.8.8.8 | 0xb365 | Standard query (0) | 256 | 432 | false | |
Dec 29, 2024 02:58:08.022938967 CET | 192.168.2.23 | 8.8.8.8 | 0xb365 | Standard query (0) | 256 | 432 | false | |
Dec 29, 2024 02:58:08.145306110 CET | 192.168.2.23 | 8.8.8.8 | 0xb365 | Standard query (0) | 256 | 432 | false | |
Dec 29, 2024 02:58:10.330240011 CET | 192.168.2.23 | 8.8.8.8 | 0x5ce9 | Standard query (0) | 256 | 434 | false | |
Dec 29, 2024 02:58:10.452739000 CET | 192.168.2.23 | 8.8.8.8 | 0x5ce9 | Standard query (0) | 256 | 434 | false | |
Dec 29, 2024 02:58:10.575404882 CET | 192.168.2.23 | 8.8.8.8 | 0x5ce9 | Standard query (0) | 256 | 434 | false | |
Dec 29, 2024 02:58:10.698106050 CET | 192.168.2.23 | 8.8.8.8 | 0x5ce9 | Standard query (0) | 256 | 434 | false | |
Dec 29, 2024 02:58:10.820633888 CET | 192.168.2.23 | 8.8.8.8 | 0x5ce9 | Standard query (0) | 256 | 434 | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 29, 2024 02:57:54.376955986 CET | 8.8.8.8 | 192.168.2.23 | 0x4094 | No error (0) | 193.200.78.37 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 01:57:53 |
Start date (UTC): | 29/12/2024 |
Path: | /tmp/Aqua.i686.elf |
Arguments: | /tmp/Aqua.i686.elf |
File size: | 50352 bytes |
MD5 hash: | e9eccfb9834ec789ab345b0e6e62e16a |
Start time (UTC): | 01:57:53 |
Start date (UTC): | 29/12/2024 |
Path: | /tmp/Aqua.i686.elf |
Arguments: | - |
File size: | 50352 bytes |
MD5 hash: | e9eccfb9834ec789ab345b0e6e62e16a |