Edit tour
Linux
Analysis Report
arm6.elf
Overview
General Information
Detection
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1582146 |
Start date and time: | 2024-12-30 02:56:45 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 9s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | arm6.elf |
Detection: | MAL |
Classification: | mal56.linELF@0/0@2/0 |
Command: | /tmp/arm6.elf |
PID: | 5475 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | $UICIDEBOY$ |
Standard Error: |
⊘No yara matches
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-30T02:57:45.631520+0100 | 2849816 | 1 | A Network Trojan was detected | 192.168.2.13 | 53632 | 85.239.34.134 | 6666 | TCP |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Networking |
---|
Source: | Suricata IDS: |
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | .symtab present: |
Source: | Classification label: |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | Direct Volume Access | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Non-Standard Port | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
24% | Virustotal | Browse | ||
26% | ReversingLabs | Linux.Backdoor.Gafgyt |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
daisy.ubuntu.com | 162.213.35.24 | true | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
85.239.34.134 | unknown | Russian Federation | 134121 | RAINBOW-HKRainbownetworklimitedHK | true |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
85.239.34.134 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
daisy.ubuntu.com | Get hash | malicious | Gafgyt | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
RAINBOW-HKRainbownetworklimitedHK | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | ScreenConnect Tool | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 5.82221209455016 |
TrID: |
|
File name: | arm6.elf |
File size: | 30'564 bytes |
MD5: | bad36d8fc61c2a221c2609dd5ff792af |
SHA1: | bc71c073a75c4847334fccdf7f6d0be3eedf18ea |
SHA256: | e5364f3baf34c9911eed614ca6c35fc032c854efb6c5ce45b2fc82b9c250cf53 |
SHA512: | f40171a5ce6209d8cd3826704d34f12aae126a48ed68a77b2e6b5351828a1d9a47345894e70b550fa84fc6e35f3eccacbcb02084241fea3fcc86b5d3c7134406 |
SSDEEP: | 768:jenflWCgSKMJbDKmTbRI+VZi5A/oTgQHc1V0h:jenflWnwJb/ZIQi5AATgQH |
TLSH: | 4FD20996F9819F11C5D1127AFA0E164E73131B2CF3EE77226E156F2067874BB0E3A816 |
File Content Preview: | .ELF..............(.....T...4...4u......4. ...(......................q...q...............q...q...q.......&..........Q.td..................................-...L..................@-.,@...0....S..... 0....S.........../..0...0...@..../..t.......q....-.@0....S |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 30004 |
Section Header Size: | 40 |
Number of Section Headers: | 14 |
Header String Table Index: | 13 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x8094 | 0x94 | 0x10 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x80b0 | 0xb0 | 0x6c9c | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0xed4c | 0x6d4c | 0x10 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0xed5c | 0x6d5c | 0x494 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.eh_frame | PROGBITS | 0x171f0 | 0x71f0 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.init_array | INIT_ARRAY | 0x171f4 | 0x71f4 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.fini_array | FINI_ARRAY | 0x171f8 | 0x71f8 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.jcr | PROGBITS | 0x171fc | 0x71fc | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.got | PROGBITS | 0x17200 | 0x7200 | 0x74 | 0x4 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x17274 | 0x7274 | 0x244 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x174b8 | 0x74b8 | 0x23dc | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.ARM.attributes | ARM_ATTRIBUTES | 0x0 | 0x74b8 | 0x10 | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0x74c8 | 0x6c | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8000 | 0x8000 | 0x71f0 | 0x71f0 | 5.8739 | 0x5 | R E | 0x8000 | .init .text .fini .rodata | |
LOAD | 0x71f0 | 0x171f0 | 0x171f0 | 0x2c8 | 0x26a4 | 3.5136 | 0x6 | RW | 0x8000 | .eh_frame .init_array .fini_array .jcr .got .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-30T02:57:45.631520+0100 | 2849816 | ETPRO MALWARE ELF/Multiverze CnC Checkin | 1 | 192.168.2.13 | 53632 | 85.239.34.134 | 6666 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 30, 2024 02:57:45.618562937 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:57:45.623558998 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:57:45.623617887 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:57:45.631520033 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:57:45.636378050 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:57:49.769591093 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:57:49.769711971 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:57:49.769885063 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:57:49.774660110 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:57:54.781241894 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:57:54.781501055 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:57:54.781502008 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:57:54.786493063 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:57:59.125097036 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:57:59.125255108 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:57:59.125308037 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:57:59.130160093 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:57:59.819967985 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:57:59.820158958 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:57:59.825062037 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:04.857590914 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:04.857888937 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:58:04.862785101 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:09.872098923 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:09.872332096 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:58:09.877321959 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:14.136725903 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:14.136903048 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:58:14.141838074 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:14.879164934 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:14.879334927 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:58:14.884191036 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:19.884844065 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:19.885102034 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:58:19.890022993 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:24.956624031 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:24.957279921 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:58:24.962222099 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:29.153701067 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:29.154056072 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:58:29.158924103 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:29.974155903 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:29.974442959 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:58:29.979352951 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:34.983551025 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:34.983659029 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:58:34.988636017 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:40.051960945 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:40.052269936 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:58:40.057194948 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:44.156881094 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:44.157161951 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:58:44.162100077 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:45.069504023 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:45.069799900 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:58:45.074685097 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:50.080955982 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:50.081604004 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:58:50.086551905 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:55.124850035 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:55.125174046 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:58:55.130084038 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:59.169323921 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:58:59.169629097 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:58:59.174601078 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:00.136609077 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:00.136894941 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:59:00.141896009 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:05.147859097 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:05.148248911 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:59:05.153213978 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:10.159460068 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:10.159781933 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:59:10.164659023 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:14.185374975 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:14.185699940 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:59:14.190634012 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:15.169172049 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:15.169411898 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:59:15.174339056 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:20.180269957 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:20.180587053 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:59:20.185518980 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:25.219510078 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:25.220029116 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:59:25.225013018 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:29.254153967 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:29.254487991 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:59:29.259455919 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:30.259890079 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:30.260263920 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:59:30.265243053 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:35.273374081 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:35.273636103 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:59:35.278556108 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:40.321480989 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:40.321887016 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:59:40.326983929 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:44.262125969 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:44.262491941 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:59:44.267394066 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:45.330933094 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:45.331465006 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:59:45.336389065 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:50.340199947 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:50.340490103 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:59:50.346164942 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:55.352575064 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 02:59:55.352979898 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 02:59:55.359070063 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:00.361077070 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:00.361404896 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 03:00:00.366395950 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:05.374866009 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:05.375340939 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 03:00:05.380285025 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:10.419771910 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:10.420043945 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 03:00:10.427011967 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:14.323437929 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:14.323997021 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 03:00:14.328857899 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:15.468075991 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:15.468394041 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 03:00:15.473372936 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:20.480803967 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:20.480982065 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 03:00:20.485944033 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:25.551759005 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:25.552045107 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 03:00:25.556905031 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:29.345689058 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:29.346007109 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 03:00:29.350797892 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:30.562424898 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:30.562536001 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 03:00:30.568104029 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:35.577301025 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:35.577469110 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 03:00:35.582324982 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:40.587140083 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:40.587409019 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 03:00:40.592246056 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:44.371689081 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:44.372004986 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 03:00:44.376904011 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:45.651693106 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:45.651887894 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 03:00:45.656712055 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:50.658427954 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:50.658736944 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 03:00:50.663608074 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:55.665345907 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:55.665549040 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 03:00:55.670435905 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:59.384677887 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:00:59.384994984 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 03:00:59.391382933 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:01:00.672554970 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:01:00.672911882 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 03:01:00.677794933 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:01:05.678678989 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:01:05.678941965 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 03:01:05.683762074 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:01:10.686405897 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:01:10.686959028 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 03:01:10.691768885 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:01:14.450656891 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:01:14.450824022 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 03:01:14.457017899 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:01:15.723196030 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Dec 30, 2024 03:01:15.723361969 CET | 53632 | 6666 | 192.168.2.13 | 85.239.34.134 |
Dec 30, 2024 03:01:15.728251934 CET | 6666 | 53632 | 85.239.34.134 | 192.168.2.13 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 30, 2024 03:00:30.669470072 CET | 47925 | 53 | 192.168.2.13 | 1.1.1.1 |
Dec 30, 2024 03:00:30.669470072 CET | 41488 | 53 | 192.168.2.13 | 1.1.1.1 |
Dec 30, 2024 03:00:30.676075935 CET | 53 | 47925 | 1.1.1.1 | 192.168.2.13 |
Dec 30, 2024 03:00:30.676662922 CET | 53 | 41488 | 1.1.1.1 | 192.168.2.13 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 30, 2024 03:00:30.669470072 CET | 192.168.2.13 | 1.1.1.1 | 0xe6e7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:00:30.669470072 CET | 192.168.2.13 | 1.1.1.1 | 0xac | Standard query (0) | 28 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 30, 2024 03:00:30.676075935 CET | 1.1.1.1 | 192.168.2.13 | 0xe6e7 | No error (0) | 162.213.35.24 | A (IP address) | IN (0x0001) | false | ||
Dec 30, 2024 03:00:30.676075935 CET | 1.1.1.1 | 192.168.2.13 | 0xe6e7 | No error (0) | 162.213.35.25 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 01:57:44 |
Start date (UTC): | 30/12/2024 |
Path: | /tmp/arm6.elf |
Arguments: | /tmp/arm6.elf |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 01:57:44 |
Start date (UTC): | 30/12/2024 |
Path: | /tmp/arm6.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |