Edit tour
Linux
Analysis Report
.Sarm5.elf
Overview
General Information
Detection
Score: | 52 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Multi AV Scanner detection for submitted file
Sample is packed with UPX
ELF contains segments with high entropy indicating compressed/encrypted content
Sample contains only a LOAD segment without any section mappings
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1582174 |
Start date and time: | 2024-12-30 03:26:28 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 27s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | .Sarm5.elf |
Detection: | MAL |
Classification: | mal52.evad.linELF@0/0@30/0 |
- VT rate limit hit for: mingleyou.top
Command: | /tmp/.Sarm5.elf |
PID: | 6217 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | Hello, World! |
Standard Error: |
- system is lnxubuntu20
- .Sarm5.elf New Fork (PID: 6219, Parent: 6217)
- .Sarm5.elf New Fork (PID: 6221, Parent: 6219)
- cleanup
⊘No yara matches
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | Socket: | Jump to behavior |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Program segment: |
Source: | Classification label: |
Data Obfuscation |
---|
Source: | String containing UPX found: | ||
Source: | String containing UPX found: | ||
Source: | String containing UPX found: |
Source: | Submission file: |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | 11 Obfuscated Files or Information | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
29% | ReversingLabs | Linux.Trojan.Svirtu | ||
24% | Virustotal | Browse |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
mingleyou.top | unknown | unknown | false | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
115.11.111.11 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
91.189.91.43 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
115.11.111.11 | Get hash | malicious | Mirai | Browse | ||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
109.202.202.202 | Get hash | malicious | Unknown | Browse |
| |
91.189.91.43 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Gafgyt | Browse | |||
91.189.91.42 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Moobot | Browse | |||
Get hash | malicious | Gafgyt | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse |
⊘No context
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
KIXS-AS-KRKoreaTelecomKR | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
CANONICAL-ASGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
CANONICAL-ASGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
INIT7CH | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 7.9100454623608085 |
TrID: |
|
File name: | .Sarm5.elf |
File size: | 22'008 bytes |
MD5: | 877aff442f5dcfb5e371139d70acb0a4 |
SHA1: | 6375d25b2cd970ce5930df870e9f366948a3a3fa |
SHA256: | 6ebab62596ec65beccf22c8beace4aa0ad652ce5429e8462536b4a418270127e |
SHA512: | e740361643f62438c55a35a915582a215fd96f078aa8ce1ad3697bc05d844b0354ec7b0b7296e83b84b820fabaca68d47d636b89ee1db40c044551e44c2e7cad |
SSDEEP: | 384:pHBOzXXfTNGUxX5S/B9dFg7Wg41Am/uShymdGUop5hl:hBOcsmM7341J/uSs3UozP |
TLSH: | 05A2C05D728A6C30EFB01E758BA4CC8D128BC978A9D73939336D853ED84530B25F5AC9 |
File Content Preview: | .ELF...a..........(.....P...4...........4. ...(......................T...T...............e..........................Q.td..............................CvUPX!........p...p.......O..........?.E.h;.}...^..........fK.........+...A.............h................ |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 0 |
Section Header Size: | 40 |
Number of Section Headers: | 0 |
Header String Table Index: | 0 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8000 | 0x8000 | 0x54ff | 0x54ff | 7.9144 | 0x5 | R E | 0x8000 | ||
LOAD | 0x65a4 | 0x1e5a4 | 0x1e5a4 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x8000 | ||
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 30, 2024 03:27:07.616321087 CET | 59562 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:27:07.621237040 CET | 22 | 59562 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:27:07.621345997 CET | 59562 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:27:07.647078991 CET | 59562 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:27:07.651912928 CET | 22 | 59562 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:27:07.651957989 CET | 59562 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:27:07.656758070 CET | 22 | 59562 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:27:08.619498014 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Dec 30, 2024 03:27:13.994685888 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Dec 30, 2024 03:27:15.530455112 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Dec 30, 2024 03:27:17.656306028 CET | 59562 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:27:17.661374092 CET | 22 | 59562 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:27:28.584738016 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Dec 30, 2024 03:27:29.012337923 CET | 22 | 59562 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:27:29.013056993 CET | 59562 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:27:29.017921925 CET | 22 | 59562 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:27:30.051666975 CET | 59564 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:27:30.056598902 CET | 22 | 59564 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:27:30.056668043 CET | 59564 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:27:30.057586908 CET | 59564 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:27:30.062464952 CET | 22 | 59564 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:27:30.062532902 CET | 59564 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:27:30.067373037 CET | 22 | 59564 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:27:40.870970964 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Dec 30, 2024 03:27:44.966471910 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Dec 30, 2024 03:27:51.401459932 CET | 22 | 59564 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:27:51.401729107 CET | 59564 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:27:51.406610966 CET | 22 | 59564 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:27:52.438986063 CET | 59566 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:27:52.443883896 CET | 22 | 59566 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:27:52.443990946 CET | 59566 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:27:52.444771051 CET | 59566 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:27:52.449556112 CET | 22 | 59566 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:27:52.449649096 CET | 59566 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:27:52.454427958 CET | 22 | 59566 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:28:09.539014101 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Dec 30, 2024 03:28:13.792634010 CET | 22 | 59566 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:28:13.793164015 CET | 59566 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:28:13.797950029 CET | 22 | 59566 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:28:14.832159042 CET | 59568 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:28:14.837090015 CET | 22 | 59568 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:28:14.837148905 CET | 59568 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:28:14.838011980 CET | 59568 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:28:14.842891932 CET | 22 | 59568 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:28:14.842942953 CET | 59568 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:28:14.847809076 CET | 22 | 59568 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:28:24.846720934 CET | 59568 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:28:24.851680994 CET | 22 | 59568 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:28:36.199565887 CET | 22 | 59568 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:28:36.199711084 CET | 59568 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:28:36.204597950 CET | 22 | 59568 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:28:37.244267941 CET | 59570 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:28:37.250325918 CET | 22 | 59570 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:28:37.250412941 CET | 59570 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:28:37.251458883 CET | 59570 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:28:37.256222963 CET | 22 | 59570 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:28:37.256285906 CET | 59570 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:28:37.261060953 CET | 22 | 59570 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:28:58.590569019 CET | 22 | 59570 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:28:58.591068983 CET | 59570 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:28:58.595936060 CET | 22 | 59570 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:28:59.630785942 CET | 59572 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:28:59.635690928 CET | 22 | 59572 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:28:59.635750055 CET | 59572 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:28:59.636701107 CET | 59572 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:28:59.641484976 CET | 22 | 59572 | 115.11.111.11 | 192.168.2.23 |
Dec 30, 2024 03:28:59.641536951 CET | 59572 | 22 | 192.168.2.23 | 115.11.111.11 |
Dec 30, 2024 03:28:59.646348000 CET | 22 | 59572 | 115.11.111.11 | 192.168.2.23 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 30, 2024 03:27:07.506047010 CET | 40368 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:27:07.513021946 CET | 53 | 40368 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:27:07.523730993 CET | 51182 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:27:07.530005932 CET | 53 | 51182 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:27:07.540996075 CET | 51248 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:27:07.547555923 CET | 53 | 51248 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:27:07.550945997 CET | 44847 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:27:07.557230949 CET | 53 | 44847 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:27:07.568695068 CET | 38126 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:27:07.575361967 CET | 53 | 38126 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:27:30.015431881 CET | 53859 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:27:30.022202015 CET | 53 | 53859 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:27:30.023147106 CET | 55899 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:27:30.029594898 CET | 53 | 55899 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:27:30.030217886 CET | 49962 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:27:30.036729097 CET | 53 | 49962 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:27:30.037352085 CET | 53061 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:27:30.043812037 CET | 53 | 53061 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:27:30.044858932 CET | 45353 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:27:30.051136017 CET | 53 | 45353 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:27:52.403577089 CET | 37547 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:27:52.410558939 CET | 53 | 37547 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:27:52.411215067 CET | 37369 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:27:52.417534113 CET | 53 | 37369 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:27:52.418133974 CET | 48704 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:27:52.424673080 CET | 53 | 48704 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:27:52.425283909 CET | 34967 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:27:52.431592941 CET | 53 | 34967 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:27:52.432215929 CET | 43345 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:27:52.438640118 CET | 53 | 43345 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:28:14.795686960 CET | 38443 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:28:14.802047968 CET | 53 | 38443 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:28:14.803141117 CET | 36173 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:28:14.809453964 CET | 53 | 36173 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:28:14.810409069 CET | 53336 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:28:14.816915035 CET | 53 | 53336 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:28:14.817903042 CET | 42676 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:28:14.824322939 CET | 53 | 42676 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:28:14.825268984 CET | 46108 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:28:14.831631899 CET | 53 | 46108 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:28:37.202157974 CET | 36429 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:28:37.209000111 CET | 53 | 36429 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:28:37.210141897 CET | 55243 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:28:37.216439009 CET | 53 | 55243 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:28:37.217525005 CET | 51478 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:28:37.224709034 CET | 53 | 51478 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:28:37.225770950 CET | 54917 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:28:37.234150887 CET | 53 | 54917 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:28:37.235245943 CET | 52489 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:28:37.243755102 CET | 53 | 52489 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:28:59.593838930 CET | 47019 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:28:59.600409031 CET | 53 | 47019 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:28:59.601519108 CET | 60340 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:28:59.608031988 CET | 53 | 60340 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:28:59.609118938 CET | 40625 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:28:59.615427971 CET | 53 | 40625 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:28:59.616468906 CET | 51694 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:28:59.622951031 CET | 53 | 51694 | 8.8.8.8 | 192.168.2.23 |
Dec 30, 2024 03:28:59.624023914 CET | 34259 | 53 | 192.168.2.23 | 8.8.8.8 |
Dec 30, 2024 03:28:59.630268097 CET | 53 | 34259 | 8.8.8.8 | 192.168.2.23 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 30, 2024 03:27:07.506047010 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:27:07.523730993 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:27:07.540996075 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:27:07.550945997 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:27:07.568695068 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:27:30.015431881 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:27:30.023147106 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:27:30.030217886 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:27:30.037352085 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:27:30.044858932 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:27:52.403577089 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:27:52.411215067 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:27:52.418133974 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:27:52.425283909 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:27:52.432215929 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:28:14.795686960 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:28:14.803141117 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:28:14.810409069 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:28:14.817903042 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:28:14.825268984 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:28:37.202157974 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:28:37.210141897 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:28:37.217525005 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:28:37.225770950 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:28:37.235245943 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:28:59.593838930 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:28:59.601519108 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:28:59.609118938 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:28:59.616468906 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 03:28:59.624023914 CET | 192.168.2.23 | 8.8.8.8 | 0x0 | Standard query (0) | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 02:27:06 |
Start date (UTC): | 30/12/2024 |
Path: | /tmp/.Sarm5.elf |
Arguments: | /tmp/.Sarm5.elf |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 02:27:06 |
Start date (UTC): | 30/12/2024 |
Path: | /tmp/.Sarm5.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 02:27:06 |
Start date (UTC): | 30/12/2024 |
Path: | /tmp/.Sarm5.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |