Edit tour
Linux
Analysis Report
mpsl.elf
Overview
General Information
Detection
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1582210 |
Start date and time: | 2024-12-30 04:08:40 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 56s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | mpsl.elf |
Detection: | MAL |
Classification: | mal56.linELF@0/0@2/0 |
Command: | /tmp/mpsl.elf |
PID: | 5531 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | $UICIDEBOY$ |
Standard Error: |
⊘No yara matches
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-30T04:09:27.463081+0100 | 2849816 | 1 | A Network Trojan was detected | 192.168.2.15 | 40788 | 85.239.34.134 | 6666 | TCP |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Networking |
---|
Source: | Suricata IDS: |
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | .symtab present: |
Source: | Classification label: |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | Direct Volume Access | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Non-Standard Port | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
24% | ReversingLabs | Linux.Backdoor.Gafgyt | ||
21% | Virustotal | Browse |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
daisy.ubuntu.com | 162.213.35.24 | true | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
85.239.34.134 | unknown | Russian Federation | 134121 | RAINBOW-HKRainbownetworklimitedHK | true |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
85.239.34.134 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
daisy.ubuntu.com | Get hash | malicious | Gafgyt | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
RAINBOW-HKRainbownetworklimitedHK | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 5.271578742897592 |
TrID: |
|
File name: | mpsl.elf |
File size: | 48'588 bytes |
MD5: | 725c9b84e51f47bf60cd550ceeeb6901 |
SHA1: | affe55fa5fbd59ddf843062110aec861128bed28 |
SHA256: | e56601764d0e0613cd34dfb1fd57bdcdf59ec7fa0ccb1c5fe61b3f81efd05dbc |
SHA512: | a0e64e3d0cc74a14057196139d80dd49405acb67607f4f1ee7b7109652735a9ff637ecb9c4d5d51de8594085de114d6a4e08cbe7df2f56a7c7ea89cc2ef01f4b |
SSDEEP: | 768:4XX2nnT8pKoN7Rt8XCYZ36acuRyXi7kvX63TVi8ocMT:4nGTjoN7Rt8XCsqac/voL |
TLSH: | 9C23C9059F610E7FD82ECE3301960B8225CCDA5661A6B7AA3174FC1CF65B54B4BE3C58 |
File Content Preview: | .ELF......................@.4...L.......4. ...(...............@...@...........................@...@......6..............D...D.@.D.@.................Q.td...............................<.E.'!......'.......................<.E.'!.............9'.. ............ |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 4 |
Section Header Offset: | 47948 |
Section Header Size: | 40 |
Number of Section Headers: | 16 |
Header String Table Index: | 15 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x4000b4 | 0xb4 | 0x8c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x400140 | 0x140 | 0xa9a0 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x40aae0 | 0xaae0 | 0x5c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x40ab40 | 0xab40 | 0x8c0 | 0x0 | 0x2 | A | 0 | 0 | 16 |
.eh_frame | PROGBITS | 0x40c400 | 0xb400 | 0x44 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.tbss | NOBITS | 0x40c444 | 0xb444 | 0x8 | 0x0 | 0x403 | WAT | 0 | 0 | 4 |
.ctors | PROGBITS | 0x40c444 | 0xb444 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x40c44c | 0xb44c | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.jcr | PROGBITS | 0x40c454 | 0xb454 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x40c460 | 0xb460 | 0x244 | 0x0 | 0x3 | WA | 0 | 0 | 16 |
.got | PROGBITS | 0x40c6b0 | 0xb6b0 | 0x430 | 0x4 | 0x10000003 | WAp | 0 | 0 | 16 |
.sbss | NOBITS | 0x40cae0 | 0xbae0 | 0x40 | 0x0 | 0x10000003 | WAp | 0 | 0 | 4 |
.bss | NOBITS | 0x40cb20 | 0xbae0 | 0x2ee8 | 0x0 | 0x3 | WA | 0 | 0 | 16 |
.mdebug.abi32 | PROGBITS | 0x84c | 0xbae0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0xbae0 | 0x6c | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x400000 | 0x400000 | 0xb400 | 0xb400 | 5.3104 | 0x5 | R E | 0x1000 | .init .text .fini .rodata | |
LOAD | 0xb400 | 0x40c400 | 0x40c400 | 0x6e0 | 0x3608 | 3.7356 | 0x6 | RW | 0x1000 | .eh_frame .tbss .ctors .dtors .jcr .data .got .sbss .bss | |
TLS | 0xb444 | 0x40c444 | 0x40c444 | 0x0 | 0x8 | 0.0000 | 0x4 | R | 0x4 | .tbss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-30T04:09:27.463081+0100 | 2849816 | ETPRO MALWARE ELF/Multiverze CnC Checkin | 1 | 192.168.2.15 | 40788 | 85.239.34.134 | 6666 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 30, 2024 04:09:27.440890074 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:09:27.445754051 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:09:27.445816994 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:09:27.463080883 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:09:27.467955112 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:09:28.830542088 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:09:28.830630064 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:09:28.830827951 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:09:28.835573912 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:09:33.837898016 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:09:33.838238001 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:09:33.838273048 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:09:33.843050957 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:09:35.381068945 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:09:35.381196022 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:09:35.381225109 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:09:35.385996103 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:09:38.849118948 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:09:38.849353075 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:09:38.854223013 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:09:43.868551970 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:09:43.868838072 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:09:43.873641968 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:09:48.889898062 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:09:48.890198946 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:09:48.894922018 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:09:50.390450001 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:09:50.390717030 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:09:50.395555019 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:09:53.898122072 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:09:53.898474932 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:09:53.903299093 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:09:58.963562965 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:09:58.963845968 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:09:58.968703985 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:03.969815969 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:03.970122099 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:10:03.974930048 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:05.431627035 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:05.431989908 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:10:05.436858892 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:08.984858036 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:08.985050917 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:10:08.989881992 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:14.032891035 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:14.033288002 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:10:14.038146019 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:19.045691967 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:19.046076059 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:10:19.050816059 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:20.441603899 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:20.441879034 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:10:20.446803093 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:24.057267904 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:24.057687998 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:10:24.062638998 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:29.064781904 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:29.065244913 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:10:29.070091963 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:34.073671103 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:34.073973894 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:10:34.079814911 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:35.448852062 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:35.449094057 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:10:35.455003977 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:39.084117889 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:39.084356070 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:10:39.089224100 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:44.161717892 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:44.161986113 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:10:44.166810989 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:49.170696974 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:49.170974016 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:10:49.175860882 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:50.463519096 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:50.463793039 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:10:50.468732119 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:54.184232950 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:54.184475899 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:10:54.189280033 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:59.224980116 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:10:59.225128889 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:10:59.229904890 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:04.266659975 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:04.266827106 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:11:04.271709919 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:05.472814083 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:05.473009109 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:11:05.477894068 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:09.279082060 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:09.279361010 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:11:09.284157991 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:14.292388916 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:14.292782068 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:11:14.297600985 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:19.293694019 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:19.294070005 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:11:19.298918962 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:20.484272957 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:20.484508991 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:11:20.489337921 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:24.357319117 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:24.357536077 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:11:24.362386942 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:29.364308119 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:29.364535093 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:11:29.369364977 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:34.380213976 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:34.380449057 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:11:34.385335922 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:35.494872093 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:35.495093107 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:11:35.499878883 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:39.457144022 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:39.457365990 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:11:39.462223053 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:44.477052927 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:44.477305889 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:11:44.482090950 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:49.489108086 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:49.489483118 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:11:49.494360924 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:50.532847881 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:50.533032894 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:11:50.537974119 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:54.530538082 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:54.530901909 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:11:54.535808086 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:59.541811943 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:11:59.542318106 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:11:59.547147989 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:04.555206060 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:04.555464983 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:12:04.560333967 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:05.544872046 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:05.545031071 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:12:05.549949884 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:09.579416990 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:09.579648018 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:12:09.584574938 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:14.585417986 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:14.585520983 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:12:14.590426922 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:19.661592007 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:19.661892891 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:12:19.666805029 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:20.555229902 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:20.555480003 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:12:20.560247898 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:24.669220924 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:24.669655085 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:12:24.674520016 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:29.682425022 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:29.682811975 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:12:29.687702894 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:34.731792927 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:34.731961012 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:12:34.736741066 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:35.562320948 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:35.562469006 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:12:35.567302942 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:39.731931925 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:39.732351065 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:12:39.737176895 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:44.739685059 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:44.739959955 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:12:44.744823933 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:49.754306078 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:49.754543066 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:12:49.759394884 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:50.569686890 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:50.569848061 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:12:50.574740887 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:54.773369074 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:54.773614883 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:12:54.778436899 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:59.788445950 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Dec 30, 2024 04:12:59.788579941 CET | 40788 | 6666 | 192.168.2.15 | 85.239.34.134 |
Dec 30, 2024 04:12:59.793380976 CET | 6666 | 40788 | 85.239.34.134 | 192.168.2.15 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 30, 2024 04:12:13.470210075 CET | 52933 | 53 | 192.168.2.15 | 1.1.1.1 |
Dec 30, 2024 04:12:13.470251083 CET | 59072 | 53 | 192.168.2.15 | 1.1.1.1 |
Dec 30, 2024 04:12:13.477099895 CET | 53 | 59072 | 1.1.1.1 | 192.168.2.15 |
Dec 30, 2024 04:12:13.477528095 CET | 53 | 52933 | 1.1.1.1 | 192.168.2.15 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 30, 2024 04:12:13.470210075 CET | 192.168.2.15 | 1.1.1.1 | 0x144d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 04:12:13.470251083 CET | 192.168.2.15 | 1.1.1.1 | 0x4146 | Standard query (0) | 28 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 30, 2024 04:12:13.477528095 CET | 1.1.1.1 | 192.168.2.15 | 0x144d | No error (0) | 162.213.35.24 | A (IP address) | IN (0x0001) | false | ||
Dec 30, 2024 04:12:13.477528095 CET | 1.1.1.1 | 192.168.2.15 | 0x144d | No error (0) | 162.213.35.25 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 03:09:26 |
Start date (UTC): | 30/12/2024 |
Path: | /tmp/mpsl.elf |
Arguments: | /tmp/mpsl.elf |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 03:09:26 |
Start date (UTC): | 30/12/2024 |
Path: | /tmp/mpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |