Edit tour
Linux
Analysis Report
arc.elf
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Multi AV Scanner detection for submitted file
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1583627 |
Start date and time: | 2025-01-03 08:19:15 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 10m 42s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | arc.elf |
Detection: | MAL |
Classification: | mal48.linELF@0/0@0/0 |
Cookbook Comments: |
|
- No process behavior to analyse as no analysis process or sample was found
- Max analysis timeout: 600s exceeded, the analysis took too long
Command: | /tmp/arc.elf |
PID: | 6287 |
Exit Code: | 255 |
Exit Code Info: | |
Killed: | False |
Standard Output: | |
Standard Error: |
⊘No yara matches
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | ReversingLabs: |
Source: | String: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: |
Source: | .symtab present: |
Source: | Classification label: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | Windows Management Instrumentation | 1 Scripting | Path Interception | Direct Volume Access | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
⊘No configs have been found
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
21% | ReversingLabs | Linux.Trojan.Mirai |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
⊘No contacted domains info
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
91.189.91.43 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
109.202.202.202 | Get hash | malicious | Unknown | Browse |
| |
91.189.91.43 | Get hash | malicious | Gafgyt, Mirai | Browse | ||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
91.189.91.42 | Get hash | malicious | Gafgyt, Mirai | Browse | ||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse |
⊘No context
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CANONICAL-ASGB | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
CANONICAL-ASGB | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
INIT7CH | Get hash | malicious | Gafgyt, Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 6.092014957517813 |
TrID: |
|
File name: | arc.elf |
File size: | 67'452 bytes |
MD5: | 7aafc24b9d72fefb90c719a0e57f65b8 |
SHA1: | fb321051fd3542cb444095101ac18425470a8d38 |
SHA256: | 4a93a9565f9ca0a8d6b4ca308ca2b66f5f161f7b9e09bf72272eb15b3429a6fd |
SHA512: | 323028a1b75ceadf0aef79df99b450bff8338341f42056b1845476c13bf8ec744d7c157337f8afc39228c385784731923945cf1316e4d87f1d8fe72f70bf101b |
SSDEEP: | 768:eiuMWcEQahkUbSELr9nQfrPNi5rKpGQ6D7IbzVrEZZie6Prj86GRDniQb0p:eNSuhkArhQTVOYgYxE/ie6PUHRDniQb |
TLSH: | EC63D8795446B1AEDBE5F0B4FC0311F62C010B19ABAC92C3658BF0FEAE2474C6656E17 |
File Content Preview: | .ELF..............].....$...4...........4. ...(.........4...4...4.......................4...4...4................................................ ......D...D...D.......H........ ......T...T...T.......................H...H...H... ... ...........Q.td....... |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 8 |
Section Header Offset: | 66572 |
Section Header Size: | 40 |
Number of Section Headers: | 22 |
Header String Table Index: | 21 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.interp | PROGBITS | 0x10134 | 0x134 | 0x14 | 0x0 | 0x2 | A | 0 | 0 | 1 |
.note.ABI-tag | NOTE | 0x10148 | 0x148 | 0x20 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.hash | HASH | 0x10168 | 0x168 | 0x190 | 0x4 | 0x2 | A | 4 | 0 | 4 |
.dynsym | DYNSYM | 0x102f8 | 0x2f8 | 0x3d0 | 0x10 | 0x2 | A | 5 | 1 | 4 |
.dynstr | STRTAB | 0x106c8 | 0x6c8 | 0x1c7 | 0x0 | 0x2 | A | 0 | 0 | 1 |
.rela.plt | RELA | 0x10890 | 0x890 | 0x2ac | 0xc | 0x42 | AI | 4 | 16 | 4 |
.init | PROGBITS | 0x10b3c | 0xb3c | 0x22 | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.plt | PROGBITS | 0x10b60 | 0xb60 | 0x2c4 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x10e24 | 0xe24 | 0xceb4 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.fini | PROGBITS | 0x1dcd8 | 0xdcd8 | 0x16 | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.rodata | PROGBITS | 0x1dcf0 | 0xdcf0 | 0xb8c | 0x0 | 0x2 | A | 0 | 0 | 4 |
.eh_frame | PROGBITS | 0x1e87c | 0xe87c | 0x4 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ctors | PROGBITS | 0x21f44 | 0xff44 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x21f4c | 0xff4c | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dynamic | DYNAMIC | 0x21f54 | 0xff54 | 0xa8 | 0x8 | 0x3 | WA | 5 | 0 | 4 |
.got.plt | PROGBITS | 0x21ffc | 0xfffc | 0xf0 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x220ec | 0x100ec | 0x204 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x222f0 | 0x102f0 | 0x9c | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.comment | PROGBITS | 0x0 | 0x102f0 | 0x43 | 0x1 | 0x30 | MS | 0 | 0 | 1 |
.ARC.attributes | <unknown> | 0x0 | 0x10333 | 0x30 | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0x10363 | 0xa9 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
PHDR | 0x34 | 0x10034 | 0x10034 | 0x100 | 0x100 | 2.4906 | 0x5 | R E | 0x4 | ||
INTERP | 0x134 | 0x10134 | 0x10134 | 0x14 | 0x14 | 3.6842 | 0x4 | R | 0x1 | /lib/ld-uClibc.so.0 | .interp |
LOAD | 0x0 | 0x10000 | 0x10000 | 0xe880 | 0xe880 | 6.4387 | 0x5 | R E | 0x2000 | .interp .note.ABI-tag .hash .dynsym .dynstr .rela.plt .init .plt .text .fini .rodata .eh_frame | |
LOAD | 0xff44 | 0x21f44 | 0x21f44 | 0x3ac | 0x448 | 4.9166 | 0x6 | RW | 0x2000 | .ctors .dtors .dynamic .got.plt .data .bss | |
DYNAMIC | 0xff54 | 0x21f54 | 0x21f54 | 0xa8 | 0xa8 | 2.0510 | 0x6 | RW | 0x4 | .dynamic | |
NOTE | 0x148 | 0x10148 | 0x10148 | 0x20 | 0x20 | 1.4988 | 0x4 | R | 0x4 | .note.ABI-tag | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x10 | ||
GNU_RELRO | 0xff44 | 0x21f44 | 0x21f44 | 0xbc | 0xbc | 2.2349 | 0x4 | R | 0x1 | .ctors .dtors .dynamic |
Type | Meta | Value | Tag |
---|---|---|---|
DT_NEEDED | sharedlib | libc.so.0 | 0x1 |
DT_INIT | value | 0x10b40 | 0xc |
DT_FINI | value | 0x1dcdc | 0xd |
DT_HASH | value | 0x10168 | 0x4 |
DT_STRTAB | value | 0x106c8 | 0x5 |
DT_SYMTAB | value | 0x102f8 | 0x6 |
DT_STRSZ | bytes | 455 | 0xa |
DT_SYMENT | bytes | 16 | 0xb |
DT_INIT | value | 0x10b40 | 0xc |
DT_FINI | value | 0x1dcdc | 0xd |
DT_DEBUG | value | 0x0 | 0x15 |
DT_PLTGOT | value | 0x10b60 | 0x3 |
DT_PLTRELSZ | bytes | 684 | 0x2 |
DT_PLTREL | pltrel | DT_RELA | 0x14 |
DT_JMPREL | value | 0x10890 | 0x17 |
DT_NULL | value | 0x0 | 0x0 |
Name | Version Info Name | Version Info File Name | Section Name | Value | Size | Symbol Type | Symbol Bind | Symbol Visibility | Ndx |
---|---|---|---|---|---|---|---|---|---|
.dynsym | 0x0 | 0 | NOTYPE | <unknown> | DEFAULT | SHN_UNDEF | |||
__bss_start | .dynsym | 0x222f0 | 0 | NOTYPE | <unknown> | DEFAULT | 18 | ||
__errno_location | .dynsym | 0x10d88 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
__uClibc_main | .dynsym | 0x10d1c | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
_edata | .dynsym | 0x222f0 | 0 | NOTYPE | <unknown> | DEFAULT | 17 | ||
_end | .dynsym | 0x2238c | 0 | NOTYPE | <unknown> | DEFAULT | 18 | ||
accept | .dynsym | 0x10c44 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
atoi | .dynsym | 0x10da0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
bind | .dynsym | 0x10c80 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
calloc | .dynsym | 0x10c5c | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
chdir | .dynsym | 0x10ca4 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
clock | .dynsym | 0x10dc4 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
close | .dynsym | 0x10df4 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
closedir | .dynsym | 0x10ddc | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
connect | .dynsym | 0x10b90 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
exit | .dynsym | 0x10d94 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
fcntl | .dynsym | 0x10de8 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
fork | .dynsym | 0x10d10 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
free | .dynsym | 0x10e00 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
getpid | .dynsym | 0x10bb4 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
getppid | .dynsym | 0x10d4c | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
getsockname | .dynsym | 0x10e18 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
getsockopt | .dynsym | 0x10d70 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
htonl | .dynsym | 0x10ce0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
htons | .dynsym | 0x10d7c | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
inet_addr | .dynsym | 0x10c8c | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
inet_ntoa | .dynsym | 0x10d40 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
ioctl | .dynsym | 0x10b78 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
kill | .dynsym | 0x10c74 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
listen | .dynsym | 0x10d04 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
malloc | .dynsym | 0x10be4 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
memcpy | .dynsym | 0x10bcc | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
memset | .dynsym | 0x10d28 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
ntohl | .dynsym | 0x10c98 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
ntohs | .dynsym | 0x10d34 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
open | .dynsym | 0x10db8 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
opendir | .dynsym | 0x10d64 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
prctl | .dynsym | 0x10bc0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
read | .dynsym | 0x10cc8 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
readdir | .dynsym | 0x10c20 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
readlink | .dynsym | 0x10bd8 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
realloc | .dynsym | 0x10cf8 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
recv | .dynsym | 0x10b84 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
recvfrom | .dynsym | 0x10bfc | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
rename | .dynsym | 0x10c50 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
select | .dynsym | 0x10c14 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
send | .dynsym | 0x10c38 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
sendto | .dynsym | 0x10cec | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
setsid | .dynsym | 0x10dd0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
setsockopt | .dynsym | 0x10cb0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
sigaddset | .dynsym | 0x10c2c | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
sigemptyset | .dynsym | 0x10b9c | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
signal | .dynsym | 0x10cbc | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
sigprocmask | .dynsym | 0x10e0c | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
sleep | .dynsym | 0x10bf0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
socket | .dynsym | 0x10c08 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
strlen | .dynsym | 0x10dac | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
strncpy | .dynsym | 0x10cd4 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
time | .dynsym | 0x10d58 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
usleep | .dynsym | 0x10ba8 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
write | .dynsym | 0x10c68 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 3, 2025 08:20:17.643254042 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Jan 3, 2025 08:20:20.203102112 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Jan 3, 2025 08:20:25.578749895 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Jan 3, 2025 08:20:41.448282957 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Jan 3, 2025 08:20:47.591434002 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Jan 3, 2025 08:20:51.686722040 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Jan 3, 2025 08:21:22.402710915 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Jan 3, 2025 08:21:42.879826069 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |