Edit tour
Linux
Analysis Report
fuckunix.x86_64.elf
Overview
General Information
Sample name: | fuckunix.x86_64.elf |
Analysis ID: | 1584474 |
MD5: | ec0334b40fe1c306ab2e7a37788c44b8 |
SHA1: | 5a55507248eb51f46ef2dfc296a9246607510434 |
SHA256: | a58781523a35d9033d99bbe68ba203864d5154d5ce1382892a5d034fe46db208 |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Mirai
Score: | 76 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Machine Learning detection for sample
Sample has stripped symbol table
Sample listens on a socket
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Yara signature match
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1584474 |
Start date and time: | 2025-01-05 15:28:27 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 27s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | fuckunix.x86_64.elf |
Detection: | MAL |
Classification: | mal76.troj.linELF@0/0@30/0 |
Command: | /tmp/fuckunix.x86_64.elf |
PID: | 5500 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | listening tun0 |
Standard Error: |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Mirai | Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Mirai_3 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
Linux_Trojan_Gafgyt_9e9530a7 | unknown | unknown |
| |
Linux_Trojan_Gafgyt_807911a2 | unknown | unknown |
| |
Linux_Trojan_Gafgyt_d4227dbf | unknown | unknown |
| |
Click to see the 6 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Mirai_3 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
Linux_Trojan_Gafgyt_9e9530a7 | unknown | unknown |
| |
Linux_Trojan_Gafgyt_807911a2 | unknown | unknown |
| |
Linux_Trojan_Gafgyt_d4227dbf | unknown | unknown |
| |
Click to see the 8 entries |
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Joe Sandbox ML: |
Source: | Socket: | Jump to behavior |
Source: | DNS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | .symtab present: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | Direct Volume Access | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
58% | Virustotal | Browse | ||
61% | ReversingLabs | Linux.Trojan.Mirai | ||
100% | Avira | EXP/ELF.Gafgyt.D | ||
100% | Joe Sandbox ML |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
⊘No contacted domains info
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
185.125.190.26 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
123.253.61.116 | unknown | Thailand | 136523 | COLODEE-AS-APCOLODEEDIGITALNETWORKCOLTDTH | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
185.125.190.26 | Get hash | malicious | Mirai | Browse | ||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Gafgyt | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
123.253.61.116 | Get hash | malicious | Mirai | Browse | ||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse |
⊘No context
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CANONICAL-ASGB | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
COLODEE-AS-APCOLODEEDIGITALNETWORKCOLTDTH | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 6.257581978658178 |
TrID: |
|
File name: | fuckunix.x86_64.elf |
File size: | 42'720 bytes |
MD5: | ec0334b40fe1c306ab2e7a37788c44b8 |
SHA1: | 5a55507248eb51f46ef2dfc296a9246607510434 |
SHA256: | a58781523a35d9033d99bbe68ba203864d5154d5ce1382892a5d034fe46db208 |
SHA512: | d316038aebd891b4126d4ef4cf1f37f1d3e179c135be947bcfdb74c6434c4fe946788a30684da164208cd3163e1c3e5727011e3094f2d913be295f2d61464257 |
SSDEEP: | 768:MIkksBtHmcHjwhqMpbiAI2doAp6XNpQNBcwdjQ9o/89aPsvKQLDL:QksBtHmcHchqYbmApm4NBcwdn89aU3Ln |
TLSH: | 7E131927F64681FDC45AC17842BBBA36D82274FE1239B19737E0FB326997D221E19C44 |
File Content Preview: | .ELF..............>.......@.....@.......`...........@.8...@.......................@.......@...............................................P.......P.....8.......`...............Q.td....................................................H...._........H........ |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 64 |
Program Header Offset: | 64 |
Program Header Size: | 56 |
Number of Program Headers: | 3 |
Section Header Offset: | 42080 |
Section Header Size: | 64 |
Number of Section Headers: | 10 |
Header String Table Index: | 9 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x4000e8 | 0xe8 | 0x13 | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.text | PROGBITS | 0x400100 | 0x100 | 0x8106 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x408206 | 0x8206 | 0xe | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.rodata | PROGBITS | 0x408220 | 0x8220 | 0x1fc0 | 0x0 | 0x2 | A | 0 | 0 | 32 |
.ctors | PROGBITS | 0x50a1e8 | 0xa1e8 | 0x10 | 0x0 | 0x3 | WA | 0 | 0 | 8 |
.dtors | PROGBITS | 0x50a1f8 | 0xa1f8 | 0x10 | 0x0 | 0x3 | WA | 0 | 0 | 8 |
.data | PROGBITS | 0x50a220 | 0xa220 | 0x200 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.bss | NOBITS | 0x50a420 | 0xa420 | 0xb28 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.shstrtab | STRTAB | 0x0 | 0xa420 | 0x3e | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x400000 | 0x400000 | 0xa1e0 | 0xa1e0 | 6.3317 | 0x5 | R E | 0x100000 | .init .text .fini .rodata | |
LOAD | 0xa1e8 | 0x50a1e8 | 0x50a1e8 | 0x238 | 0xd60 | 2.9262 | 0x6 | RW | 0x100000 | .ctors .dtors .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x8 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 5, 2025 15:29:19.390809059 CET | 58228 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:29:19.395576000 CET | 80 | 58228 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:29:19.395665884 CET | 58228 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:29:19.396313906 CET | 58228 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:29:19.401103020 CET | 80 | 58228 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:29:19.401145935 CET | 58228 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:29:19.405927896 CET | 80 | 58228 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:29:29.406260967 CET | 58228 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:29:29.411005974 CET | 80 | 58228 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:29:30.163722992 CET | 46540 | 443 | 192.168.2.14 | 185.125.190.26 |
Jan 5, 2025 15:29:40.776345968 CET | 80 | 58228 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:29:40.776561975 CET | 58228 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:29:40.781459093 CET | 80 | 58228 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:29:41.818629980 CET | 58230 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:29:41.823451996 CET | 80 | 58230 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:29:41.823520899 CET | 58230 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:29:41.824259996 CET | 58230 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:29:41.829137087 CET | 80 | 58230 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:29:41.829189062 CET | 58230 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:29:41.834017992 CET | 80 | 58230 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:30:01.650921106 CET | 46540 | 443 | 192.168.2.14 | 185.125.190.26 |
Jan 5, 2025 15:30:03.200436115 CET | 80 | 58230 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:30:03.200932980 CET | 58230 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:30:03.205770016 CET | 80 | 58230 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:30:04.246728897 CET | 58232 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:30:04.252245903 CET | 80 | 58232 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:30:04.252294064 CET | 58232 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:30:04.252907038 CET | 58232 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:30:04.258307934 CET | 80 | 58232 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:30:04.258351088 CET | 58232 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:30:04.263164997 CET | 80 | 58232 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:30:25.621191025 CET | 80 | 58232 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:30:25.621387959 CET | 58232 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:30:25.626207113 CET | 80 | 58232 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:30:26.664465904 CET | 58234 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:30:26.669264078 CET | 80 | 58234 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:30:26.669348955 CET | 58234 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:30:26.670403004 CET | 58234 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:30:26.675188065 CET | 80 | 58234 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:30:26.675251007 CET | 58234 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:30:26.682039022 CET | 80 | 58234 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:30:36.680057049 CET | 58234 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:30:36.684931993 CET | 80 | 58234 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:30:48.027967930 CET | 80 | 58234 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:30:48.028623104 CET | 58234 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:30:48.033452988 CET | 80 | 58234 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:30:49.095001936 CET | 58236 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:30:49.099874020 CET | 80 | 58236 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:30:49.099946976 CET | 58236 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:30:49.100963116 CET | 58236 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:30:49.105690956 CET | 80 | 58236 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:30:49.105751991 CET | 58236 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:30:49.110532999 CET | 80 | 58236 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:31:10.450472116 CET | 80 | 58236 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:31:10.450694084 CET | 58236 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:31:10.455533981 CET | 80 | 58236 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:31:11.493412018 CET | 58238 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:31:11.498285055 CET | 80 | 58238 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:31:11.498402119 CET | 58238 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:31:11.499464989 CET | 58238 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:31:11.504192114 CET | 80 | 58238 | 123.253.61.116 | 192.168.2.14 |
Jan 5, 2025 15:31:11.504235983 CET | 58238 | 80 | 192.168.2.14 | 123.253.61.116 |
Jan 5, 2025 15:31:11.508985996 CET | 80 | 58238 | 123.253.61.116 | 192.168.2.14 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 5, 2025 15:29:19.349864960 CET | 46641 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:29:19.359736919 CET | 53 | 46641 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:29:19.360477924 CET | 60361 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:29:19.367445946 CET | 53 | 60361 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:29:19.368077040 CET | 47375 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:29:19.375193119 CET | 53 | 47375 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:29:19.375794888 CET | 38678 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:29:19.382747889 CET | 53 | 38678 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:29:19.383382082 CET | 55898 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:29:19.390449047 CET | 53 | 55898 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:29:41.778803110 CET | 53622 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:29:41.786590099 CET | 53 | 53622 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:29:41.787492990 CET | 40340 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:29:41.794408083 CET | 53 | 40340 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:29:41.795381069 CET | 40278 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:29:41.802412987 CET | 53 | 40278 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:29:41.803159952 CET | 45832 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:29:41.810369968 CET | 53 | 45832 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:29:41.811192989 CET | 40823 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:29:41.818280935 CET | 53 | 40823 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:30:04.202987909 CET | 36956 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:30:04.209868908 CET | 53 | 36956 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:30:04.210510969 CET | 44778 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:30:04.217403889 CET | 53 | 44778 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:30:04.218105078 CET | 35263 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:30:04.224875927 CET | 53 | 35263 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:30:04.225491047 CET | 34194 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:30:04.237958908 CET | 53 | 34194 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:30:04.238766909 CET | 40094 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:30:04.246407032 CET | 53 | 40094 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:30:26.624408007 CET | 43638 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:30:26.631556988 CET | 53 | 43638 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:30:26.632720947 CET | 48632 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:30:26.640192986 CET | 53 | 48632 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:30:26.641284943 CET | 40196 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:30:26.647960901 CET | 53 | 40196 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:30:26.649044037 CET | 35880 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:30:26.655894041 CET | 53 | 35880 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:30:26.656970024 CET | 59253 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:30:26.663928986 CET | 53 | 59253 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:30:49.030467987 CET | 40331 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:30:49.037477016 CET | 53 | 40331 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:30:49.038166046 CET | 51987 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:30:49.069880962 CET | 53 | 51987 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:30:49.071258068 CET | 37206 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:30:49.078341007 CET | 53 | 37206 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:30:49.079387903 CET | 52871 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:30:49.086371899 CET | 53 | 52871 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:30:49.087465048 CET | 55417 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:30:49.094443083 CET | 53 | 55417 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:31:11.453496933 CET | 47999 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:31:11.460422039 CET | 53 | 47999 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:31:11.461091995 CET | 43815 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:31:11.468776941 CET | 53 | 43815 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:31:11.469799995 CET | 53100 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:31:11.476748943 CET | 53 | 53100 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:31:11.477744102 CET | 56907 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:31:11.484730959 CET | 53 | 56907 | 8.8.8.8 | 192.168.2.14 |
Jan 5, 2025 15:31:11.485807896 CET | 33195 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 5, 2025 15:31:11.492882967 CET | 53 | 33195 | 8.8.8.8 | 192.168.2.14 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 5, 2025 15:29:19.349864960 CET | 192.168.2.14 | 8.8.8.8 | 0x44ae | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:29:19.360477924 CET | 192.168.2.14 | 8.8.8.8 | 0x44ae | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:29:19.368077040 CET | 192.168.2.14 | 8.8.8.8 | 0x44ae | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:29:19.375794888 CET | 192.168.2.14 | 8.8.8.8 | 0x44ae | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:29:19.383382082 CET | 192.168.2.14 | 8.8.8.8 | 0x44ae | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:29:41.778803110 CET | 192.168.2.14 | 8.8.8.8 | 0x87f5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:29:41.787492990 CET | 192.168.2.14 | 8.8.8.8 | 0x87f5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:29:41.795381069 CET | 192.168.2.14 | 8.8.8.8 | 0x87f5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:29:41.803159952 CET | 192.168.2.14 | 8.8.8.8 | 0x87f5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:29:41.811192989 CET | 192.168.2.14 | 8.8.8.8 | 0x87f5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:04.202987909 CET | 192.168.2.14 | 8.8.8.8 | 0x2196 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:04.210510969 CET | 192.168.2.14 | 8.8.8.8 | 0x2196 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:04.218105078 CET | 192.168.2.14 | 8.8.8.8 | 0x2196 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:04.225491047 CET | 192.168.2.14 | 8.8.8.8 | 0x2196 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:04.238766909 CET | 192.168.2.14 | 8.8.8.8 | 0x2196 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:26.624408007 CET | 192.168.2.14 | 8.8.8.8 | 0x80a8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:26.632720947 CET | 192.168.2.14 | 8.8.8.8 | 0x80a8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:26.641284943 CET | 192.168.2.14 | 8.8.8.8 | 0x80a8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:26.649044037 CET | 192.168.2.14 | 8.8.8.8 | 0x80a8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:26.656970024 CET | 192.168.2.14 | 8.8.8.8 | 0x80a8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:49.030467987 CET | 192.168.2.14 | 8.8.8.8 | 0x46d5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:49.038166046 CET | 192.168.2.14 | 8.8.8.8 | 0x46d5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:49.071258068 CET | 192.168.2.14 | 8.8.8.8 | 0x46d5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:49.079387903 CET | 192.168.2.14 | 8.8.8.8 | 0x46d5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:49.087465048 CET | 192.168.2.14 | 8.8.8.8 | 0x46d5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:31:11.453496933 CET | 192.168.2.14 | 8.8.8.8 | 0x4d83 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:31:11.461091995 CET | 192.168.2.14 | 8.8.8.8 | 0x4d83 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:31:11.469799995 CET | 192.168.2.14 | 8.8.8.8 | 0x4d83 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:31:11.477744102 CET | 192.168.2.14 | 8.8.8.8 | 0x4d83 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:31:11.485807896 CET | 192.168.2.14 | 8.8.8.8 | 0x4d83 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 5, 2025 15:29:19.359736919 CET | 8.8.8.8 | 192.168.2.14 | 0x44ae | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:29:19.367445946 CET | 8.8.8.8 | 192.168.2.14 | 0x44ae | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:29:19.375193119 CET | 8.8.8.8 | 192.168.2.14 | 0x44ae | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:29:19.382747889 CET | 8.8.8.8 | 192.168.2.14 | 0x44ae | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:29:19.390449047 CET | 8.8.8.8 | 192.168.2.14 | 0x44ae | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:29:41.786590099 CET | 8.8.8.8 | 192.168.2.14 | 0x87f5 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:29:41.794408083 CET | 8.8.8.8 | 192.168.2.14 | 0x87f5 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:29:41.802412987 CET | 8.8.8.8 | 192.168.2.14 | 0x87f5 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:29:41.810369968 CET | 8.8.8.8 | 192.168.2.14 | 0x87f5 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:29:41.818280935 CET | 8.8.8.8 | 192.168.2.14 | 0x87f5 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:04.209868908 CET | 8.8.8.8 | 192.168.2.14 | 0x2196 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:04.217403889 CET | 8.8.8.8 | 192.168.2.14 | 0x2196 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:04.224875927 CET | 8.8.8.8 | 192.168.2.14 | 0x2196 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:04.237958908 CET | 8.8.8.8 | 192.168.2.14 | 0x2196 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:04.246407032 CET | 8.8.8.8 | 192.168.2.14 | 0x2196 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:26.631556988 CET | 8.8.8.8 | 192.168.2.14 | 0x80a8 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:26.640192986 CET | 8.8.8.8 | 192.168.2.14 | 0x80a8 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:26.647960901 CET | 8.8.8.8 | 192.168.2.14 | 0x80a8 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:26.655894041 CET | 8.8.8.8 | 192.168.2.14 | 0x80a8 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:26.663928986 CET | 8.8.8.8 | 192.168.2.14 | 0x80a8 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:49.037477016 CET | 8.8.8.8 | 192.168.2.14 | 0x46d5 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:49.069880962 CET | 8.8.8.8 | 192.168.2.14 | 0x46d5 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:49.078341007 CET | 8.8.8.8 | 192.168.2.14 | 0x46d5 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:49.086371899 CET | 8.8.8.8 | 192.168.2.14 | 0x46d5 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:30:49.094443083 CET | 8.8.8.8 | 192.168.2.14 | 0x46d5 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:31:11.460422039 CET | 8.8.8.8 | 192.168.2.14 | 0x4d83 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:31:11.468776941 CET | 8.8.8.8 | 192.168.2.14 | 0x4d83 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:31:11.476748943 CET | 8.8.8.8 | 192.168.2.14 | 0x4d83 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:31:11.484730959 CET | 8.8.8.8 | 192.168.2.14 | 0x4d83 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 5, 2025 15:31:11.492882967 CET | 8.8.8.8 | 192.168.2.14 | 0x4d83 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.14 | 58228 | 123.253.61.116 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 5, 2025 15:29:19.396313906 CET | 16 | OUT | |
Jan 5, 2025 15:29:19.401145935 CET | 13 | OUT | |
Jan 5, 2025 15:29:29.406260967 CET | 14 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
1 | 192.168.2.14 | 58230 | 123.253.61.116 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 5, 2025 15:29:41.824259996 CET | 16 | OUT | |
Jan 5, 2025 15:29:41.829189062 CET | 13 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
2 | 192.168.2.14 | 58232 | 123.253.61.116 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 5, 2025 15:30:04.252907038 CET | 16 | OUT | |
Jan 5, 2025 15:30:04.258351088 CET | 13 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
3 | 192.168.2.14 | 58234 | 123.253.61.116 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 5, 2025 15:30:26.670403004 CET | 16 | OUT | |
Jan 5, 2025 15:30:26.675251007 CET | 13 | OUT | |
Jan 5, 2025 15:30:36.680057049 CET | 14 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
4 | 192.168.2.14 | 58236 | 123.253.61.116 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 5, 2025 15:30:49.100963116 CET | 16 | OUT | |
Jan 5, 2025 15:30:49.105751991 CET | 13 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
5 | 192.168.2.14 | 58238 | 123.253.61.116 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 5, 2025 15:31:11.499464989 CET | 16 | OUT | |
Jan 5, 2025 15:31:11.504235983 CET | 13 | OUT |
System Behavior
Start time (UTC): | 14:29:18 |
Start date (UTC): | 05/01/2025 |
Path: | /tmp/fuckunix.x86_64.elf |
Arguments: | /tmp/fuckunix.x86_64.elf |
File size: | 42720 bytes |
MD5 hash: | ec0334b40fe1c306ab2e7a37788c44b8 |
Start time (UTC): | 14:29:18 |
Start date (UTC): | 05/01/2025 |
Path: | /tmp/fuckunix.x86_64.elf |
Arguments: | - |
File size: | 42720 bytes |
MD5 hash: | ec0334b40fe1c306ab2e7a37788c44b8 |