Edit tour
Linux
Analysis Report
mips.elf
Overview
General Information
Detection
Mirai, Moobot
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Detected Mirai
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Mirai
Yara detected Moobot
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match
Classification
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1589157 |
Start date and time: | 2025-01-11 14:22:16 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 31s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | mips.elf |
Detection: | MAL |
Classification: | mal100.troj.evad.linELF@0/0@19/0 |
Command: | /tmp/mips.elf |
PID: | 5523 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | done. |
Standard Error: |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Mirai | Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world. | No Attribution |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
MooBot | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Moobot | Yara detected Moobot | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Moobot | Yara detected Moobot | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
|
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-11T14:23:08.547300+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35344 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:23:17.161972+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35346 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:23:23.804597+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35348 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:23:28.452388+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35350 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:23:36.198583+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35352 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:23:38.847274+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35354 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:23:45.465890+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35356 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:23:52.099239+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35358 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:24:00.711525+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35360 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:24:10.319649+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35362 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:24:11.947547+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35364 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:24:21.568440+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35366 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:24:28.191682+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35368 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:24:29.813198+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35370 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:24:37.443803+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35372 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:24:45.062666+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35374 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:24:54.702759+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35376 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:25:01.349957+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35378 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:25:09.966828+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35380 | 154.213.187.118 | 1314 | TCP |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | TCP traffic: |
Source: | DNS traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | .symtab present: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | 1 File Deletion | 1 OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Non-Standard Port | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
56% | Virustotal | Browse | ||
50% | ReversingLabs | Linux.Trojan.Mirai | ||
100% | Avira | EXP/ELF.Mirai.Z.A |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
webhorizon.icu | 154.213.187.118 | true | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
154.213.187.118 | webhorizon.icu | Seychelles | 22769 | DDOSING-BGP-NETWORKUS | false |
⊘No context
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
webhorizon.icu | Get hash | malicious | Mirai, Moobot | Browse |
| |
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
DDOSING-BGP-NETWORKUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 5.395836814014891 |
TrID: |
|
File name: | mips.elf |
File size: | 76'384 bytes |
MD5: | f4d93073bff0f1813d2e63919279ed07 |
SHA1: | 832ed71744ee67079ce066720a22d75483312b72 |
SHA256: | 3feeac05decb1f0ef77a2609f3727887a78411a544fc62dda7f7dc4f14aefb0a |
SHA512: | 7b560236b882b764df5e2f23bc4a8027ae4f75b2020edb97dead7a52176484b3833a6c11198b2baca176785ed9cb797cf36d0b88ab2c42f05be44f51b4f5991a |
SSDEEP: | 768:uOHdEN88rdOdkr06mCpddIgGg/vPQKTQCQmZzck7XDSWbT2tAjUv5yzmRef8yWRH:aL5d5gLazT7vLU5e/W6nQ9D |
TLSH: | 6673951A6E628FADF759833447B78E21AB5833D627D1D641E26CD6002F7034E641FFA8 |
File Content Preview: | .ELF.....................@.`...4..(X.....4. ...(.............@...@........................ ..E ..E .......* ........dt.Q............................<...'......!'.......................<...'......!... ....'9... ......................<...'......!........'9. |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 75864 |
Section Header Size: | 40 |
Number of Section Headers: | 13 |
Header String Table Index: | 12 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x400094 | 0x94 | 0x8c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x400120 | 0x120 | 0xfaa0 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x40fbc0 | 0xfbc0 | 0x5c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x40fc20 | 0xfc20 | 0x1af0 | 0x0 | 0x2 | A | 0 | 0 | 16 |
.ctors | PROGBITS | 0x452000 | 0x12000 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x452008 | 0x12008 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x452020 | 0x12020 | 0x3a0 | 0x0 | 0x3 | WA | 0 | 0 | 16 |
.got | PROGBITS | 0x4523c0 | 0x123c0 | 0x440 | 0x4 | 0x10000003 | WAp | 0 | 0 | 16 |
.sbss | NOBITS | 0x452800 | 0x12800 | 0x1c | 0x0 | 0x10000003 | WAp | 0 | 0 | 4 |
.bss | NOBITS | 0x452820 | 0x12800 | 0x2200 | 0x0 | 0x3 | WA | 0 | 0 | 16 |
.mdebug.abi32 | PROGBITS | 0x900 | 0x12800 | 0x0 | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0x12800 | 0x57 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x400000 | 0x400000 | 0x11710 | 0x11710 | 5.5435 | 0x5 | R E | 0x10000 | .init .text .fini .rodata | |
LOAD | 0x12000 | 0x452000 | 0x452000 | 0x800 | 0x2a20 | 3.7305 | 0x6 | RW | 0x10000 | .ctors .dtors .data .got .sbss .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-11T14:23:08.547300+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35344 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:23:17.161972+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35346 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:23:23.804597+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35348 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:23:28.452388+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35350 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:23:36.198583+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35352 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:23:38.847274+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35354 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:23:45.465890+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35356 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:23:52.099239+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35358 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:24:00.711525+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35360 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:24:10.319649+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35362 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:24:11.947547+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35364 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:24:21.568440+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35366 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:24:28.191682+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35368 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:24:29.813198+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35370 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:24:37.443803+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35372 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:24:45.062666+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35374 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:24:54.702759+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35376 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:25:01.349957+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35378 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:25:09.966828+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35380 | 154.213.187.118 | 1314 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 11, 2025 14:23:08.538638115 CET | 35344 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:08.543567896 CET | 1314 | 35344 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:08.543633938 CET | 35344 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:08.547300100 CET | 35344 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:08.552213907 CET | 1314 | 35344 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:09.144376040 CET | 1314 | 35344 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:09.144656897 CET | 35344 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:09.151113033 CET | 1314 | 35344 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:17.155910969 CET | 35346 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:17.160975933 CET | 1314 | 35346 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:17.161051989 CET | 35346 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:17.161972046 CET | 35346 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:17.166841030 CET | 1314 | 35346 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:17.782470942 CET | 1314 | 35346 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:17.782910109 CET | 35346 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:17.791292906 CET | 1314 | 35346 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:23.797938108 CET | 35348 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:23.803145885 CET | 1314 | 35348 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:23.803232908 CET | 35348 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:23.804596901 CET | 35348 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:23.809415102 CET | 1314 | 35348 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:24.433610916 CET | 1314 | 35348 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:24.433806896 CET | 35348 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:24.438652039 CET | 1314 | 35348 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:28.445430040 CET | 35350 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:28.450325012 CET | 1314 | 35350 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:28.450403929 CET | 35350 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:28.452388048 CET | 35350 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:28.457288980 CET | 1314 | 35350 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:29.046149015 CET | 1314 | 35350 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:29.046391010 CET | 35350 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:29.051414967 CET | 1314 | 35350 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:36.192826033 CET | 35352 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:36.197649002 CET | 1314 | 35352 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:36.197721004 CET | 35352 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:36.198582888 CET | 35352 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:36.203330994 CET | 1314 | 35352 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:36.828567028 CET | 1314 | 35352 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:36.828893900 CET | 35352 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:36.833746910 CET | 1314 | 35352 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:38.840815067 CET | 35354 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:38.845772982 CET | 1314 | 35354 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:38.845853090 CET | 35354 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:38.847274065 CET | 35354 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:38.852121115 CET | 1314 | 35354 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:39.449703932 CET | 1314 | 35354 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:39.449955940 CET | 35354 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:39.450047970 CET | 35354 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:39.454933882 CET | 1314 | 35354 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:45.460349083 CET | 35356 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:45.465203047 CET | 1314 | 35356 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:45.465296984 CET | 35356 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:45.465889931 CET | 35356 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:45.470705032 CET | 1314 | 35356 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:46.081067085 CET | 1314 | 35356 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:46.081300020 CET | 35356 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:46.086126089 CET | 1314 | 35356 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:52.093147993 CET | 35358 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:52.098170996 CET | 1314 | 35358 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:52.098225117 CET | 35358 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:52.099239111 CET | 35358 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:52.104195118 CET | 1314 | 35358 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:52.693476915 CET | 1314 | 35358 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:23:52.693660975 CET | 35358 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:23:52.698878050 CET | 1314 | 35358 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:00.705185890 CET | 35360 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:00.710170031 CET | 1314 | 35360 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:00.710254908 CET | 35360 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:00.711524963 CET | 35360 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:00.716375113 CET | 1314 | 35360 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:01.302527905 CET | 1314 | 35360 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:01.303170919 CET | 35360 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:01.308017015 CET | 1314 | 35360 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:10.313239098 CET | 35362 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:10.318183899 CET | 1314 | 35362 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:10.318281889 CET | 35362 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:10.319648981 CET | 35362 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:10.324506044 CET | 1314 | 35362 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:10.929775953 CET | 1314 | 35362 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:10.930202961 CET | 35362 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:10.935106039 CET | 1314 | 35362 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:11.941158056 CET | 35364 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:11.946094036 CET | 1314 | 35364 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:11.946176052 CET | 35364 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:11.947546959 CET | 35364 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:11.952430964 CET | 1314 | 35364 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:12.550178051 CET | 1314 | 35364 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:12.550404072 CET | 35364 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:12.555310011 CET | 1314 | 35364 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:21.561908960 CET | 35366 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:21.566899061 CET | 1314 | 35366 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:21.567023993 CET | 35366 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:21.568439960 CET | 35366 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:21.573290110 CET | 1314 | 35366 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:22.173579931 CET | 1314 | 35366 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:22.173979044 CET | 35366 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:22.178920984 CET | 1314 | 35366 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:28.185384035 CET | 35368 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:28.190274000 CET | 1314 | 35368 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:28.190359116 CET | 35368 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:28.191682100 CET | 35368 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:28.198859930 CET | 1314 | 35368 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:28.795207024 CET | 1314 | 35368 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:28.795648098 CET | 35368 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:28.800597906 CET | 1314 | 35368 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:29.806551933 CET | 35370 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:29.811580896 CET | 1314 | 35370 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:29.811731100 CET | 35370 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:29.813198090 CET | 35370 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:29.818439960 CET | 1314 | 35370 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:30.423161983 CET | 1314 | 35370 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:30.423618078 CET | 35370 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:30.428579092 CET | 1314 | 35370 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:37.436074972 CET | 35372 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:37.441710949 CET | 1314 | 35372 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:37.441883087 CET | 35372 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:37.443803072 CET | 35372 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:37.448698044 CET | 1314 | 35372 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:38.044032097 CET | 1314 | 35372 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:38.044276953 CET | 35372 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:38.049154997 CET | 1314 | 35372 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:45.056248903 CET | 35374 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:45.061129093 CET | 1314 | 35374 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:45.061263084 CET | 35374 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:45.062665939 CET | 35374 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:45.067456961 CET | 1314 | 35374 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:45.684629917 CET | 1314 | 35374 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:45.684952974 CET | 35374 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:45.689836025 CET | 1314 | 35374 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:54.696403980 CET | 35376 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:54.701294899 CET | 1314 | 35376 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:54.701421022 CET | 35376 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:54.702759027 CET | 35376 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:54.707545042 CET | 1314 | 35376 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:55.331191063 CET | 1314 | 35376 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:24:55.331635952 CET | 35376 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:24:55.338890076 CET | 1314 | 35376 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:25:01.343481064 CET | 35378 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:25:01.348448038 CET | 1314 | 35378 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:25:01.348541975 CET | 35378 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:25:01.349956989 CET | 35378 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:25:01.354824066 CET | 1314 | 35378 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:25:01.948879004 CET | 1314 | 35378 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:25:01.948983908 CET | 35378 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:25:01.953905106 CET | 1314 | 35378 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:25:09.960345984 CET | 35380 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:25:09.965334892 CET | 1314 | 35380 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:25:09.965461016 CET | 35380 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:25:09.966828108 CET | 35380 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:25:09.971707106 CET | 1314 | 35380 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:25:10.564635992 CET | 1314 | 35380 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:25:10.564958096 CET | 35380 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:25:10.569799900 CET | 1314 | 35380 | 154.213.187.118 | 192.168.2.14 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 11, 2025 14:23:08.364846945 CET | 56334 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:23:08.536569118 CET | 53 | 56334 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:23:17.148391962 CET | 59272 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:23:17.155160904 CET | 53 | 59272 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:23:23.786027908 CET | 43584 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:23:23.797193050 CET | 53 | 43584 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:23:28.437335968 CET | 37156 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:23:28.444549084 CET | 53 | 37156 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:23:36.049566984 CET | 37590 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:23:36.192104101 CET | 53 | 37590 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:23:38.832686901 CET | 40026 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:23:38.840039968 CET | 53 | 40026 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:23:45.452146053 CET | 41330 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:23:45.459968090 CET | 53 | 41330 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:23:52.084491968 CET | 52513 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:23:52.091924906 CET | 53 | 52513 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:24:00.696541071 CET | 34850 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:24:00.704272985 CET | 53 | 34850 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:24:10.305325985 CET | 40445 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:24:10.312380075 CET | 53 | 40445 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:24:11.933640003 CET | 52134 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:24:11.940479040 CET | 53 | 52134 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:24:21.554042101 CET | 50295 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:24:21.561202049 CET | 53 | 50295 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:24:28.177939892 CET | 34774 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:24:28.184515953 CET | 53 | 34774 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:24:29.798953056 CET | 39255 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:24:29.805792093 CET | 53 | 39255 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:24:37.427352905 CET | 32983 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:24:37.434700966 CET | 53 | 32983 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:24:45.048321962 CET | 48535 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:24:45.055443048 CET | 53 | 48535 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:24:54.688553095 CET | 34682 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:24:54.695646048 CET | 53 | 34682 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:25:01.335469961 CET | 37399 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:25:01.342690945 CET | 53 | 37399 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:25:09.952420950 CET | 57371 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:25:09.959686041 CET | 53 | 57371 | 8.8.8.8 | 192.168.2.14 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 11, 2025 14:23:08.364846945 CET | 192.168.2.14 | 8.8.8.8 | 0x565b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:23:17.148391962 CET | 192.168.2.14 | 8.8.8.8 | 0x639b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:23:23.786027908 CET | 192.168.2.14 | 8.8.8.8 | 0x971d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:23:28.437335968 CET | 192.168.2.14 | 8.8.8.8 | 0x7bd3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:23:36.049566984 CET | 192.168.2.14 | 8.8.8.8 | 0xcada | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:23:38.832686901 CET | 192.168.2.14 | 8.8.8.8 | 0x7b9d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:23:45.452146053 CET | 192.168.2.14 | 8.8.8.8 | 0x75da | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:23:52.084491968 CET | 192.168.2.14 | 8.8.8.8 | 0x52ac | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:24:00.696541071 CET | 192.168.2.14 | 8.8.8.8 | 0x2259 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:24:10.305325985 CET | 192.168.2.14 | 8.8.8.8 | 0xa6c6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:24:11.933640003 CET | 192.168.2.14 | 8.8.8.8 | 0x67a4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:24:21.554042101 CET | 192.168.2.14 | 8.8.8.8 | 0x967c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:24:28.177939892 CET | 192.168.2.14 | 8.8.8.8 | 0x1d2f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:24:29.798953056 CET | 192.168.2.14 | 8.8.8.8 | 0xa40c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:24:37.427352905 CET | 192.168.2.14 | 8.8.8.8 | 0x67e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:24:45.048321962 CET | 192.168.2.14 | 8.8.8.8 | 0x94bc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:24:54.688553095 CET | 192.168.2.14 | 8.8.8.8 | 0xaf5e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:25:01.335469961 CET | 192.168.2.14 | 8.8.8.8 | 0x364a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:25:09.952420950 CET | 192.168.2.14 | 8.8.8.8 | 0x2637 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 11, 2025 14:23:08.536569118 CET | 8.8.8.8 | 192.168.2.14 | 0x565b | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:23:17.155160904 CET | 8.8.8.8 | 192.168.2.14 | 0x639b | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:23:23.797193050 CET | 8.8.8.8 | 192.168.2.14 | 0x971d | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:23:28.444549084 CET | 8.8.8.8 | 192.168.2.14 | 0x7bd3 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:23:36.192104101 CET | 8.8.8.8 | 192.168.2.14 | 0xcada | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:23:38.840039968 CET | 8.8.8.8 | 192.168.2.14 | 0x7b9d | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:23:45.459968090 CET | 8.8.8.8 | 192.168.2.14 | 0x75da | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:23:52.091924906 CET | 8.8.8.8 | 192.168.2.14 | 0x52ac | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:24:00.704272985 CET | 8.8.8.8 | 192.168.2.14 | 0x2259 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:24:10.312380075 CET | 8.8.8.8 | 192.168.2.14 | 0xa6c6 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:24:11.940479040 CET | 8.8.8.8 | 192.168.2.14 | 0x67a4 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:24:21.561202049 CET | 8.8.8.8 | 192.168.2.14 | 0x967c | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:24:28.184515953 CET | 8.8.8.8 | 192.168.2.14 | 0x1d2f | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:24:29.805792093 CET | 8.8.8.8 | 192.168.2.14 | 0xa40c | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:24:37.434700966 CET | 8.8.8.8 | 192.168.2.14 | 0x67e | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:24:45.055443048 CET | 8.8.8.8 | 192.168.2.14 | 0x94bc | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:24:54.695646048 CET | 8.8.8.8 | 192.168.2.14 | 0xaf5e | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:25:01.342690945 CET | 8.8.8.8 | 192.168.2.14 | 0x364a | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:25:09.959686041 CET | 8.8.8.8 | 192.168.2.14 | 0x2637 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 13:23:07 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/mips.elf |
Arguments: | /tmp/mips.elf |
File size: | 5777432 bytes |
MD5 hash: | 0083f1f0e77be34ad27f849842bbb00c |
Start time (UTC): | 13:23:07 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/mips.elf |
Arguments: | - |
File size: | 5777432 bytes |
MD5 hash: | 0083f1f0e77be34ad27f849842bbb00c |
Start time (UTC): | 13:23:07 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/mips.elf |
Arguments: | - |
File size: | 5777432 bytes |
MD5 hash: | 0083f1f0e77be34ad27f849842bbb00c |
Start time (UTC): | 13:23:07 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/mips.elf |
Arguments: | - |
File size: | 5777432 bytes |
MD5 hash: | 0083f1f0e77be34ad27f849842bbb00c |
Start time (UTC): | 13:23:07 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/mips.elf |
Arguments: | - |
File size: | 5777432 bytes |
MD5 hash: | 0083f1f0e77be34ad27f849842bbb00c |