Edit tour
Linux
Analysis Report
m68k.elf
Overview
General Information
Detection
Mirai, Moobot
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Detected Mirai
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Mirai
Yara detected Moobot
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match
Classification
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1589162 |
Start date and time: | 2025-01-11 14:30:31 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 32s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | m68k.elf |
Detection: | MAL |
Classification: | mal100.troj.evad.linELF@0/0@19/0 |
Command: | /tmp/m68k.elf |
PID: | 5516 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | done. |
Standard Error: |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Mirai | Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world. | No Attribution |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
MooBot | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Moobot | Yara detected Moobot | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Moobot | Yara detected Moobot | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
JoeSecurity_Moobot | Yara detected Moobot | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Click to see the 1 entries |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-11T14:31:26.724420+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35340 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:31:30.342195+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35342 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:31:35.974840+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35344 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:31:46.595021+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35346 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:31:49.208191+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35348 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:31:53.840383+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35350 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:32:03.475573+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35352 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:32:10.104601+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35354 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:32:15.749991+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35356 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:32:26.394737+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35358 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:32:32.033745+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35360 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:32:38.665703+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35362 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:32:47.277335+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35364 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:32:53.911065+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35366 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:32:59.550507+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35368 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:33:07.428365+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35370 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:33:12.251891+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35372 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:33:18.154803+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35374 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:33:24.781914+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35376 | 154.213.187.118 | 1314 | TCP |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | TCP traffic: |
Source: | DNS traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | .symtab present: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | 1 File Deletion | 1 OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Non-Standard Port | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
61% | ReversingLabs | Linux.Trojan.Mirai | ||
100% | Avira | EXP/ELF.Mirai.Z.A |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
webhorizon.icu | 154.213.187.118 | true | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
154.213.187.118 | webhorizon.icu | Seychelles | 22769 | DDOSING-BGP-NETWORKUS | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
154.213.187.118 | Get hash | malicious | Mirai, Moobot | Browse | ||
Get hash | malicious | Mirai, Moobot | Browse | |||
Get hash | malicious | Mirai, Moobot | Browse | |||
Get hash | malicious | Mirai, Moobot | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
webhorizon.icu | Get hash | malicious | Mirai, Moobot | Browse |
| |
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
DDOSING-BGP-NETWORKUS | Get hash | malicious | Mirai, Moobot | Browse |
| |
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 6.213815777610397 |
TrID: |
|
File name: | m68k.elf |
File size: | 62'732 bytes |
MD5: | 580ca18e5140ee547814f8377ee536f3 |
SHA1: | 3a00867a59798b9bee2b0efc145d3008c65ec087 |
SHA256: | 0d605f7d0ff62a3882e18d347d5a5cbd58f26aa047158b61a5f63fe9f15aa3e7 |
SHA512: | f70753253a2746be75300a66aa66aa4ddaaef9d6858b0fcaa615dead51f7abf354566f8b3a8b0e903ad28fceaea229ab8d95bb54e8cfa95d97ac0b41f1910566 |
SSDEEP: | 1536:1Zdzr2WROpGA83ynq+nzWZ77DfDWFCASE8YC1:1Zd/2W8pGtQzM7f+x8YC1 |
TLSH: | 52531B99F801CD7DF81BD77F4457090ABA71A3D152831B36239BF9A3BC721A91923E81 |
File Content Preview: | .ELF.......................D...4...|.....4. ...(.................................. ....................d..%$...... .dt.Q............................NV..a....da....hN^NuNV..J9...<f>"y.... QJ.g.X.#.....N."y.... QJ.f.A.....J.g.Hy....N.X........<N^NuNV..N^NuN |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 62332 |
Section Header Size: | 40 |
Number of Section Headers: | 10 |
Header String Table Index: | 9 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x80000094 | 0x94 | 0x14 | 0x0 | 0x6 | AX | 0 | 0 | 2 |
.text | PROGBITS | 0x800000a8 | 0xa8 | 0xd592 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.fini | PROGBITS | 0x8000d63a | 0xd63a | 0xe | 0x0 | 0x6 | AX | 0 | 0 | 2 |
.rodata | PROGBITS | 0x8000d648 | 0xd648 | 0x198a | 0x0 | 0x2 | A | 0 | 0 | 2 |
.ctors | PROGBITS | 0x80010fd8 | 0xefd8 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x80010fe0 | 0xefe0 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x80010fec | 0xefec | 0x350 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x8001133c | 0xf33c | 0x21c0 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.shstrtab | STRTAB | 0x0 | 0xf33c | 0x3e | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x80000000 | 0x80000000 | 0xefd2 | 0xefd2 | 6.2535 | 0x5 | R E | 0x2000 | .init .text .fini .rodata | |
LOAD | 0xefd8 | 0x80010fd8 | 0x80010fd8 | 0x364 | 0x2524 | 2.8157 | 0x6 | RW | 0x2000 | .ctors .dtors .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x4 |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-11T14:31:26.724420+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35340 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:31:30.342195+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35342 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:31:35.974840+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35344 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:31:46.595021+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35346 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:31:49.208191+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35348 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:31:53.840383+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35350 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:32:03.475573+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35352 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:32:10.104601+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35354 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:32:15.749991+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35356 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:32:26.394737+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35358 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:32:32.033745+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35360 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:32:38.665703+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35362 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:32:47.277335+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35364 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:32:53.911065+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35366 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:32:59.550507+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35368 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:33:07.428365+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35370 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:33:12.251891+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35372 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:33:18.154803+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35374 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:33:24.781914+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35376 | 154.213.187.118 | 1314 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 11, 2025 14:31:26.715287924 CET | 35340 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:31:26.720274925 CET | 1314 | 35340 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:31:26.720366955 CET | 35340 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:31:26.724420071 CET | 35340 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:31:26.729823112 CET | 1314 | 35340 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:31:27.325391054 CET | 1314 | 35340 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:31:27.326037884 CET | 35340 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:31:27.331037045 CET | 1314 | 35340 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:31:30.336466074 CET | 35342 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:31:30.341336966 CET | 1314 | 35342 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:31:30.341413975 CET | 35342 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:31:30.342195034 CET | 35342 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:31:30.347013950 CET | 1314 | 35342 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:31:30.956653118 CET | 1314 | 35342 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:31:30.957036018 CET | 35342 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:31:30.962055922 CET | 1314 | 35342 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:31:35.968081951 CET | 35344 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:31:35.973340034 CET | 1314 | 35344 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:31:35.973416090 CET | 35344 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:31:35.974839926 CET | 35344 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:31:35.979665041 CET | 1314 | 35344 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:31:36.577120066 CET | 1314 | 35344 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:31:36.577631950 CET | 35344 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:31:36.582475901 CET | 1314 | 35344 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:31:46.589023113 CET | 35346 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:31:46.593825102 CET | 1314 | 35346 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:31:46.593883991 CET | 35346 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:31:46.595021009 CET | 35346 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:31:46.599747896 CET | 1314 | 35346 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:31:47.189166069 CET | 1314 | 35346 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:31:47.189390898 CET | 35346 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:31:47.194206953 CET | 1314 | 35346 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:31:49.201364994 CET | 35348 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:31:49.206425905 CET | 1314 | 35348 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:31:49.206502914 CET | 35348 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:31:49.208190918 CET | 35348 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:31:49.213244915 CET | 1314 | 35348 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:31:49.820204973 CET | 1314 | 35348 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:31:49.820689917 CET | 35348 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:31:49.825611115 CET | 1314 | 35348 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:31:53.833518028 CET | 35350 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:31:53.839068890 CET | 1314 | 35350 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:31:53.839346886 CET | 35350 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:31:53.840383053 CET | 35350 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:31:53.845539093 CET | 1314 | 35350 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:31:54.458456993 CET | 1314 | 35350 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:31:54.458822966 CET | 35350 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:31:54.463818073 CET | 1314 | 35350 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:03.469221115 CET | 35352 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:03.474550962 CET | 1314 | 35352 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:03.474638939 CET | 35352 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:03.475573063 CET | 35352 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:03.480437040 CET | 1314 | 35352 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:04.087503910 CET | 1314 | 35352 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:04.087711096 CET | 35352 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:04.092732906 CET | 1314 | 35352 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:10.097979069 CET | 35354 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:10.103080034 CET | 1314 | 35354 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:10.103141069 CET | 35354 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:10.104600906 CET | 35354 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:10.109603882 CET | 1314 | 35354 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:10.732642889 CET | 1314 | 35354 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:10.733052969 CET | 35354 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:10.738542080 CET | 1314 | 35354 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:15.743614912 CET | 35356 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:15.748950958 CET | 1314 | 35356 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:15.749032021 CET | 35356 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:15.749990940 CET | 35356 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:15.755031109 CET | 1314 | 35356 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:16.379045010 CET | 1314 | 35356 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:16.379303932 CET | 35356 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:16.384144068 CET | 1314 | 35356 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:26.389143944 CET | 35358 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:26.393937111 CET | 1314 | 35358 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:26.394030094 CET | 35358 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:26.394737005 CET | 35358 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:26.399492979 CET | 1314 | 35358 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:27.017585039 CET | 1314 | 35358 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:27.018030882 CET | 35358 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:27.023216009 CET | 1314 | 35358 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:32.027894974 CET | 35360 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:32.032829046 CET | 1314 | 35360 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:32.032912016 CET | 35360 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:32.033745050 CET | 35360 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:32.038574934 CET | 1314 | 35360 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:32.646900892 CET | 1314 | 35360 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:32.647253036 CET | 35360 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:32.652184010 CET | 1314 | 35360 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:38.659096956 CET | 35362 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:38.664078951 CET | 1314 | 35362 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:38.664191961 CET | 35362 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:38.665703058 CET | 35362 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:38.670509100 CET | 1314 | 35362 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:39.259341955 CET | 1314 | 35362 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:39.259892941 CET | 35362 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:39.264844894 CET | 1314 | 35362 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:47.270952940 CET | 35364 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:47.276221037 CET | 1314 | 35364 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:47.276294947 CET | 35364 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:47.277334929 CET | 35364 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:47.282191992 CET | 1314 | 35364 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:47.888602018 CET | 1314 | 35364 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:47.888914108 CET | 35364 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:47.893841028 CET | 1314 | 35364 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:53.902076006 CET | 35366 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:53.907130957 CET | 1314 | 35366 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:53.907419920 CET | 35366 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:53.911065102 CET | 35366 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:53.916225910 CET | 1314 | 35366 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:54.530618906 CET | 1314 | 35366 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:54.530972958 CET | 35366 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:54.535918951 CET | 1314 | 35366 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:59.543428898 CET | 35368 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:59.548360109 CET | 1314 | 35368 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:32:59.548604012 CET | 35368 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:59.550507069 CET | 35368 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:32:59.555360079 CET | 1314 | 35368 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:33:00.155198097 CET | 1314 | 35368 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:33:00.155715942 CET | 35368 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:33:00.160573006 CET | 1314 | 35368 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:33:07.422804117 CET | 35370 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:33:07.427619934 CET | 1314 | 35370 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:33:07.427684069 CET | 35370 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:33:07.428364992 CET | 35370 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:33:07.433149099 CET | 1314 | 35370 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:33:08.057938099 CET | 1314 | 35370 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:33:08.058228970 CET | 35370 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:33:08.063200951 CET | 1314 | 35370 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:33:12.245083094 CET | 35372 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:33:12.249985933 CET | 1314 | 35372 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:33:12.250142097 CET | 35372 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:33:12.251890898 CET | 35372 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:33:12.256773949 CET | 1314 | 35372 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:33:12.845422029 CET | 1314 | 35372 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:33:12.845699072 CET | 35372 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:33:12.850557089 CET | 1314 | 35372 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:33:18.148422956 CET | 35374 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:33:18.153295994 CET | 1314 | 35374 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:33:18.153390884 CET | 35374 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:33:18.154803038 CET | 35374 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:33:18.161153078 CET | 1314 | 35374 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:33:18.764723063 CET | 1314 | 35374 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:33:18.765134096 CET | 35374 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:33:18.770015955 CET | 1314 | 35374 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:33:24.776110888 CET | 35376 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:33:24.780989885 CET | 1314 | 35376 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:33:24.781095028 CET | 35376 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:33:24.781913996 CET | 35376 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:33:24.786732912 CET | 1314 | 35376 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:33:25.399689913 CET | 1314 | 35376 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:33:25.400079966 CET | 35376 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:33:25.405082941 CET | 1314 | 35376 | 154.213.187.118 | 192.168.2.14 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 11, 2025 14:31:26.694506884 CET | 55505 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:31:26.702002048 CET | 53 | 55505 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:31:30.328550100 CET | 41711 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:31:30.335910082 CET | 53 | 41711 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:31:35.959889889 CET | 34969 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:31:35.967206001 CET | 53 | 34969 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:31:46.580929995 CET | 59217 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:31:46.588429928 CET | 53 | 59217 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:31:49.193145990 CET | 34098 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:31:49.200542927 CET | 53 | 34098 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:31:53.824636936 CET | 41734 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:31:53.832489014 CET | 53 | 41734 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:32:03.461461067 CET | 41672 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:32:03.468595982 CET | 53 | 41672 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:32:10.089854002 CET | 32923 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:32:10.097119093 CET | 53 | 32923 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:32:15.735846043 CET | 55860 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:32:15.742995977 CET | 53 | 55860 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:32:26.381282091 CET | 42630 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:32:26.388660908 CET | 53 | 42630 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:32:32.020850897 CET | 52877 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:32:32.027348042 CET | 53 | 52877 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:32:38.651340961 CET | 56798 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:32:38.658257008 CET | 53 | 56798 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:32:47.262797117 CET | 38252 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:32:47.270318031 CET | 53 | 38252 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:32:53.893358946 CET | 43554 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:32:53.899903059 CET | 53 | 43554 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:32:59.535151958 CET | 60832 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:32:59.542027950 CET | 53 | 60832 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:33:07.159187078 CET | 54433 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:33:07.421677113 CET | 53 | 54433 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:33:12.061525106 CET | 59084 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:33:12.243071079 CET | 53 | 59084 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:33:17.849251032 CET | 50993 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:33:18.147176981 CET | 53 | 50993 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:33:24.768189907 CET | 38004 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:33:24.775582075 CET | 53 | 38004 | 8.8.8.8 | 192.168.2.14 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 11, 2025 14:31:26.694506884 CET | 192.168.2.14 | 8.8.8.8 | 0x9e74 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:31:30.328550100 CET | 192.168.2.14 | 8.8.8.8 | 0x991d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:31:35.959889889 CET | 192.168.2.14 | 8.8.8.8 | 0x1f23 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:31:46.580929995 CET | 192.168.2.14 | 8.8.8.8 | 0x62f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:31:49.193145990 CET | 192.168.2.14 | 8.8.8.8 | 0xc19d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:31:53.824636936 CET | 192.168.2.14 | 8.8.8.8 | 0xbbb1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:32:03.461461067 CET | 192.168.2.14 | 8.8.8.8 | 0x83a1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:32:10.089854002 CET | 192.168.2.14 | 8.8.8.8 | 0x9a0d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:32:15.735846043 CET | 192.168.2.14 | 8.8.8.8 | 0x3346 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:32:26.381282091 CET | 192.168.2.14 | 8.8.8.8 | 0x1af5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:32:32.020850897 CET | 192.168.2.14 | 8.8.8.8 | 0xed1a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:32:38.651340961 CET | 192.168.2.14 | 8.8.8.8 | 0x43f9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:32:47.262797117 CET | 192.168.2.14 | 8.8.8.8 | 0x8ac6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:32:53.893358946 CET | 192.168.2.14 | 8.8.8.8 | 0x3cdf | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:32:59.535151958 CET | 192.168.2.14 | 8.8.8.8 | 0xb90e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:33:07.159187078 CET | 192.168.2.14 | 8.8.8.8 | 0x46d2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:33:12.061525106 CET | 192.168.2.14 | 8.8.8.8 | 0x7f23 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:33:17.849251032 CET | 192.168.2.14 | 8.8.8.8 | 0xf2d3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:33:24.768189907 CET | 192.168.2.14 | 8.8.8.8 | 0xcdce | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 11, 2025 14:31:26.702002048 CET | 8.8.8.8 | 192.168.2.14 | 0x9e74 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:31:30.335910082 CET | 8.8.8.8 | 192.168.2.14 | 0x991d | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:31:35.967206001 CET | 8.8.8.8 | 192.168.2.14 | 0x1f23 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:31:46.588429928 CET | 8.8.8.8 | 192.168.2.14 | 0x62f | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:31:49.200542927 CET | 8.8.8.8 | 192.168.2.14 | 0xc19d | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:31:53.832489014 CET | 8.8.8.8 | 192.168.2.14 | 0xbbb1 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:32:03.468595982 CET | 8.8.8.8 | 192.168.2.14 | 0x83a1 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:32:10.097119093 CET | 8.8.8.8 | 192.168.2.14 | 0x9a0d | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:32:15.742995977 CET | 8.8.8.8 | 192.168.2.14 | 0x3346 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:32:26.388660908 CET | 8.8.8.8 | 192.168.2.14 | 0x1af5 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:32:32.027348042 CET | 8.8.8.8 | 192.168.2.14 | 0xed1a | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:32:38.658257008 CET | 8.8.8.8 | 192.168.2.14 | 0x43f9 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:32:47.270318031 CET | 8.8.8.8 | 192.168.2.14 | 0x8ac6 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:32:53.899903059 CET | 8.8.8.8 | 192.168.2.14 | 0x3cdf | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:32:59.542027950 CET | 8.8.8.8 | 192.168.2.14 | 0xb90e | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:33:07.421677113 CET | 8.8.8.8 | 192.168.2.14 | 0x46d2 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:33:12.243071079 CET | 8.8.8.8 | 192.168.2.14 | 0x7f23 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:33:18.147176981 CET | 8.8.8.8 | 192.168.2.14 | 0xf2d3 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:33:24.775582075 CET | 8.8.8.8 | 192.168.2.14 | 0xcdce | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 13:31:25 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/m68k.elf |
Arguments: | /tmp/m68k.elf |
File size: | 4463432 bytes |
MD5 hash: | cd177594338c77b895ae27c33f8f86cc |
Start time (UTC): | 13:31:25 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/m68k.elf |
Arguments: | - |
File size: | 4463432 bytes |
MD5 hash: | cd177594338c77b895ae27c33f8f86cc |
Start time (UTC): | 13:31:25 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/m68k.elf |
Arguments: | - |
File size: | 4463432 bytes |
MD5 hash: | cd177594338c77b895ae27c33f8f86cc |
Start time (UTC): | 13:31:25 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/m68k.elf |
Arguments: | - |
File size: | 4463432 bytes |
MD5 hash: | cd177594338c77b895ae27c33f8f86cc |
Start time (UTC): | 13:31:25 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/m68k.elf |
Arguments: | - |
File size: | 4463432 bytes |
MD5 hash: | cd177594338c77b895ae27c33f8f86cc |