Edit tour
Linux
Analysis Report
arm.elf
Overview
General Information
Sample name: | arm.elf |
Analysis ID: | 1589163 |
MD5: | 436f659b243018cde3661a2504754379 |
SHA1: | a28edeced9da46ef133f366b2ce8d46a31cf9626 |
SHA256: | fe4724af2151cebbcc41e1dac2e8c119fc269f90f21328bfebdb869ca39832d3 |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Mirai, Moobot
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Detected Mirai
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Mirai
Yara detected Moobot
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match
Classification
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1589163 |
Start date and time: | 2025-01-11 14:32:20 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 35s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | arm.elf |
Detection: | MAL |
Classification: | mal100.troj.evad.linELF@0/0@22/0 |
Command: | /tmp/arm.elf |
PID: | 5544 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | done. |
Standard Error: |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Mirai | Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world. | No Attribution |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
MooBot | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Moobot | Yara detected Moobot | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Moobot | Yara detected Moobot | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
JoeSecurity_Moobot | Yara detected Moobot | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Click to see the 1 entries |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-11T14:33:13.001701+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49326 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:33:18.617736+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49328 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:33:26.236792+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49330 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:33:29.861047+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49332 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:33:36.732684+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49334 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:33:41.539952+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49336 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:33:50.356211+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49338 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:33:58.995937+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49340 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:34:08.634868+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49342 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:34:16.275637+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49344 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:34:23.916333+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49346 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:34:26.537546+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49348 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:34:34.324338+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49350 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:34:37.967535+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49352 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:34:45.594443+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49354 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:34:48.207134+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49356 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:34:49.826937+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49358 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:34:58.447326+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49360 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:35:06.086941+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49362 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:35:07.699774+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49364 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:35:10.334534+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49366 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:35:13.958232+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49368 | 154.213.187.118 | 1314 | TCP |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | TCP traffic: |
Source: | DNS traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | .symtab present: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | 1 File Deletion | 1 OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Non-Standard Port | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
57% | Virustotal | Browse | ||
61% | ReversingLabs | Linux.Trojan.Mirai | ||
100% | Avira | EXP/ELF.Mirai.Z.A |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
webhorizon.icu | 154.213.187.118 | true | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
154.213.187.118 | webhorizon.icu | Seychelles | 22769 | DDOSING-BGP-NETWORKUS | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
154.213.187.118 | Get hash | malicious | Mirai, Moobot | Browse | ||
Get hash | malicious | Mirai, Moobot | Browse | |||
Get hash | malicious | Mirai, Moobot | Browse | |||
Get hash | malicious | Mirai, Moobot | Browse | |||
Get hash | malicious | Mirai, Moobot | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
webhorizon.icu | Get hash | malicious | Mirai, Moobot | Browse |
| |
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
DDOSING-BGP-NETWORKUS | Get hash | malicious | Mirai, Moobot | Browse |
| |
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 6.097917883380458 |
TrID: |
|
File name: | arm.elf |
File size: | 61'256 bytes |
MD5: | 436f659b243018cde3661a2504754379 |
SHA1: | a28edeced9da46ef133f366b2ce8d46a31cf9626 |
SHA256: | fe4724af2151cebbcc41e1dac2e8c119fc269f90f21328bfebdb869ca39832d3 |
SHA512: | a43f3f9dd3af4d85ee79d7ae2c69997f3f9169322777857a8ec5d0a33edec053dc6c1ed3459d1c0644289b4b92d7d398fac1656235ff06d0504b4e2e12fea6d3 |
SSDEEP: | 1536:qfM5Ug0HC5oqTJA9hB7JkGQ8DGgLgv6nw:2MfoxJ88it6nw |
TLSH: | 5F533951F8815623C6D1127BF66E428D3B2623E8E2DF73079D225F2037C692B0DABE55 |
File Content Preview: | .ELF...a..........(.........4...........4. ...(.....................................................h...<%..........Q.td..................................-...L."....3..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 60856 |
Section Header Size: | 40 |
Number of Section Headers: | 10 |
Header String Table Index: | 9 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x8094 | 0x94 | 0x18 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x80b0 | 0xb0 | 0xcfd0 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x15080 | 0xd080 | 0x14 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x15094 | 0xd094 | 0x1978 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ctors | PROGBITS | 0x1ea10 | 0xea10 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x1ea18 | 0xea18 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x1ea24 | 0xea24 | 0x354 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x1ed78 | 0xed78 | 0x21d4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.shstrtab | STRTAB | 0x0 | 0xed78 | 0x3e | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8000 | 0x8000 | 0xea0c | 0xea0c | 6.1358 | 0x5 | R E | 0x8000 | .init .text .fini .rodata | |
LOAD | 0xea10 | 0x1ea10 | 0x1ea10 | 0x368 | 0x253c | 2.6434 | 0x6 | RW | 0x8000 | .ctors .dtors .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-11T14:33:13.001701+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49326 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:33:18.617736+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49328 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:33:26.236792+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49330 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:33:29.861047+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49332 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:33:36.732684+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49334 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:33:41.539952+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49336 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:33:50.356211+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49338 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:33:58.995937+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49340 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:34:08.634868+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49342 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:34:16.275637+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49344 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:34:23.916333+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49346 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:34:26.537546+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49348 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:34:34.324338+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49350 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:34:37.967535+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49352 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:34:45.594443+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49354 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:34:48.207134+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49356 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:34:49.826937+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49358 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:34:58.447326+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49360 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:35:06.086941+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49362 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:35:07.699774+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49364 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:35:10.334534+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49366 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:35:13.958232+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49368 | 154.213.187.118 | 1314 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 11, 2025 14:33:12.993225098 CET | 49326 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:12.998066902 CET | 1314 | 49326 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:12.998119116 CET | 49326 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:13.001701117 CET | 49326 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:13.006441116 CET | 1314 | 49326 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:13.600378036 CET | 1314 | 49326 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:13.600770950 CET | 49326 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:13.605684042 CET | 1314 | 49326 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:18.612025023 CET | 49328 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:18.616895914 CET | 1314 | 49328 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:18.617003918 CET | 49328 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:18.617736101 CET | 49328 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:18.622526884 CET | 1314 | 49328 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:19.219906092 CET | 1314 | 49328 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:19.220290899 CET | 49328 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:19.225425959 CET | 1314 | 49328 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:26.230961084 CET | 49330 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:26.235872030 CET | 1314 | 49330 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:26.235974073 CET | 49330 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:26.236792088 CET | 49330 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:26.241671085 CET | 1314 | 49330 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:26.842020988 CET | 1314 | 49330 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:26.842458010 CET | 49330 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:26.847387075 CET | 1314 | 49330 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:29.854696989 CET | 49332 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:29.859906912 CET | 1314 | 49332 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:29.859991074 CET | 49332 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:29.861047029 CET | 49332 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:29.865983963 CET | 1314 | 49332 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:30.463063955 CET | 1314 | 49332 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:30.463361979 CET | 49332 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:30.468569040 CET | 1314 | 49332 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:36.726988077 CET | 49334 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:36.731889009 CET | 1314 | 49334 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:36.731945992 CET | 49334 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:36.732683897 CET | 49334 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:36.737523079 CET | 1314 | 49334 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:37.342895031 CET | 1314 | 49334 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:37.343123913 CET | 49334 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:37.347989082 CET | 1314 | 49334 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:41.533610106 CET | 49336 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:41.538472891 CET | 1314 | 49336 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:41.538548946 CET | 49336 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:41.539952040 CET | 49336 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:41.544806004 CET | 1314 | 49336 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:42.149480104 CET | 1314 | 49336 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:42.149652958 CET | 49336 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:42.154532909 CET | 1314 | 49336 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:50.350260973 CET | 49338 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:50.355195045 CET | 1314 | 49338 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:50.355284929 CET | 49338 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:50.356210947 CET | 49338 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:50.361118078 CET | 1314 | 49338 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:50.978710890 CET | 1314 | 49338 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:50.979013920 CET | 49338 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:50.983838081 CET | 1314 | 49338 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:58.989875078 CET | 49340 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:58.994880915 CET | 1314 | 49340 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:58.995066881 CET | 49340 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:58.995937109 CET | 49340 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:59.001163960 CET | 1314 | 49340 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:59.617307901 CET | 1314 | 49340 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:33:59.617650986 CET | 49340 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:33:59.622572899 CET | 1314 | 49340 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:08.628129005 CET | 49342 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:08.633857012 CET | 1314 | 49342 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:08.633925915 CET | 49342 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:08.634867907 CET | 49342 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:08.640255928 CET | 1314 | 49342 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:09.256731033 CET | 1314 | 49342 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:09.257095098 CET | 49342 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:09.262006044 CET | 1314 | 49342 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:16.269062042 CET | 49344 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:16.273988962 CET | 1314 | 49344 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:16.274085999 CET | 49344 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:16.275636911 CET | 49344 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:16.280467033 CET | 1314 | 49344 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:16.897344112 CET | 1314 | 49344 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:16.897918940 CET | 49344 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:16.903177977 CET | 1314 | 49344 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:23.909953117 CET | 49346 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:23.914911985 CET | 1314 | 49346 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:23.915016890 CET | 49346 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:23.916332960 CET | 49346 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:23.921186924 CET | 1314 | 49346 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:24.518811941 CET | 1314 | 49346 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:24.519067049 CET | 49346 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:24.524147987 CET | 1314 | 49346 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:26.531194925 CET | 49348 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:26.536200047 CET | 1314 | 49348 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:26.536287069 CET | 49348 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:26.537545919 CET | 49348 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:26.542417049 CET | 1314 | 49348 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:27.140183926 CET | 1314 | 49348 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:27.140355110 CET | 49348 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:27.145370960 CET | 1314 | 49348 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:34.318039894 CET | 49350 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:34.323026896 CET | 1314 | 49350 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:34.323118925 CET | 49350 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:34.324337959 CET | 49350 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:34.329180002 CET | 1314 | 49350 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:34.945431948 CET | 1314 | 49350 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:34.945799112 CET | 49350 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:34.950670004 CET | 1314 | 49350 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:37.960819006 CET | 49352 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:37.965750933 CET | 1314 | 49352 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:37.965847969 CET | 49352 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:37.967535019 CET | 49352 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:37.972299099 CET | 1314 | 49352 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:38.576356888 CET | 1314 | 49352 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:38.576814890 CET | 49352 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:38.581706047 CET | 1314 | 49352 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:45.588248968 CET | 49354 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:45.593216896 CET | 1314 | 49354 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:45.593327999 CET | 49354 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:45.594443083 CET | 49354 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:45.599311113 CET | 1314 | 49354 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:46.188832045 CET | 1314 | 49354 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:46.189138889 CET | 49354 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:46.194118977 CET | 1314 | 49354 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:48.200874090 CET | 49356 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:48.205801010 CET | 1314 | 49356 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:48.205885887 CET | 49356 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:48.207134008 CET | 49356 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:48.212027073 CET | 1314 | 49356 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:48.810123920 CET | 1314 | 49356 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:48.810410023 CET | 49356 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:48.815476894 CET | 1314 | 49356 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:49.821069002 CET | 49358 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:49.826010942 CET | 1314 | 49358 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:49.826077938 CET | 49358 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:49.826936960 CET | 49358 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:49.831883907 CET | 1314 | 49358 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:50.429404974 CET | 1314 | 49358 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:50.429675102 CET | 49358 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:50.434529066 CET | 1314 | 49358 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:58.440939903 CET | 49360 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:58.445935965 CET | 1314 | 49360 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:58.446007967 CET | 49360 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:58.447325945 CET | 49360 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:58.452219963 CET | 1314 | 49360 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:59.069704056 CET | 1314 | 49360 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:34:59.069889069 CET | 49360 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:34:59.074740887 CET | 1314 | 49360 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:35:06.080892086 CET | 49362 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:35:06.085797071 CET | 1314 | 49362 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:35:06.085922956 CET | 49362 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:35:06.086941004 CET | 49362 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:35:06.091782093 CET | 1314 | 49362 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:35:06.680855036 CET | 1314 | 49362 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:35:06.681206942 CET | 49362 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:35:06.686074018 CET | 1314 | 49362 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:35:07.693423986 CET | 49364 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:35:07.698344946 CET | 1314 | 49364 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:35:07.698419094 CET | 49364 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:35:07.699774027 CET | 49364 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:35:07.704632998 CET | 1314 | 49364 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:35:08.309583902 CET | 1314 | 49364 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:35:08.310002089 CET | 49364 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:35:08.314965963 CET | 1314 | 49364 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:35:10.325186014 CET | 49366 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:35:10.332626104 CET | 1314 | 49366 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:35:10.332734108 CET | 49366 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:35:10.334533930 CET | 49366 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:35:10.340935946 CET | 1314 | 49366 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:35:10.940207005 CET | 1314 | 49366 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:35:10.940640926 CET | 49366 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:35:10.945564032 CET | 1314 | 49366 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:35:13.952295065 CET | 49368 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:35:13.957153082 CET | 1314 | 49368 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:35:13.957216978 CET | 49368 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:35:13.958231926 CET | 49368 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:35:13.963057995 CET | 1314 | 49368 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:35:14.587990046 CET | 1314 | 49368 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:35:14.588315010 CET | 49368 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:35:14.593226910 CET | 1314 | 49368 | 154.213.187.118 | 192.168.2.15 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 11, 2025 14:33:12.983997107 CET | 43524 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:33:12.991223097 CET | 53 | 43524 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:33:18.603840113 CET | 46553 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:33:18.611557961 CET | 53 | 46553 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:33:26.223011971 CET | 37863 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:33:26.230456114 CET | 53 | 37863 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:33:29.845959902 CET | 51707 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:33:29.853636980 CET | 53 | 51707 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:33:36.466473103 CET | 47191 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:33:36.726121902 CET | 53 | 47191 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:33:41.345504045 CET | 55852 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:33:41.532088995 CET | 53 | 55852 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:33:50.152496099 CET | 33834 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:33:50.349303961 CET | 53 | 33834 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:33:58.981708050 CET | 46961 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:33:58.989018917 CET | 53 | 46961 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:34:08.620182991 CET | 33347 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:34:08.627475977 CET | 53 | 33347 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:34:16.260442019 CET | 41461 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:34:16.268199921 CET | 53 | 41461 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:34:23.902266026 CET | 40319 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:34:23.909204960 CET | 53 | 40319 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:34:26.523051977 CET | 58147 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:34:26.530464888 CET | 53 | 58147 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:34:34.144319057 CET | 44405 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:34:34.316905975 CET | 53 | 44405 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:34:37.949697018 CET | 45161 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:34:37.959894896 CET | 53 | 45161 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:34:45.580427885 CET | 33579 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:34:45.587491989 CET | 53 | 33579 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:34:48.192852974 CET | 53748 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:34:48.200048923 CET | 53 | 53748 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:34:49.813302040 CET | 33202 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:34:49.820559978 CET | 53 | 33202 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:34:58.433152914 CET | 54641 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:34:58.440227985 CET | 53 | 54641 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:35:06.072943926 CET | 39375 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:35:06.080137968 CET | 53 | 39375 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:35:07.685117006 CET | 59058 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:35:07.692523003 CET | 53 | 59058 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:35:10.313694954 CET | 43357 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:35:10.324153900 CET | 53 | 43357 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:35:13.944036961 CET | 59668 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:35:13.951380014 CET | 53 | 59668 | 8.8.8.8 | 192.168.2.15 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 11, 2025 14:33:12.983997107 CET | 192.168.2.15 | 8.8.8.8 | 0xb402 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:33:18.603840113 CET | 192.168.2.15 | 8.8.8.8 | 0x5df5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:33:26.223011971 CET | 192.168.2.15 | 8.8.8.8 | 0x177b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:33:29.845959902 CET | 192.168.2.15 | 8.8.8.8 | 0x8468 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:33:36.466473103 CET | 192.168.2.15 | 8.8.8.8 | 0xd75f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:33:41.345504045 CET | 192.168.2.15 | 8.8.8.8 | 0x723f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:33:50.152496099 CET | 192.168.2.15 | 8.8.8.8 | 0xb18e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:33:58.981708050 CET | 192.168.2.15 | 8.8.8.8 | 0xce81 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:34:08.620182991 CET | 192.168.2.15 | 8.8.8.8 | 0xca1b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:34:16.260442019 CET | 192.168.2.15 | 8.8.8.8 | 0xe77f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:34:23.902266026 CET | 192.168.2.15 | 8.8.8.8 | 0x8248 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:34:26.523051977 CET | 192.168.2.15 | 8.8.8.8 | 0x73a5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:34:34.144319057 CET | 192.168.2.15 | 8.8.8.8 | 0xbf6a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:34:37.949697018 CET | 192.168.2.15 | 8.8.8.8 | 0x494e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:34:45.580427885 CET | 192.168.2.15 | 8.8.8.8 | 0xd3ab | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:34:48.192852974 CET | 192.168.2.15 | 8.8.8.8 | 0xbd20 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:34:49.813302040 CET | 192.168.2.15 | 8.8.8.8 | 0x317d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:34:58.433152914 CET | 192.168.2.15 | 8.8.8.8 | 0x3ae4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:35:06.072943926 CET | 192.168.2.15 | 8.8.8.8 | 0xf5ac | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:35:07.685117006 CET | 192.168.2.15 | 8.8.8.8 | 0xe5f9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:35:10.313694954 CET | 192.168.2.15 | 8.8.8.8 | 0x3409 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:35:13.944036961 CET | 192.168.2.15 | 8.8.8.8 | 0x3470 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 11, 2025 14:33:12.991223097 CET | 8.8.8.8 | 192.168.2.15 | 0xb402 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:33:18.611557961 CET | 8.8.8.8 | 192.168.2.15 | 0x5df5 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:33:26.230456114 CET | 8.8.8.8 | 192.168.2.15 | 0x177b | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:33:29.853636980 CET | 8.8.8.8 | 192.168.2.15 | 0x8468 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:33:36.726121902 CET | 8.8.8.8 | 192.168.2.15 | 0xd75f | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:33:41.532088995 CET | 8.8.8.8 | 192.168.2.15 | 0x723f | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:33:50.349303961 CET | 8.8.8.8 | 192.168.2.15 | 0xb18e | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:33:58.989018917 CET | 8.8.8.8 | 192.168.2.15 | 0xce81 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:34:08.627475977 CET | 8.8.8.8 | 192.168.2.15 | 0xca1b | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:34:16.268199921 CET | 8.8.8.8 | 192.168.2.15 | 0xe77f | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:34:23.909204960 CET | 8.8.8.8 | 192.168.2.15 | 0x8248 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:34:26.530464888 CET | 8.8.8.8 | 192.168.2.15 | 0x73a5 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:34:34.316905975 CET | 8.8.8.8 | 192.168.2.15 | 0xbf6a | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:34:37.959894896 CET | 8.8.8.8 | 192.168.2.15 | 0x494e | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:34:45.587491989 CET | 8.8.8.8 | 192.168.2.15 | 0xd3ab | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:34:48.200048923 CET | 8.8.8.8 | 192.168.2.15 | 0xbd20 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:34:49.820559978 CET | 8.8.8.8 | 192.168.2.15 | 0x317d | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:34:58.440227985 CET | 8.8.8.8 | 192.168.2.15 | 0x3ae4 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:35:06.080137968 CET | 8.8.8.8 | 192.168.2.15 | 0xf5ac | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:35:07.692523003 CET | 8.8.8.8 | 192.168.2.15 | 0xe5f9 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:35:10.324153900 CET | 8.8.8.8 | 192.168.2.15 | 0x3409 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:35:13.951380014 CET | 8.8.8.8 | 192.168.2.15 | 0x3470 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 13:33:12 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/arm.elf |
Arguments: | /tmp/arm.elf |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 13:33:12 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/arm.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 13:33:12 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/arm.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 13:33:12 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/arm.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 13:33:12 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/arm.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |