Edit tour
Linux
Analysis Report
sh4.elf
Overview
General Information
Detection
Mirai, Moobot
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Detected Mirai
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Mirai
Yara detected Moobot
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match
Classification
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1589164 |
Start date and time: | 2025-01-11 14:34:36 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 38s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | sh4.elf |
Detection: | MAL |
Classification: | mal100.troj.evad.linELF@0/0@21/0 |
Command: | /tmp/sh4.elf |
PID: | 5510 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | done. |
Standard Error: |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Mirai | Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world. | No Attribution |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
MooBot | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Moobot | Yara detected Moobot | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Moobot | Yara detected Moobot | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
JoeSecurity_Moobot | Yara detected Moobot | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Click to see the 1 entries |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-11T14:35:31.961360+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35340 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:35:36.580907+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35342 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:35:43.199009+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35344 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:35:46.852974+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35346 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:35:52.472778+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35348 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:35:57.119534+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35350 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:36:07.735696+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35352 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:36:13.344848+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35354 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:36:22.964428+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35356 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:36:30.611135+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35358 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:36:40.240133+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35360 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:36:49.888387+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35362 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:36:56.511667+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35364 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:03.155203+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35366 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:05.780103+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35368 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:07.420224+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35370 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:12.059999+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35372 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:14.689376+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35374 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:22.312355+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35376 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:28.945736+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35378 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:34.654746+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.14 | 35380 | 154.213.187.118 | 1314 | TCP |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | TCP traffic: |
Source: | DNS traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | .symtab present: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | 1 File Deletion | 1 OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Non-Standard Port | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
60% | Virustotal | Browse | ||
58% | ReversingLabs | Linux.Trojan.Mirai | ||
100% | Avira | EXP/ELF.Mirai.Z.A |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
webhorizon.icu | 154.213.187.118 | true | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
154.213.187.118 | webhorizon.icu | Seychelles | 22769 | DDOSING-BGP-NETWORKUS | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
154.213.187.118 | Get hash | malicious | Mirai, Moobot | Browse | ||
Get hash | malicious | Mirai, Moobot | Browse | |||
Get hash | malicious | Mirai, Moobot | Browse | |||
Get hash | malicious | Mirai, Moobot | Browse | |||
Get hash | malicious | Mirai, Moobot | Browse | |||
Get hash | malicious | Mirai, Moobot | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
webhorizon.icu | Get hash | malicious | Mirai, Moobot | Browse |
| |
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
DDOSING-BGP-NETWORKUS | Get hash | malicious | Mirai, Moobot | Browse |
| |
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 6.835229488394901 |
TrID: |
|
File name: | sh4.elf |
File size: | 51'796 bytes |
MD5: | e96aafc35c6092d55a3fdaf07f0879a2 |
SHA1: | 6e689389acd78e70cc749acbc99f91932226c69f |
SHA256: | 7373f03e5841bfe3f7f7afb768b280235ccb2d369ba2da322bfab5b38f15b03f |
SHA512: | 3675ad0c368748d58ca2683da578ad298bb79a9f54b1ff189291c4987bd7cf6311369696859c25524a196d277b22b610fe23d977df567e2a83642d612e1b9cb6 |
SSDEEP: | 768:qIap1jeOYyLmAfxthLr5uhKeSR//CHIDLKX54KafzozVZuVCAa8RWfgJBdwnwI8:PaLj3/L/fxzEY3LKX549MzOVCAhJsnw |
TLSH: | AE338D66E81A6E18C0560170B9648F741F63F0C4934B2EFB19E9C2B95493EACF519FF8 |
File Content Preview: | .ELF..............*.......@.4...........4. ...(...............@...@..................... ... .A. .A.d...8%..........Q.td............................././"O.n........#.*@........#.*@.....o&O.n...l..............................././.../.a"O.!...n...a.b("...q. |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 51396 |
Section Header Size: | 40 |
Number of Section Headers: | 10 |
Header String Table Index: | 9 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x400094 | 0x94 | 0x30 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x4000e0 | 0xe0 | 0xaaa0 | 0x0 | 0x6 | AX | 0 | 0 | 32 |
.fini | PROGBITS | 0x40ab80 | 0xab80 | 0x24 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x40aba4 | 0xaba4 | 0x1978 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ctors | PROGBITS | 0x41c520 | 0xc520 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x41c528 | 0xc528 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x41c534 | 0xc534 | 0x350 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x41c884 | 0xc884 | 0x21d4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.shstrtab | STRTAB | 0x0 | 0xc884 | 0x3e | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x400000 | 0x400000 | 0xc51c | 0xc51c | 6.8941 | 0x5 | R E | 0x10000 | .init .text .fini .rodata | |
LOAD | 0xc520 | 0x41c520 | 0x41c520 | 0x364 | 0x2538 | 2.7186 | 0x6 | RW | 0x10000 | .ctors .dtors .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-11T14:35:31.961360+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35340 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:35:36.580907+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35342 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:35:43.199009+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35344 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:35:46.852974+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35346 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:35:52.472778+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35348 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:35:57.119534+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35350 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:36:07.735696+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35352 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:36:13.344848+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35354 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:36:22.964428+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35356 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:36:30.611135+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35358 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:36:40.240133+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35360 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:36:49.888387+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35362 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:36:56.511667+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35364 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:03.155203+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35366 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:05.780103+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35368 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:07.420224+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35370 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:12.059999+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35372 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:14.689376+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35374 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:22.312355+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35376 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:28.945736+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35378 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:34.654746+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.14 | 35380 | 154.213.187.118 | 1314 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 11, 2025 14:35:31.948781013 CET | 35340 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:35:31.953722000 CET | 1314 | 35340 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:35:31.953792095 CET | 35340 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:35:31.961359978 CET | 35340 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:35:31.966259003 CET | 1314 | 35340 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:35:32.563252926 CET | 1314 | 35340 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:35:32.563565016 CET | 35340 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:35:32.568447113 CET | 1314 | 35340 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:35:36.574668884 CET | 35342 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:35:36.580277920 CET | 1314 | 35342 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:35:36.580337048 CET | 35342 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:35:36.580907106 CET | 35342 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:35:36.585680962 CET | 1314 | 35342 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:35:37.180454969 CET | 1314 | 35342 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:35:37.180665016 CET | 35342 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:35:37.185581923 CET | 1314 | 35342 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:35:43.193295002 CET | 35344 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:35:43.198086023 CET | 1314 | 35344 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:35:43.198142052 CET | 35344 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:35:43.199008942 CET | 35344 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:35:43.203823090 CET | 1314 | 35344 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:35:43.837937117 CET | 1314 | 35344 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:35:43.838180065 CET | 35344 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:35:43.843024969 CET | 1314 | 35344 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:35:46.847384930 CET | 35346 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:35:46.852257967 CET | 1314 | 35346 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:35:46.852332115 CET | 35346 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:35:46.852973938 CET | 35346 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:35:46.857791901 CET | 1314 | 35346 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:35:47.455552101 CET | 1314 | 35346 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:35:47.455881119 CET | 35346 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:35:47.461968899 CET | 1314 | 35346 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:35:52.466648102 CET | 35348 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:35:52.471621037 CET | 1314 | 35348 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:35:52.471683025 CET | 35348 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:35:52.472778082 CET | 35348 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:35:52.477653980 CET | 1314 | 35348 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:35:53.101459026 CET | 1314 | 35348 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:35:53.101761103 CET | 35348 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:35:53.106565952 CET | 1314 | 35348 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:35:57.111979961 CET | 35350 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:35:57.118716002 CET | 1314 | 35350 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:35:57.118818045 CET | 35350 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:35:57.119534016 CET | 35350 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:35:57.125511885 CET | 1314 | 35350 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:35:57.718980074 CET | 1314 | 35350 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:35:57.719392061 CET | 35350 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:35:57.724312067 CET | 1314 | 35350 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:36:07.728807926 CET | 35352 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:36:07.734791994 CET | 1314 | 35352 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:36:07.734860897 CET | 35352 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:36:07.735696077 CET | 35352 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:36:07.740564108 CET | 1314 | 35352 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:36:08.329767942 CET | 1314 | 35352 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:36:08.330321074 CET | 35352 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:36:08.335269928 CET | 1314 | 35352 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:36:13.339293003 CET | 35354 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:36:13.344229937 CET | 1314 | 35354 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:36:13.344379902 CET | 35354 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:36:13.344847918 CET | 35354 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:36:13.349649906 CET | 1314 | 35354 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:36:13.942714930 CET | 1314 | 35354 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:36:13.943166971 CET | 35354 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:36:13.948077917 CET | 1314 | 35354 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:36:22.955635071 CET | 35356 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:36:22.962260962 CET | 1314 | 35356 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:36:22.962342978 CET | 35356 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:36:22.964427948 CET | 35356 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:36:22.971182108 CET | 1314 | 35356 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:36:23.595060110 CET | 1314 | 35356 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:36:23.595505953 CET | 35356 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:36:23.600425959 CET | 1314 | 35356 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:36:30.605438948 CET | 35358 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:36:30.610318899 CET | 1314 | 35358 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:36:30.610390902 CET | 35358 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:36:30.611135006 CET | 35358 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:36:30.615926981 CET | 1314 | 35358 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:36:31.224200010 CET | 1314 | 35358 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:36:31.224489927 CET | 35358 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:36:31.229406118 CET | 1314 | 35358 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:36:40.234392881 CET | 35360 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:36:40.239276886 CET | 1314 | 35360 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:36:40.239373922 CET | 35360 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:36:40.240133047 CET | 35360 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:36:40.245019913 CET | 1314 | 35360 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:36:40.870270014 CET | 1314 | 35360 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:36:40.870640039 CET | 35360 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:36:40.875508070 CET | 1314 | 35360 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:36:49.882303953 CET | 35362 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:36:49.887238026 CET | 1314 | 35362 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:36:49.887322903 CET | 35362 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:36:49.888386965 CET | 35362 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:36:49.893630981 CET | 1314 | 35362 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:36:50.490061998 CET | 1314 | 35362 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:36:50.490437984 CET | 35362 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:36:50.495249987 CET | 1314 | 35362 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:36:56.503789902 CET | 35364 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:36:56.510859013 CET | 1314 | 35364 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:36:56.511070967 CET | 35364 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:36:56.511667013 CET | 35364 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:36:56.520988941 CET | 1314 | 35364 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:36:57.136831045 CET | 1314 | 35364 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:36:57.137161970 CET | 35364 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:36:57.142132044 CET | 1314 | 35364 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:03.148793936 CET | 35366 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:03.153852940 CET | 1314 | 35366 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:03.153933048 CET | 35366 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:03.155203104 CET | 35366 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:03.160074949 CET | 1314 | 35366 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:03.757961035 CET | 1314 | 35366 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:03.758230925 CET | 35366 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:03.763086081 CET | 1314 | 35366 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:05.769264936 CET | 35368 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:05.778690100 CET | 1314 | 35368 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:05.778800964 CET | 35368 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:05.780102968 CET | 35368 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:05.784876108 CET | 1314 | 35368 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:06.402537107 CET | 1314 | 35368 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:06.403201103 CET | 35368 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:06.408097029 CET | 1314 | 35368 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:07.414407015 CET | 35370 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:07.419352055 CET | 1314 | 35370 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:07.419418097 CET | 35370 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:07.420223951 CET | 35370 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:07.425035954 CET | 1314 | 35370 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:08.040343046 CET | 1314 | 35370 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:08.040626049 CET | 35370 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:08.045499086 CET | 1314 | 35370 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:12.053653002 CET | 35372 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:12.058578968 CET | 1314 | 35372 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:12.058661938 CET | 35372 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:12.059998989 CET | 35372 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:12.064867020 CET | 1314 | 35372 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:12.670722961 CET | 1314 | 35372 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:12.670972109 CET | 35372 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:12.675878048 CET | 1314 | 35372 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:14.682776928 CET | 35374 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:14.688200951 CET | 1314 | 35374 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:14.688345909 CET | 35374 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:14.689376116 CET | 35374 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:14.694555998 CET | 1314 | 35374 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:15.295388937 CET | 1314 | 35374 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:15.295515060 CET | 35374 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:15.300631046 CET | 1314 | 35374 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:22.306546926 CET | 35376 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:22.311358929 CET | 1314 | 35376 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:22.311436892 CET | 35376 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:22.312355042 CET | 35376 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:22.317138910 CET | 1314 | 35376 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:22.928112984 CET | 1314 | 35376 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:22.928319931 CET | 35376 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:22.933130980 CET | 1314 | 35376 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:28.939481020 CET | 35378 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:28.944370031 CET | 1314 | 35378 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:28.944524050 CET | 35378 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:28.945735931 CET | 35378 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:28.950469971 CET | 1314 | 35378 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:29.636012077 CET | 1314 | 35378 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:29.636430025 CET | 35378 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:29.641304970 CET | 1314 | 35378 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:34.648252964 CET | 35380 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:34.653275013 CET | 1314 | 35380 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:34.653461933 CET | 35380 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:34.654746056 CET | 35380 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:34.659615040 CET | 1314 | 35380 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:35.259673119 CET | 1314 | 35380 | 154.213.187.118 | 192.168.2.14 |
Jan 11, 2025 14:37:35.259923935 CET | 35380 | 1314 | 192.168.2.14 | 154.213.187.118 |
Jan 11, 2025 14:37:35.264810085 CET | 1314 | 35380 | 154.213.187.118 | 192.168.2.14 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 11, 2025 14:35:31.935192108 CET | 33345 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:35:31.942370892 CET | 53 | 33345 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:35:36.566879988 CET | 47553 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:35:36.574259996 CET | 53 | 47553 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:35:43.182403088 CET | 44828 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:35:43.192728996 CET | 53 | 44828 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:35:46.839849949 CET | 60344 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:35:46.847029924 CET | 53 | 60344 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:35:52.458425045 CET | 44925 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:35:52.466031075 CET | 53 | 44925 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:35:57.103904009 CET | 41318 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:35:57.111346006 CET | 53 | 41318 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:36:07.720966101 CET | 34175 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:36:07.728163004 CET | 53 | 34175 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:36:13.331721067 CET | 38899 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:36:13.338638067 CET | 53 | 38899 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:36:22.946063995 CET | 49798 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:36:22.954870939 CET | 53 | 49798 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:36:30.597470045 CET | 58978 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:36:30.604836941 CET | 53 | 58978 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:36:40.226635933 CET | 38426 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:36:40.233839989 CET | 53 | 38426 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:36:49.874506950 CET | 46566 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:36:49.881719112 CET | 53 | 46566 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:36:56.492189884 CET | 54706 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:36:56.503216982 CET | 53 | 54706 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:37:03.140463114 CET | 47083 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:37:03.147994041 CET | 53 | 47083 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:37:05.761117935 CET | 33863 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:37:05.768507004 CET | 53 | 33863 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:37:07.406563997 CET | 39525 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:37:07.413889885 CET | 53 | 39525 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:37:12.043967962 CET | 59722 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:37:12.051507950 CET | 53 | 59722 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:37:14.674379110 CET | 50337 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:37:14.681870937 CET | 53 | 50337 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:37:22.298444033 CET | 42144 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:37:22.305850983 CET | 53 | 42144 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:37:28.932192087 CET | 57773 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:37:28.938663960 CET | 53 | 57773 | 8.8.8.8 | 192.168.2.14 |
Jan 11, 2025 14:37:34.640110970 CET | 36400 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 11, 2025 14:37:34.647562027 CET | 53 | 36400 | 8.8.8.8 | 192.168.2.14 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 11, 2025 14:35:31.935192108 CET | 192.168.2.14 | 8.8.8.8 | 0xb575 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:35:36.566879988 CET | 192.168.2.14 | 8.8.8.8 | 0x1d84 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:35:43.182403088 CET | 192.168.2.14 | 8.8.8.8 | 0xb824 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:35:46.839849949 CET | 192.168.2.14 | 8.8.8.8 | 0xa5aa | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:35:52.458425045 CET | 192.168.2.14 | 8.8.8.8 | 0x7ec7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:35:57.103904009 CET | 192.168.2.14 | 8.8.8.8 | 0x1a52 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:36:07.720966101 CET | 192.168.2.14 | 8.8.8.8 | 0xb86f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:36:13.331721067 CET | 192.168.2.14 | 8.8.8.8 | 0xda4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:36:22.946063995 CET | 192.168.2.14 | 8.8.8.8 | 0x30c4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:36:30.597470045 CET | 192.168.2.14 | 8.8.8.8 | 0xe287 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:36:40.226635933 CET | 192.168.2.14 | 8.8.8.8 | 0x6900 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:36:49.874506950 CET | 192.168.2.14 | 8.8.8.8 | 0x2d93 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:36:56.492189884 CET | 192.168.2.14 | 8.8.8.8 | 0x1bb | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:37:03.140463114 CET | 192.168.2.14 | 8.8.8.8 | 0x7129 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:37:05.761117935 CET | 192.168.2.14 | 8.8.8.8 | 0xbc4b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:37:07.406563997 CET | 192.168.2.14 | 8.8.8.8 | 0x9fa3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:37:12.043967962 CET | 192.168.2.14 | 8.8.8.8 | 0xd968 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:37:14.674379110 CET | 192.168.2.14 | 8.8.8.8 | 0xf6fe | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:37:22.298444033 CET | 192.168.2.14 | 8.8.8.8 | 0x5bb2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:37:28.932192087 CET | 192.168.2.14 | 8.8.8.8 | 0x1824 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:37:34.640110970 CET | 192.168.2.14 | 8.8.8.8 | 0x93a3 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 11, 2025 14:35:31.942370892 CET | 8.8.8.8 | 192.168.2.14 | 0xb575 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:35:36.574259996 CET | 8.8.8.8 | 192.168.2.14 | 0x1d84 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:35:43.192728996 CET | 8.8.8.8 | 192.168.2.14 | 0xb824 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:35:46.847029924 CET | 8.8.8.8 | 192.168.2.14 | 0xa5aa | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:35:52.466031075 CET | 8.8.8.8 | 192.168.2.14 | 0x7ec7 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:35:57.111346006 CET | 8.8.8.8 | 192.168.2.14 | 0x1a52 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:36:07.728163004 CET | 8.8.8.8 | 192.168.2.14 | 0xb86f | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:36:13.338638067 CET | 8.8.8.8 | 192.168.2.14 | 0xda4 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:36:22.954870939 CET | 8.8.8.8 | 192.168.2.14 | 0x30c4 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:36:30.604836941 CET | 8.8.8.8 | 192.168.2.14 | 0xe287 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:36:40.233839989 CET | 8.8.8.8 | 192.168.2.14 | 0x6900 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:36:49.881719112 CET | 8.8.8.8 | 192.168.2.14 | 0x2d93 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:36:56.503216982 CET | 8.8.8.8 | 192.168.2.14 | 0x1bb | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:37:03.147994041 CET | 8.8.8.8 | 192.168.2.14 | 0x7129 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:37:05.768507004 CET | 8.8.8.8 | 192.168.2.14 | 0xbc4b | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:37:07.413889885 CET | 8.8.8.8 | 192.168.2.14 | 0x9fa3 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:37:12.051507950 CET | 8.8.8.8 | 192.168.2.14 | 0xd968 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:37:14.681870937 CET | 8.8.8.8 | 192.168.2.14 | 0xf6fe | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:37:22.305850983 CET | 8.8.8.8 | 192.168.2.14 | 0x5bb2 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:37:28.938663960 CET | 8.8.8.8 | 192.168.2.14 | 0x1824 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:37:34.647562027 CET | 8.8.8.8 | 192.168.2.14 | 0x93a3 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 13:35:31 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/sh4.elf |
Arguments: | /tmp/sh4.elf |
File size: | 4139976 bytes |
MD5 hash: | 8943e5f8f8c280467b4472c15ae93ba9 |
Start time (UTC): | 13:35:31 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/sh4.elf |
Arguments: | - |
File size: | 4139976 bytes |
MD5 hash: | 8943e5f8f8c280467b4472c15ae93ba9 |
Start time (UTC): | 13:35:31 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/sh4.elf |
Arguments: | - |
File size: | 4139976 bytes |
MD5 hash: | 8943e5f8f8c280467b4472c15ae93ba9 |
Start time (UTC): | 13:35:31 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/sh4.elf |
Arguments: | - |
File size: | 4139976 bytes |
MD5 hash: | 8943e5f8f8c280467b4472c15ae93ba9 |
Start time (UTC): | 13:35:31 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/sh4.elf |
Arguments: | - |
File size: | 4139976 bytes |
MD5 hash: | 8943e5f8f8c280467b4472c15ae93ba9 |