Edit tour
Linux
Analysis Report
ppc.elf
Overview
General Information
Sample name: | ppc.elf |
Analysis ID: | 1589166 |
MD5: | b3d599e248dc77055c2b43756660cbe6 |
SHA1: | 448a8f13491f19ed94a391f5597db1c0e4df4a38 |
SHA256: | 779d005b4a5834d7c5020b5da5ed17332afc12d64fa7ce3e3bf0c39fa8efdda7 |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Mirai, Moobot
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Detected Mirai
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Mirai
Yara detected Moobot
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match
Classification
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1589166 |
Start date and time: | 2025-01-11 14:36:24 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 34s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | ppc.elf |
Detection: | MAL |
Classification: | mal100.troj.evad.linELF@0/0@21/0 |
Command: | /tmp/ppc.elf |
PID: | 5530 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | done. |
Standard Error: |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Mirai | Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world. | No Attribution |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
MooBot | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Moobot | Yara detected Moobot | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Moobot | Yara detected Moobot | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
JoeSecurity_Moobot | Yara detected Moobot | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Click to see the 1 entries |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-11T14:37:20.144464+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49326 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:26.704239+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49328 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:29.340574+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49330 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:37.990228+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49332 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:39.626471+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49334 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:43.894748+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49336 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:50.503260+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49338 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:52.140446+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49340 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:56.788515+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49342 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:38:00.473363+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49344 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:38:11.094959+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49346 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:38:21.727694+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49348 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:38:32.374550+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49350 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:38:41.012926+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49352 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:38:45.622675+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49354 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:38:53.249835+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49356 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:39:00.921303+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49358 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:39:08.550940+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49360 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:39:13.190714+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49362 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:39:17.830656+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49364 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:39:21.461150+0100 | 2030491 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 49366 | 154.213.187.118 | 1314 | TCP |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | TCP traffic: |
Source: | DNS traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | .symtab present: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | 1 File Deletion | 1 OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Non-Standard Port | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
61% | ReversingLabs | Linux.Trojan.Mirai | ||
100% | Avira | EXP/ELF.Mirai.Z.A |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
webhorizon.icu | 154.213.187.118 | true | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
154.213.187.118 | webhorizon.icu | Seychelles | 22769 | DDOSING-BGP-NETWORKUS | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
154.213.187.118 | Get hash | malicious | Mirai, Moobot | Browse | ||
Get hash | malicious | Mirai, Moobot | Browse | |||
Get hash | malicious | Mirai, Moobot | Browse | |||
Get hash | malicious | Mirai, Moobot | Browse | |||
Get hash | malicious | Mirai, Moobot | Browse | |||
Get hash | malicious | Mirai, Moobot | Browse | |||
Get hash | malicious | Mirai, Moobot | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
webhorizon.icu | Get hash | malicious | Mirai, Moobot | Browse |
| |
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
DDOSING-BGP-NETWORKUS | Get hash | malicious | Mirai, Moobot | Browse |
| |
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 6.236003161813702 |
TrID: |
|
File name: | ppc.elf |
File size: | 56'384 bytes |
MD5: | b3d599e248dc77055c2b43756660cbe6 |
SHA1: | 448a8f13491f19ed94a391f5597db1c0e4df4a38 |
SHA256: | 779d005b4a5834d7c5020b5da5ed17332afc12d64fa7ce3e3bf0c39fa8efdda7 |
SHA512: | ec4ddfb0e20107670bdf3a718cc4c2d36ee89125793f7e8a5fd27ff9d7febed63c0f6ede49cfeedc3032f43451376ebad70e0a09c833c614e831c5d2c7a001f6 |
SSDEEP: | 768:JfsrmjuyuRP4R1I0mQC/N4IICBKepcC9NEIs9+m1HVOjvYggGK0FRxtrSEwnkIY:VsIuy80cI6Keacmf+MVyYgg5Ix5Ynk7 |
TLSH: | B2434A02B31C0E47C0A35970263F5BD097BEA5E022E4F685351F9B969A72E371486FCD |
File Content Preview: | .ELF...........................4...`.....4. ...(.......................................................h..%0........dt.Q.............................!..|......$H...H......$8!. |...N.. .!..|.......?..........t..../...@..\?........+../...A..$8...})......N.. |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 55904 |
Section Header Size: | 40 |
Number of Section Headers: | 12 |
Header String Table Index: | 11 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x10000094 | 0x94 | 0x24 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x100000b8 | 0xb8 | 0xbc28 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.fini | PROGBITS | 0x1000bce0 | 0xbce0 | 0x20 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x1000bd00 | 0xbd00 | 0x19a8 | 0x0 | 0x2 | A | 0 | 0 | 8 |
.ctors | PROGBITS | 0x1001d6ac | 0xd6ac | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x1001d6b4 | 0xd6b4 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x1001d6c0 | 0xd6c0 | 0x314 | 0x0 | 0x3 | WA | 0 | 0 | 8 |
.sdata | PROGBITS | 0x1001d9d4 | 0xd9d4 | 0x40 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.sbss | NOBITS | 0x1001da14 | 0xda14 | 0x60 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x1001da74 | 0xda14 | 0x2168 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.shstrtab | STRTAB | 0x0 | 0xda14 | 0x4b | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x10000000 | 0x10000000 | 0xd6a8 | 0xd6a8 | 6.2905 | 0x5 | R E | 0x10000 | .init .text .fini .rodata | |
LOAD | 0xd6ac | 0x1001d6ac | 0x1001d6ac | 0x368 | 0x2530 | 2.8282 | 0x6 | RW | 0x10000 | .ctors .dtors .data .sdata .sbss .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x4 |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-11T14:37:20.144464+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49326 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:26.704239+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49328 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:29.340574+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49330 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:37.990228+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49332 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:39.626471+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49334 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:43.894748+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49336 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:50.503260+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49338 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:52.140446+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49340 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:37:56.788515+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49342 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:38:00.473363+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49344 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:38:11.094959+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49346 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:38:21.727694+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49348 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:38:32.374550+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49350 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:38:41.012926+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49352 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:38:45.622675+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49354 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:38:53.249835+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49356 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:39:00.921303+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49358 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:39:08.550940+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49360 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:39:13.190714+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49362 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:39:17.830656+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49364 | 154.213.187.118 | 1314 | TCP |
2025-01-11T14:39:21.461150+0100 | 2030491 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M2 (Group String Len 2+) | 1 | 192.168.2.15 | 49366 | 154.213.187.118 | 1314 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 11, 2025 14:37:20.071774006 CET | 49326 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:20.076643944 CET | 1314 | 49326 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:20.076706886 CET | 49326 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:20.144464016 CET | 49326 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:20.149369955 CET | 1314 | 49326 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:20.683222055 CET | 1314 | 49326 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:20.683521032 CET | 49326 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:20.688441992 CET | 1314 | 49326 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:26.698184013 CET | 49328 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:26.703165054 CET | 1314 | 49328 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:26.703283072 CET | 49328 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:26.704238892 CET | 49328 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:26.709168911 CET | 1314 | 49328 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:27.324722052 CET | 1314 | 49328 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:27.325026035 CET | 49328 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:27.329883099 CET | 1314 | 49328 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:29.334644079 CET | 49330 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:29.339472055 CET | 1314 | 49330 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:29.339524031 CET | 49330 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:29.340574026 CET | 49330 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:29.345335960 CET | 1314 | 49330 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:29.973100901 CET | 1314 | 49330 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:29.973387957 CET | 49330 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:29.978311062 CET | 1314 | 49330 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:37.984225035 CET | 49332 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:37.989126921 CET | 1314 | 49332 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:37.989232063 CET | 49332 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:37.990227938 CET | 49332 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:37.995058060 CET | 1314 | 49332 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:38.609203100 CET | 1314 | 49332 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:38.609500885 CET | 49332 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:38.614435911 CET | 1314 | 49332 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:39.620393038 CET | 49334 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:39.625315905 CET | 1314 | 49334 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:39.625397921 CET | 49334 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:39.626471043 CET | 49334 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:39.631282091 CET | 1314 | 49334 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:40.233290911 CET | 1314 | 49334 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:40.233583927 CET | 49334 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:40.238497972 CET | 1314 | 49334 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:43.889040947 CET | 49336 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:43.893873930 CET | 1314 | 49336 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:43.893928051 CET | 49336 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:43.894747972 CET | 49336 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:43.899544001 CET | 1314 | 49336 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:44.486515045 CET | 1314 | 49336 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:44.486712933 CET | 49336 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:44.491687059 CET | 1314 | 49336 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:50.497199059 CET | 49338 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:50.502137899 CET | 1314 | 49338 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:50.502209902 CET | 49338 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:50.503259897 CET | 49338 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:50.508121014 CET | 1314 | 49338 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:51.122910976 CET | 1314 | 49338 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:51.123188972 CET | 49338 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:51.128129959 CET | 1314 | 49338 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:52.133912086 CET | 49340 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:52.139131069 CET | 1314 | 49340 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:52.139219999 CET | 49340 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:52.140445948 CET | 49340 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:52.145550013 CET | 1314 | 49340 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:52.770495892 CET | 1314 | 49340 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:52.770616055 CET | 49340 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:52.775578022 CET | 1314 | 49340 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:56.782438040 CET | 49342 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:56.787343025 CET | 1314 | 49342 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:56.787425995 CET | 49342 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:56.788515091 CET | 49342 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:56.793330908 CET | 1314 | 49342 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:57.456350088 CET | 1314 | 49342 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:37:57.456681013 CET | 49342 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:37:57.461585999 CET | 1314 | 49342 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:38:00.467171907 CET | 49344 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:00.472193956 CET | 1314 | 49344 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:38:00.472279072 CET | 49344 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:00.473362923 CET | 49344 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:00.478176117 CET | 1314 | 49344 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:38:01.076854944 CET | 1314 | 49344 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:38:01.077092886 CET | 49344 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:01.077142000 CET | 49344 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:01.082298040 CET | 1314 | 49344 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:38:11.088641882 CET | 49346 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:11.093595028 CET | 1314 | 49346 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:38:11.093684912 CET | 49346 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:11.094959021 CET | 49346 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:11.099818945 CET | 1314 | 49346 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:38:11.708081961 CET | 1314 | 49346 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:38:11.708565950 CET | 49346 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:11.713563919 CET | 1314 | 49346 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:38:21.721528053 CET | 49348 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:21.726394892 CET | 1314 | 49348 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:38:21.726481915 CET | 49348 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:21.727694035 CET | 49348 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:21.732546091 CET | 1314 | 49348 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:38:22.357040882 CET | 1314 | 49348 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:38:22.357491016 CET | 49348 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:22.362406015 CET | 1314 | 49348 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:38:32.368401051 CET | 49350 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:32.373295069 CET | 1314 | 49350 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:38:32.373399019 CET | 49350 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:32.374550104 CET | 49350 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:32.379371881 CET | 1314 | 49350 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:38:32.994812012 CET | 1314 | 49350 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:38:32.995089054 CET | 49350 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:33.000303030 CET | 1314 | 49350 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:38:41.006342888 CET | 49352 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:41.011820078 CET | 1314 | 49352 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:38:41.011894941 CET | 49352 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:41.012926102 CET | 49352 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:41.017762899 CET | 1314 | 49352 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:38:41.606625080 CET | 1314 | 49352 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:38:41.606908083 CET | 49352 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:41.611826897 CET | 1314 | 49352 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:38:45.616902113 CET | 49354 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:45.621723890 CET | 1314 | 49354 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:38:45.621794939 CET | 49354 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:45.622674942 CET | 49354 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:45.627440929 CET | 1314 | 49354 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:38:46.232922077 CET | 1314 | 49354 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:38:46.233125925 CET | 49354 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:46.238086939 CET | 1314 | 49354 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:38:53.243833065 CET | 49356 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:53.248760939 CET | 1314 | 49356 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:38:53.248871088 CET | 49356 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:53.249835014 CET | 49356 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:53.254667997 CET | 1314 | 49356 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:38:53.902228117 CET | 1314 | 49356 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:38:53.902499914 CET | 49356 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:38:53.907361031 CET | 1314 | 49356 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:39:00.914891005 CET | 49358 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:39:00.919878960 CET | 1314 | 49358 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:39:00.919990063 CET | 49358 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:39:00.921303034 CET | 49358 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:39:00.926151991 CET | 1314 | 49358 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:39:01.531404972 CET | 1314 | 49358 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:39:01.531711102 CET | 49358 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:39:01.536672115 CET | 1314 | 49358 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:39:08.544578075 CET | 49360 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:39:08.549509048 CET | 1314 | 49360 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:39:08.549592972 CET | 49360 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:39:08.550940037 CET | 49360 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:39:08.555809975 CET | 1314 | 49360 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:39:09.171919107 CET | 1314 | 49360 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:39:09.172346115 CET | 49360 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:39:09.177390099 CET | 1314 | 49360 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:39:13.184186935 CET | 49362 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:39:13.189105034 CET | 1314 | 49362 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:39:13.189177990 CET | 49362 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:39:13.190713882 CET | 49362 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:39:13.195549965 CET | 1314 | 49362 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:39:13.811981916 CET | 1314 | 49362 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:39:13.812437057 CET | 49362 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:39:13.817452908 CET | 1314 | 49362 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:39:17.824249029 CET | 49364 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:39:17.829185963 CET | 1314 | 49364 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:39:17.829307079 CET | 49364 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:39:17.830656052 CET | 49364 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:39:17.835570097 CET | 1314 | 49364 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:39:18.444502115 CET | 1314 | 49364 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:39:18.444684982 CET | 49364 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:39:18.449598074 CET | 1314 | 49364 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:39:21.454878092 CET | 49366 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:39:21.459747076 CET | 1314 | 49366 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:39:21.459878922 CET | 49366 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:39:21.461149931 CET | 49366 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:39:21.465975046 CET | 1314 | 49366 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:39:22.063462019 CET | 1314 | 49366 | 154.213.187.118 | 192.168.2.15 |
Jan 11, 2025 14:39:22.063739061 CET | 49366 | 1314 | 192.168.2.15 | 154.213.187.118 |
Jan 11, 2025 14:39:22.068603992 CET | 1314 | 49366 | 154.213.187.118 | 192.168.2.15 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 11, 2025 14:37:20.063010931 CET | 33211 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:37:20.070044041 CET | 53 | 33211 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:37:26.689985991 CET | 52385 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:37:26.697346926 CET | 53 | 52385 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:37:29.327631950 CET | 55839 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:37:29.334098101 CET | 53 | 55839 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:37:37.976552963 CET | 53117 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:37:37.983664036 CET | 53 | 53117 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:37:39.612909079 CET | 47436 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:37:39.619802952 CET | 53 | 47436 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:37:43.236082077 CET | 51041 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:37:43.888150930 CET | 53 | 51041 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:37:50.489368916 CET | 46005 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:37:50.496637106 CET | 53 | 46005 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:37:52.126135111 CET | 54754 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:37:52.133254051 CET | 53 | 54754 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:37:56.773171902 CET | 45660 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:37:56.781805038 CET | 53 | 45660 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:38:00.459737062 CET | 33047 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:38:00.466514111 CET | 53 | 33047 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:38:11.080262899 CET | 49205 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:38:11.087889910 CET | 53 | 49205 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:38:21.712114096 CET | 36155 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:38:21.720881939 CET | 53 | 36155 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:38:32.360654116 CET | 34144 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:38:32.367649078 CET | 53 | 34144 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:38:40.998327971 CET | 39415 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:38:41.005542040 CET | 53 | 39415 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:38:45.609468937 CET | 59437 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:38:45.616348982 CET | 53 | 59437 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:38:53.236015081 CET | 48214 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:38:53.243232012 CET | 53 | 48214 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:39:00.906372070 CET | 54723 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:39:00.914084911 CET | 53 | 54723 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:39:08.536173105 CET | 33257 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:39:08.543513060 CET | 53 | 33257 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:39:13.176162004 CET | 41727 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:39:13.183348894 CET | 53 | 41727 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:39:17.816025972 CET | 43842 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:39:17.823520899 CET | 53 | 43842 | 8.8.8.8 | 192.168.2.15 |
Jan 11, 2025 14:39:21.447763920 CET | 55773 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 11, 2025 14:39:21.454197884 CET | 53 | 55773 | 8.8.8.8 | 192.168.2.15 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 11, 2025 14:37:20.063010931 CET | 192.168.2.15 | 8.8.8.8 | 0xd547 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:37:26.689985991 CET | 192.168.2.15 | 8.8.8.8 | 0xe28b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:37:29.327631950 CET | 192.168.2.15 | 8.8.8.8 | 0x52e6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:37:37.976552963 CET | 192.168.2.15 | 8.8.8.8 | 0x4799 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:37:39.612909079 CET | 192.168.2.15 | 8.8.8.8 | 0x2052 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:37:43.236082077 CET | 192.168.2.15 | 8.8.8.8 | 0x7b47 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:37:50.489368916 CET | 192.168.2.15 | 8.8.8.8 | 0x1043 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:37:52.126135111 CET | 192.168.2.15 | 8.8.8.8 | 0x9cba | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:37:56.773171902 CET | 192.168.2.15 | 8.8.8.8 | 0xa940 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:38:00.459737062 CET | 192.168.2.15 | 8.8.8.8 | 0x4c0c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:38:11.080262899 CET | 192.168.2.15 | 8.8.8.8 | 0x534f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:38:21.712114096 CET | 192.168.2.15 | 8.8.8.8 | 0x4992 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:38:32.360654116 CET | 192.168.2.15 | 8.8.8.8 | 0x432d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:38:40.998327971 CET | 192.168.2.15 | 8.8.8.8 | 0x954b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:38:45.609468937 CET | 192.168.2.15 | 8.8.8.8 | 0x3680 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:38:53.236015081 CET | 192.168.2.15 | 8.8.8.8 | 0x8f0d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:39:00.906372070 CET | 192.168.2.15 | 8.8.8.8 | 0x95f3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:39:08.536173105 CET | 192.168.2.15 | 8.8.8.8 | 0x901f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:39:13.176162004 CET | 192.168.2.15 | 8.8.8.8 | 0xac2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:39:17.816025972 CET | 192.168.2.15 | 8.8.8.8 | 0x912b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 14:39:21.447763920 CET | 192.168.2.15 | 8.8.8.8 | 0x301b | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 11, 2025 14:37:20.070044041 CET | 8.8.8.8 | 192.168.2.15 | 0xd547 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:37:26.697346926 CET | 8.8.8.8 | 192.168.2.15 | 0xe28b | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:37:29.334098101 CET | 8.8.8.8 | 192.168.2.15 | 0x52e6 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:37:37.983664036 CET | 8.8.8.8 | 192.168.2.15 | 0x4799 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:37:39.619802952 CET | 8.8.8.8 | 192.168.2.15 | 0x2052 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:37:43.888150930 CET | 8.8.8.8 | 192.168.2.15 | 0x7b47 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:37:50.496637106 CET | 8.8.8.8 | 192.168.2.15 | 0x1043 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:37:52.133254051 CET | 8.8.8.8 | 192.168.2.15 | 0x9cba | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:37:56.781805038 CET | 8.8.8.8 | 192.168.2.15 | 0xa940 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:38:00.466514111 CET | 8.8.8.8 | 192.168.2.15 | 0x4c0c | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:38:11.087889910 CET | 8.8.8.8 | 192.168.2.15 | 0x534f | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:38:21.720881939 CET | 8.8.8.8 | 192.168.2.15 | 0x4992 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:38:32.367649078 CET | 8.8.8.8 | 192.168.2.15 | 0x432d | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:38:41.005542040 CET | 8.8.8.8 | 192.168.2.15 | 0x954b | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:38:45.616348982 CET | 8.8.8.8 | 192.168.2.15 | 0x3680 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:38:53.243232012 CET | 8.8.8.8 | 192.168.2.15 | 0x8f0d | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:39:00.914084911 CET | 8.8.8.8 | 192.168.2.15 | 0x95f3 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:39:08.543513060 CET | 8.8.8.8 | 192.168.2.15 | 0x901f | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:39:13.183348894 CET | 8.8.8.8 | 192.168.2.15 | 0xac2 | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:39:17.823520899 CET | 8.8.8.8 | 192.168.2.15 | 0x912b | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 14:39:21.454197884 CET | 8.8.8.8 | 192.168.2.15 | 0x301b | No error (0) | 154.213.187.118 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 13:37:19 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/ppc.elf |
Arguments: | /tmp/ppc.elf |
File size: | 5388968 bytes |
MD5 hash: | ae65271c943d3451b7f026d1fadccea6 |
Start time (UTC): | 13:37:19 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/ppc.elf |
Arguments: | - |
File size: | 5388968 bytes |
MD5 hash: | ae65271c943d3451b7f026d1fadccea6 |
Start time (UTC): | 13:37:19 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/ppc.elf |
Arguments: | - |
File size: | 5388968 bytes |
MD5 hash: | ae65271c943d3451b7f026d1fadccea6 |
Start time (UTC): | 13:37:19 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/ppc.elf |
Arguments: | - |
File size: | 5388968 bytes |
MD5 hash: | ae65271c943d3451b7f026d1fadccea6 |
Start time (UTC): | 13:37:19 |
Start date (UTC): | 11/01/2025 |
Path: | /tmp/ppc.elf |
Arguments: | - |
File size: | 5388968 bytes |
MD5 hash: | ae65271c943d3451b7f026d1fadccea6 |