Linux
Analysis Report
boatnet.mpsl.elf
Overview
General Information
Detection
Score: | 88 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Classification
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1589460 |
Start date and time: | 2025-01-12 15:48:11 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 24s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | boatnet.mpsl.elf |
Detection: | MAL |
Classification: | mal88.spre.troj.evad.linELF@0/0@2/0 |
Command: | /tmp/boatnet.mpsl.elf |
PID: | 5840 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | lzrd cock fest"/proc/"/exe |
Standard Error: |
- system is lnxubuntu20
- boatnet.mpsl.elf New Fork (PID: 5842, Parent: 5840)
- boatnet.mpsl.elf New Fork (PID: 5844, Parent: 5840)
- boatnet.mpsl.elf New Fork (PID: 5846, Parent: 5840)
- xfce4-panel New Fork (PID: 5852, Parent: 3235)
- xfce4-panel New Fork (PID: 5853, Parent: 3235)
- xfce4-panel New Fork (PID: 5854, Parent: 3235)
- wrapper-2.0 New Fork (PID: 5876, Parent: 5854)
- xfce4-panel New Fork (PID: 5855, Parent: 3235)
- xfce4-panel New Fork (PID: 5856, Parent: 3235)
- xfce4-panel New Fork (PID: 5857, Parent: 3235)
- dbus-daemon New Fork (PID: 5875, Parent: 5874)
- systemd New Fork (PID: 5884, Parent: 3044)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Mirai | Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Mirai_5 | Yara detected Mirai | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
Linux_Trojan_Gafgyt_ea92cca8 | unknown | unknown |
| |
Mirai_Botnet_Malware | Detects Mirai Botnet Malware | Florian Roth |
| |
Click to see the 22 entries |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior |
Source: | Program segment: |
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Data Obfuscation |
---|
Source: | String containing UPX found: | ||
Source: | String containing UPX found: | ||
Source: | String containing UPX found: |
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior | ||
Source: | Directory: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Submission file: |
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | 1 Hidden Files and Directories | 1 OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Non-Standard Port | Exfiltration Over Other Network Medium | 1 Service Stop |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 11 Obfuscated Files or Information | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
42% | Virustotal | Browse | ||
55% | ReversingLabs | Linux.Trojan.Mirai | ||
100% | Avira | EXP/ELF.Agent.M.28 |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
daisy.ubuntu.com | 162.213.35.24 | true | false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
94.158.245.27 | unknown | Moldova Republic of | 39798 | MIVOCLOUDMD | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
94.158.245.27 | Get hash | malicious | Mirai | Browse | ||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
daisy.ubuntu.com | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
MIVOCLOUDMD | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
File type: | |
Entropy (8bit): | 7.912726423037366 |
TrID: |
|
File name: | boatnet.mpsl.elf |
File size: | 33'708 bytes |
MD5: | 4e23210e2603fe08846bf7eeebd8aab5 |
SHA1: | b6f6949d7c9da505946a90bbb8cca46a4c3efd53 |
SHA256: | cd510f2661e5d81afed3093967ef5c31f1a14967a0e88b2b005549695653eaaa |
SHA512: | 9f3d48b2744fa1d3b489fcec2d1dd2b1ecf74f3ae47d38cc0b424a10b20f69ce1c61809426f0f58068dcf902fcaeb815dee465b9b2c8512973d3e4cbbfe4a2d8 |
SSDEEP: | 768:GiBo3YwNAQcN+vKVi7Wb5YAfSCu4vlwX/iyEo6pGeGvKxFWm:Gi0cN+iVi7USmvlwX/iyEmewm |
TLSH: | 4EE2E11CD920349DCF2D5CB951DE29718440E0DB3253CBAAA7159C8A3678A8FFE8F625 |
File Content Preview: | .ELF....................8o..4...........4. ...(.....................u...u...............h...h.E.h.E.................S.|EUPX!d.......H...H.......S..........?.E.h;....#......b.L#3...z6RMN.....r..]...3.Z.6uG.W.yq#l..C...g.,.K'.k.X.......+l.../k.............+ |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 2 |
Section Header Offset: | 0 |
Section Header Size: | 40 |
Number of Section Headers: | 0 |
Header String Table Index: | 0 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x100000 | 0x100000 | 0x8275 | 0x8275 | 7.9159 | 0x5 | R E | 0x10000 | ||
LOAD | 0xbd68 | 0x45bd68 | 0x45bd68 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x10000 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 12, 2025 15:49:22.567980051 CET | 54084 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:22.573079109 CET | 3778 | 54084 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:22.573198080 CET | 54084 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:22.613094091 CET | 54084 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:22.618197918 CET | 3778 | 54084 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:22.618256092 CET | 54084 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:22.623186111 CET | 3778 | 54084 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.256339073 CET | 3778 | 54084 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.256427050 CET | 54084 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.256603956 CET | 3778 | 54084 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.256628036 CET | 54084 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.256640911 CET | 3778 | 54084 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.256658077 CET | 54084 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.256675005 CET | 3778 | 54084 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.256689072 CET | 54084 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.256705999 CET | 3778 | 54084 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.256716967 CET | 54084 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.256761074 CET | 54084 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.256759882 CET | 3778 | 54084 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.256795883 CET | 3778 | 54084 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.256812096 CET | 54084 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.256824970 CET | 3778 | 54084 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.256841898 CET | 54084 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.256856918 CET | 3778 | 54084 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.256871939 CET | 54084 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.256892920 CET | 3778 | 54084 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.256901979 CET | 54084 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.256936073 CET | 54084 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.256962061 CET | 54086 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.261440039 CET | 3778 | 54084 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.261476040 CET | 3778 | 54084 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.261497021 CET | 54084 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.261522055 CET | 54084 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.261984110 CET | 3778 | 54086 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.262068987 CET | 54086 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.262691975 CET | 54086 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.267515898 CET | 3778 | 54086 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.267575979 CET | 54086 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.272455931 CET | 3778 | 54086 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.941850901 CET | 3778 | 54086 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.942070007 CET | 54086 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.942070007 CET | 54086 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.942080975 CET | 3778 | 54086 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.942115068 CET | 3778 | 54086 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.942151070 CET | 54086 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.942152023 CET | 3778 | 54086 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.942174911 CET | 54086 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.942186117 CET | 3778 | 54086 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.942209959 CET | 54086 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.942219973 CET | 3778 | 54086 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.942233086 CET | 54086 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.942250013 CET | 3778 | 54086 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.942272902 CET | 54086 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.942284107 CET | 3778 | 54086 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.942300081 CET | 54086 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.942320108 CET | 3778 | 54086 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.942337036 CET | 54086 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.942353964 CET | 3778 | 54086 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.942375898 CET | 54086 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.942399025 CET | 54086 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.942783117 CET | 54088 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.947283983 CET | 3778 | 54086 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.947338104 CET | 3778 | 54086 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.947361946 CET | 54086 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.947387934 CET | 54086 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.947638988 CET | 3778 | 54088 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.947707891 CET | 54088 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.948903084 CET | 54088 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.953747034 CET | 3778 | 54088 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:23.954150915 CET | 54088 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:23.959023952 CET | 3778 | 54088 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:24.664640903 CET | 3778 | 54088 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:24.664946079 CET | 54088 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:24.664946079 CET | 54088 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:24.665043116 CET | 3778 | 54088 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:24.665081978 CET | 3778 | 54088 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:24.665117025 CET | 3778 | 54088 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:24.665126085 CET | 54088 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:24.665126085 CET | 54088 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:24.665153027 CET | 3778 | 54088 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:24.665169001 CET | 54088 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:24.665188074 CET | 3778 | 54088 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:24.665191889 CET | 54088 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:24.665220976 CET | 3778 | 54088 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:24.665235996 CET | 54088 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:24.665255070 CET | 3778 | 54088 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:24.665266037 CET | 54088 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:24.665291071 CET | 3778 | 54088 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:24.665299892 CET | 54088 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:24.665327072 CET | 3778 | 54088 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:24.665334940 CET | 54088 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:24.665375948 CET | 54088 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:24.665426016 CET | 54090 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:24.670515060 CET | 3778 | 54090 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:24.670568943 CET | 54090 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:24.671184063 CET | 54090 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:24.676132917 CET | 3778 | 54090 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:24.676183939 CET | 54090 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:24.681056023 CET | 3778 | 54090 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:25.381186008 CET | 3778 | 54090 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:25.381375074 CET | 54090 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:25.381375074 CET | 54090 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:25.381620884 CET | 3778 | 54090 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:25.381630898 CET | 3778 | 54090 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:25.381648064 CET | 3778 | 54090 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:25.381685972 CET | 54090 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:25.381685972 CET | 54090 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:25.381709099 CET | 54090 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:25.381819010 CET | 54092 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:25.383764982 CET | 3778 | 54090 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:25.383790016 CET | 3778 | 54090 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:25.383810043 CET | 54090 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:25.383831024 CET | 3778 | 54090 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:25.383862019 CET | 54090 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:25.383862019 CET | 54090 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:25.386306047 CET | 3778 | 54090 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:25.386322021 CET | 3778 | 54090 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:25.386337042 CET | 3778 | 54090 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:25.386346102 CET | 54090 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:25.386346102 CET | 54090 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:25.386353016 CET | 3778 | 54090 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:25.386377096 CET | 54090 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:25.386394978 CET | 54090 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:25.386651993 CET | 3778 | 54092 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:25.386709929 CET | 54092 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:25.387356997 CET | 54092 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:25.392177105 CET | 3778 | 54092 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:25.392220974 CET | 54092 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:25.397010088 CET | 3778 | 54092 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:26.069328070 CET | 3778 | 54092 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:26.069406986 CET | 54092 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.069437981 CET | 54092 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.069636106 CET | 3778 | 54092 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:26.069679976 CET | 3778 | 54092 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:26.069696903 CET | 54092 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.069720984 CET | 54092 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.069732904 CET | 3778 | 54092 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:26.069772005 CET | 54092 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.069781065 CET | 3778 | 54092 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:26.069816113 CET | 3778 | 54092 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:26.069822073 CET | 54092 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.069855928 CET | 3778 | 54092 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:26.069859028 CET | 54092 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.069891930 CET | 54092 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.069993019 CET | 54094 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.070178032 CET | 3778 | 54092 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:26.070214033 CET | 54092 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.070230007 CET | 3778 | 54092 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:26.070265055 CET | 3778 | 54092 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:26.070277929 CET | 54092 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.070301056 CET | 54092 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.074460030 CET | 3778 | 54092 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:26.074493885 CET | 3778 | 54092 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:26.074502945 CET | 54092 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.074532986 CET | 54092 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.074834108 CET | 3778 | 54094 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:26.074879885 CET | 54094 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.075575113 CET | 54094 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.080457926 CET | 3778 | 54094 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:26.080502987 CET | 54094 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.085407019 CET | 3778 | 54094 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:26.760363102 CET | 3778 | 54094 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:26.760736942 CET | 54094 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.760736942 CET | 54094 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.760802031 CET | 3778 | 54094 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:26.760809898 CET | 3778 | 54094 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:26.760837078 CET | 3778 | 54094 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:26.760843992 CET | 3778 | 54094 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:26.760859966 CET | 3778 | 54094 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:26.760879993 CET | 3778 | 54094 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:26.760890961 CET | 3778 | 54094 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:26.760900974 CET | 54094 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.760900974 CET | 54094 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.760900974 CET | 54094 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.760907888 CET | 3778 | 54094 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:26.760921955 CET | 54094 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.760921955 CET | 54094 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.760921955 CET | 54094 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.760927916 CET | 3778 | 54094 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:26.760947943 CET | 54094 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.760947943 CET | 54094 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.760986090 CET | 54094 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.761266947 CET | 54096 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.770484924 CET | 3778 | 54096 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:26.770565033 CET | 54096 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.771203041 CET | 54096 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.776073933 CET | 3778 | 54096 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:26.776124001 CET | 54096 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:26.780999899 CET | 3778 | 54096 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:27.472198963 CET | 3778 | 54096 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:27.472702980 CET | 3778 | 54096 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:27.472723007 CET | 3778 | 54096 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:27.472759008 CET | 3778 | 54096 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:27.472786903 CET | 3778 | 54096 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:27.472805977 CET | 3778 | 54096 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:27.472840071 CET | 3778 | 54096 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:27.472862005 CET | 3778 | 54096 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:27.472894907 CET | 3778 | 54096 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:27.472903967 CET | 54096 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:27.472903967 CET | 54096 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:27.472903967 CET | 54096 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:27.472903967 CET | 54096 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:27.472903967 CET | 54096 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:27.472903967 CET | 54096 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:27.472938061 CET | 3778 | 54096 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:27.472938061 CET | 54096 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:27.472938061 CET | 54096 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:27.472938061 CET | 54096 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:27.472938061 CET | 54096 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:27.472999096 CET | 54096 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:27.473618031 CET | 54098 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:27.477761984 CET | 3778 | 54096 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:27.477859974 CET | 54096 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:27.478507042 CET | 3778 | 54098 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:27.478566885 CET | 54098 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:27.479238987 CET | 54098 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:27.484014988 CET | 3778 | 54098 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:27.484096050 CET | 54098 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:27.488890886 CET | 3778 | 54098 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:28.050060034 CET | 54098 | 3778 | 192.168.2.15 | 94.158.245.27 |
Jan 12, 2025 15:49:28.055370092 CET | 3778 | 54098 | 94.158.245.27 | 192.168.2.15 |
Jan 12, 2025 15:49:28.055479050 CET | 54098 | 3778 | 192.168.2.15 | 94.158.245.27 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 12, 2025 15:52:06.038760900 CET | 36833 | 53 | 192.168.2.15 | 1.1.1.1 |
Jan 12, 2025 15:52:06.038830042 CET | 52937 | 53 | 192.168.2.15 | 1.1.1.1 |
Jan 12, 2025 15:52:06.046741962 CET | 53 | 36833 | 1.1.1.1 | 192.168.2.15 |
Jan 12, 2025 15:52:06.047580004 CET | 53 | 52937 | 1.1.1.1 | 192.168.2.15 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 12, 2025 15:52:06.038760900 CET | 192.168.2.15 | 1.1.1.1 | 0xd2c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 12, 2025 15:52:06.038830042 CET | 192.168.2.15 | 1.1.1.1 | 0x5752 | Standard query (0) | 28 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 12, 2025 15:52:06.046741962 CET | 1.1.1.1 | 192.168.2.15 | 0xd2c | No error (0) | 162.213.35.24 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2025 15:52:06.046741962 CET | 1.1.1.1 | 192.168.2.15 | 0xd2c | No error (0) | 162.213.35.25 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 14:49:21 |
Start date (UTC): | 12/01/2025 |
Path: | /tmp/boatnet.mpsl.elf |
Arguments: | /tmp/boatnet.mpsl.elf |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 14:49:21 |
Start date (UTC): | 12/01/2025 |
Path: | /tmp/boatnet.mpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 14:49:21 |
Start date (UTC): | 12/01/2025 |
Path: | /tmp/boatnet.mpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 14:49:21 |
Start date (UTC): | 12/01/2025 |
Path: | /tmp/boatnet.mpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 14:49:27 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 14:49:27 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 14:49:27 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 14:49:27 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 14:49:27 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 14:49:27 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 14:49:33 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | - |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 14:49:33 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/sbin/xfpm-power-backlight-helper |
Arguments: | /usr/sbin/xfpm-power-backlight-helper --get-max-brightness |
File size: | 14656 bytes |
MD5 hash: | 3d221ad23f28ca3259f599b1664e2427 |
Start time (UTC): | 14:49:27 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 14:49:27 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 14:49:27 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 14:49:27 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 14:49:27 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 14:49:27 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 14:49:33 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/bin/dbus-daemon |
Arguments: | - |
File size: | 249032 bytes |
MD5 hash: | 3089d47e3f3ab84cd81c48fd406d7a8c |
Start time (UTC): | 14:49:33 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd |
File size: | 112880 bytes |
MD5 hash: | 4c7a0d6d258bb970905b19b84abcd8e9 |
Start time (UTC): | 14:49:37 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 14:49:37 |
Start date (UTC): | 12/01/2025 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd |
File size: | 112872 bytes |
MD5 hash: | eee956f1b227c1d5031f9c61223255d1 |