Edit tour
Linux
Analysis Report
bot.x86_64.elf
Overview
General Information
Sample name: | bot.x86_64.elf |
Analysis ID: | 1591223 |
MD5: | f0b16f2bd1291806dfebe873a52cbbec |
SHA1: | e037e0d55c8b88ee82c627ffa95b13cfbb9c4d40 |
SHA256: | 14c2f2acb973fa38251edda7ed747ce464aed13c23baccd7f039ef193c6f0eed |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Mirai, Gafgyt, Okiru
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Detected Mirai
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Gafgyt
Yara detected Mirai
Yara detected Okiru
Connects to many ports of the same IP (likely port scanning)
Machine Learning detection for sample
Uses dynamic DNS services
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Yara signature match
Classification
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1591223 |
Start date and time: | 2025-01-14 20:32:10 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 32s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | bot.x86_64.elf |
Detection: | MAL |
Classification: | mal100.troj.linELF@0/0@23/0 |
- VT rate limit hit for: crystalc2.duckdns.org
Command: | /tmp/bot.x86_64.elf |
PID: | 6223 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | done. |
Standard Error: |
- system is lnxubuntu20
- bot.x86_64.elf New Fork (PID: 6224, Parent: 6223)
- bot.x86_64.elf New Fork (PID: 6225, Parent: 6224)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Mirai | Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world. | No Attribution |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Bashlite, Gafgyt | Bashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS). Originally it was also known under the name Bashdoor, but this term now refers to the exploit method used by the malware. It has been used to launch attacks of up to 400 Gbps. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Gafgyt | Yara detected Gafgyt | Joe Security | ||
JoeSecurity_Okiru | Yara detected Okiru | Joe Security | ||
JoeSecurity_Mirai_3 | Yara detected Mirai | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
Click to see the 14 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Gafgyt | Yara detected Gafgyt | Joe Security | ||
JoeSecurity_Okiru | Yara detected Okiru | Joe Security | ||
JoeSecurity_Mirai_3 | Yara detected Mirai | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
Click to see the 18 entries |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-14T20:32:57.656668+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 33900 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:33:04.293706+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 33902 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:33:06.945192+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 33904 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:33:13.579823+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 33906 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:33:15.268475+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 33908 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:33:16.814323+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 33910 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:33:23.383487+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 33912 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:33:28.930368+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 33914 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:33:36.499800+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 33916 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:33:47.151889+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 33918 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:33:52.705578+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 33920 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:33:57.274836+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 33922 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:34:06.842095+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 33924 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:34:09.410721+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 33926 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:34:20.049212+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 33928 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:34:21.592868+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 33930 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:34:30.155006+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 33932 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:34:35.810615+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 33934 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:34:41.373879+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 33936 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:34:42.926757+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 33938 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:34:47.504291+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 33940 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:34:54.064424+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.23 | 33942 | 45.133.74.89 | 43957 | TCP |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Source: | Joe Sandbox ML: |
Source: | String: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | TCP traffic: |
Source: | DNS query: |
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: |
Source: | .symtab present: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | Windows Management Instrumentation | 1 Scripting | Path Interception | Direct Volume Access | 1 OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 12 Application Layer Protocol | Traffic Duplication | Data Destruction |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
63% | ReversingLabs | Linux.Backdoor.Mirai | ||
100% | Avira | EXP/ELF.Mirai.Z.A | ||
100% | Joe Sandbox ML |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
crystalc2.duckdns.org | 45.133.74.89 | true | true | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
45.133.74.89 | crystalc2.duckdns.org | Germany | 202322 | EVERYONE-BANDWIDTH-INCDE | true | |
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
91.189.91.43 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
109.202.202.202 | Get hash | malicious | Unknown | Browse |
| |
91.189.91.43 | Get hash | malicious | Prometei | Browse | ||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Moobot | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
91.189.91.42 | Get hash | malicious | Prometei | Browse | ||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Moobot | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse |
⊘No context
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CANONICAL-ASGB | Get hash | malicious | Prometei | Browse |
| |
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
CANONICAL-ASGB | Get hash | malicious | Prometei | Browse |
| |
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
EVERYONE-BANDWIDTH-INCDE | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
INIT7CH | Get hash | malicious | Prometei | Browse |
| |
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 5.2236099305060035 |
TrID: |
|
File name: | bot.x86_64.elf |
File size: | 139'576 bytes |
MD5: | f0b16f2bd1291806dfebe873a52cbbec |
SHA1: | e037e0d55c8b88ee82c627ffa95b13cfbb9c4d40 |
SHA256: | 14c2f2acb973fa38251edda7ed747ce464aed13c23baccd7f039ef193c6f0eed |
SHA512: | 4f950617872212669cf5aa41054b31e54c48f9db771c05d9875eaf214df1d4ee435103957009b2f0cd544d76bfa9db3ba40323d872d3c2b3ac6d493782296662 |
SSDEEP: | 3072:tGtwnNiaOnUTMFKPT9OSQ7AOaogjV2iZlBWCgriA1QPdL:tGtwnNiaOnUTOuLyB1QPd |
TLSH: | CFD33A17B5C180FDC4DAC5B44F9EF53ADD32B1AC1238B16B2BD4AA221E4AE315F1DA50 |
File Content Preview: | .ELF..............>.......@.....@...................@.8...@.......................@.......@...............................................Q.......Q.....x....... ...............Q.td....................................................H...._.....]..H........ |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 64 |
Program Header Offset: | 64 |
Program Header Size: | 56 |
Number of Program Headers: | 3 |
Section Header Offset: | 138936 |
Section Header Size: | 64 |
Number of Section Headers: | 10 |
Header String Table Index: | 9 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x4000e8 | 0xe8 | 0x13 | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.text | PROGBITS | 0x400100 | 0x100 | 0x15dd6 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x415ed6 | 0x15ed6 | 0xe | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.rodata | PROGBITS | 0x415f00 | 0x15f00 | 0x30c0 | 0x0 | 0x2 | A | 0 | 0 | 32 |
.ctors | PROGBITS | 0x519000 | 0x19000 | 0x18 | 0x0 | 0x3 | WA | 0 | 0 | 8 |
.dtors | PROGBITS | 0x519018 | 0x19018 | 0x10 | 0x0 | 0x3 | WA | 0 | 0 | 8 |
.data | PROGBITS | 0x519040 | 0x19040 | 0x8e38 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.bss | NOBITS | 0x521e80 | 0x21e78 | 0x72a0 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.shstrtab | STRTAB | 0x0 | 0x21e78 | 0x3e | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x400000 | 0x400000 | 0x18fc0 | 0x18fc0 | 6.3973 | 0x5 | R E | 0x100000 | .init .text .fini .rodata | |
LOAD | 0x19000 | 0x519000 | 0x519000 | 0x8e78 | 0x10120 | 0.2272 | 0x6 | RW | 0x100000 | .ctors .dtors .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x8 |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-14T20:32:57.656668+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 33900 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:33:04.293706+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 33902 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:33:06.945192+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 33904 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:33:13.579823+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 33906 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:33:15.268475+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 33908 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:33:16.814323+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 33910 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:33:23.383487+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 33912 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:33:28.930368+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 33914 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:33:36.499800+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 33916 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:33:47.151889+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 33918 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:33:52.705578+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 33920 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:33:57.274836+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 33922 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:34:06.842095+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 33924 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:34:09.410721+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 33926 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:34:20.049212+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 33928 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:34:21.592868+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 33930 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:34:30.155006+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 33932 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:34:35.810615+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 33934 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:34:41.373879+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 33936 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:34:42.926757+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 33938 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:34:47.504291+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 33940 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:34:54.064424+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.23 | 33942 | 45.133.74.89 | 43957 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 14, 2025 20:32:57.650707960 CET | 33900 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:32:57.655498981 CET | 43957 | 33900 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:32:57.655553102 CET | 33900 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:32:57.656667948 CET | 33900 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:32:57.661541939 CET | 43957 | 33900 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:32:58.185925007 CET | 43957 | 33900 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:32:58.186036110 CET | 33900 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:32:58.190886021 CET | 43957 | 33900 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:32:59.683669090 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Jan 14, 2025 20:33:01.219480991 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Jan 14, 2025 20:33:04.287763119 CET | 33902 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:04.292642117 CET | 43957 | 33902 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:04.292731047 CET | 33902 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:04.293705940 CET | 33902 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:04.300782919 CET | 43957 | 33902 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:04.832298994 CET | 43957 | 33902 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:04.832401991 CET | 33902 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:04.837201118 CET | 43957 | 33902 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:06.939650059 CET | 33904 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:06.944516897 CET | 43957 | 33904 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:06.944575071 CET | 33904 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:06.945192099 CET | 33904 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:06.949923992 CET | 43957 | 33904 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:07.472114086 CET | 43957 | 33904 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:07.472239017 CET | 33904 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:07.477221966 CET | 43957 | 33904 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:13.574249029 CET | 33906 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:13.579058886 CET | 43957 | 33906 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:13.579111099 CET | 33906 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:13.579823017 CET | 33906 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:13.585745096 CET | 43957 | 33906 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:14.162446976 CET | 43957 | 33906 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:14.162708998 CET | 33906 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:14.167538881 CET | 43957 | 33906 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:15.262429953 CET | 33908 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:15.267731905 CET | 43957 | 33908 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:15.267791033 CET | 33908 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:15.268475056 CET | 33908 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:15.273721933 CET | 43957 | 33908 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:15.799076080 CET | 43957 | 33908 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:15.799299002 CET | 33908 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:15.804120064 CET | 43957 | 33908 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:16.065442085 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Jan 14, 2025 20:33:16.808686972 CET | 33910 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:16.813493013 CET | 43957 | 33910 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:16.813550949 CET | 33910 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:16.814322948 CET | 33910 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:16.819093943 CET | 43957 | 33910 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:17.367458105 CET | 43957 | 33910 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:17.367573023 CET | 33910 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:17.372425079 CET | 43957 | 33910 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:23.377557993 CET | 33912 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:23.382376909 CET | 43957 | 33912 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:23.382441998 CET | 33912 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:23.383486986 CET | 33912 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:23.388290882 CET | 43957 | 33912 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:23.914028883 CET | 43957 | 33912 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:23.914802074 CET | 33912 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:23.919677019 CET | 43957 | 33912 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:26.304177999 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Jan 14, 2025 20:33:28.924398899 CET | 33914 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:28.929217100 CET | 43957 | 33914 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:28.929554939 CET | 33914 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:28.930367947 CET | 33914 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:28.935127020 CET | 43957 | 33914 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:29.483052969 CET | 43957 | 33914 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:29.483339071 CET | 33914 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:29.488240957 CET | 43957 | 33914 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:32.447395086 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Jan 14, 2025 20:33:36.493654013 CET | 33916 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:36.498588085 CET | 43957 | 33916 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:36.498658895 CET | 33916 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:36.499799967 CET | 33916 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:36.505106926 CET | 43957 | 33916 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:37.044369936 CET | 43957 | 33916 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:37.044615030 CET | 33916 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:37.049479961 CET | 43957 | 33916 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:47.144969940 CET | 33918 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:47.150702000 CET | 43957 | 33918 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:47.150768995 CET | 33918 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:47.151889086 CET | 33918 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:47.156699896 CET | 43957 | 33918 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:47.689194918 CET | 43957 | 33918 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:47.689579964 CET | 33918 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:47.694489956 CET | 43957 | 33918 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:52.699692965 CET | 33920 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:52.704595089 CET | 43957 | 33920 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:52.704685926 CET | 33920 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:52.705578089 CET | 33920 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:52.710464954 CET | 43957 | 33920 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:53.258564949 CET | 43957 | 33920 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:53.258685112 CET | 33920 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:53.263503075 CET | 43957 | 33920 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:57.019867897 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Jan 14, 2025 20:33:57.268773079 CET | 33922 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:57.273737907 CET | 43957 | 33922 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:57.273804903 CET | 33922 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:57.274836063 CET | 33922 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:57.279666901 CET | 43957 | 33922 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:57.826528072 CET | 43957 | 33922 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:33:57.826677084 CET | 33922 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:33:57.831584930 CET | 43957 | 33922 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:06.836121082 CET | 33924 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:06.840940952 CET | 43957 | 33924 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:06.841018915 CET | 33924 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:06.842094898 CET | 33924 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:06.846843958 CET | 43957 | 33924 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:07.393553019 CET | 43957 | 33924 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:07.393712044 CET | 33924 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:07.398556948 CET | 43957 | 33924 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:09.404053926 CET | 33926 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:09.408940077 CET | 43957 | 33926 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:09.409034967 CET | 33926 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:09.410721064 CET | 33926 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:09.415513992 CET | 43957 | 33926 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:09.938062906 CET | 43957 | 33926 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:09.938201904 CET | 33926 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:09.943538904 CET | 43957 | 33926 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:20.042735100 CET | 33928 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:20.048031092 CET | 43957 | 33928 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:20.048084974 CET | 33928 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:20.049211979 CET | 33928 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:20.054007053 CET | 43957 | 33928 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:20.575937986 CET | 43957 | 33928 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:20.576067924 CET | 33928 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:20.580955029 CET | 43957 | 33928 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:21.586884022 CET | 33930 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:21.591716051 CET | 43957 | 33930 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:21.591767073 CET | 33930 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:21.592868090 CET | 33930 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:21.597697973 CET | 43957 | 33930 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:22.138298035 CET | 43957 | 33930 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:22.138473034 CET | 33930 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:22.143399000 CET | 43957 | 33930 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:30.148696899 CET | 33932 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:30.153546095 CET | 43957 | 33932 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:30.153614044 CET | 33932 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:30.155005932 CET | 33932 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:30.159753084 CET | 43957 | 33932 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:30.702200890 CET | 43957 | 33932 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:30.702436924 CET | 33932 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:30.707237005 CET | 43957 | 33932 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:35.803906918 CET | 33934 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:35.809618950 CET | 43957 | 33934 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:35.809690952 CET | 33934 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:35.810615063 CET | 33934 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:35.816070080 CET | 43957 | 33934 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:36.356338024 CET | 43957 | 33934 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:36.356602907 CET | 33934 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:36.361479998 CET | 43957 | 33934 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:41.366935015 CET | 33936 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:41.371961117 CET | 43957 | 33936 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:41.372134924 CET | 33936 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:41.373878956 CET | 33936 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:41.378748894 CET | 43957 | 33936 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:41.910082102 CET | 43957 | 33936 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:41.910450935 CET | 33936 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:41.915421963 CET | 43957 | 33936 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:42.920876026 CET | 33938 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:42.925789118 CET | 43957 | 33938 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:42.925848007 CET | 33938 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:42.926757097 CET | 33938 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:42.931665897 CET | 43957 | 33938 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:43.486202002 CET | 43957 | 33938 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:43.486346960 CET | 33938 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:43.491199970 CET | 43957 | 33938 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:47.497955084 CET | 33940 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:47.503155947 CET | 43957 | 33940 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:47.503242016 CET | 33940 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:47.504291058 CET | 33940 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:47.509126902 CET | 43957 | 33940 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:48.048891068 CET | 43957 | 33940 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:48.049134970 CET | 33940 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:48.054038048 CET | 43957 | 33940 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:54.058733940 CET | 33942 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:54.063641071 CET | 43957 | 33942 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:54.063713074 CET | 33942 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:54.064424038 CET | 33942 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:54.069757938 CET | 43957 | 33942 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:54.652460098 CET | 43957 | 33942 | 45.133.74.89 | 192.168.2.23 |
Jan 14, 2025 20:34:54.652757883 CET | 33942 | 43957 | 192.168.2.23 | 45.133.74.89 |
Jan 14, 2025 20:34:54.657689095 CET | 43957 | 33942 | 45.133.74.89 | 192.168.2.23 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 14, 2025 20:32:57.552086115 CET | 57730 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 14, 2025 20:32:57.650183916 CET | 53 | 57730 | 8.8.8.8 | 192.168.2.23 |
Jan 14, 2025 20:33:04.187455893 CET | 43814 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 14, 2025 20:33:04.287273884 CET | 53 | 43814 | 8.8.8.8 | 192.168.2.23 |
Jan 14, 2025 20:33:06.842763901 CET | 46680 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 14, 2025 20:33:06.939148903 CET | 53 | 46680 | 8.8.8.8 | 192.168.2.23 |
Jan 14, 2025 20:33:13.473442078 CET | 36641 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 14, 2025 20:33:13.573520899 CET | 53 | 36641 | 8.8.8.8 | 192.168.2.23 |
Jan 14, 2025 20:33:15.164414883 CET | 48143 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 14, 2025 20:33:15.261940002 CET | 53 | 48143 | 8.8.8.8 | 192.168.2.23 |
Jan 14, 2025 20:33:16.801248074 CET | 45245 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 14, 2025 20:33:16.808207989 CET | 53 | 45245 | 8.8.8.8 | 192.168.2.23 |
Jan 14, 2025 20:33:23.369574070 CET | 34514 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 14, 2025 20:33:23.377022982 CET | 53 | 34514 | 8.8.8.8 | 192.168.2.23 |
Jan 14, 2025 20:33:28.916681051 CET | 52748 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 14, 2025 20:33:28.923578024 CET | 53 | 52748 | 8.8.8.8 | 192.168.2.23 |
Jan 14, 2025 20:33:36.485308886 CET | 59966 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 14, 2025 20:33:36.492994070 CET | 53 | 59966 | 8.8.8.8 | 192.168.2.23 |
Jan 14, 2025 20:33:46.046497107 CET | 43728 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 14, 2025 20:33:47.143910885 CET | 53 | 43728 | 8.8.8.8 | 192.168.2.23 |
Jan 14, 2025 20:33:52.691833019 CET | 33710 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 14, 2025 20:33:52.699104071 CET | 53 | 33710 | 8.8.8.8 | 192.168.2.23 |
Jan 14, 2025 20:33:57.260929108 CET | 39390 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 14, 2025 20:33:57.268218040 CET | 53 | 39390 | 8.8.8.8 | 192.168.2.23 |
Jan 14, 2025 20:34:06.828860998 CET | 54261 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 14, 2025 20:34:06.835469007 CET | 53 | 54261 | 8.8.8.8 | 192.168.2.23 |
Jan 14, 2025 20:34:09.396348000 CET | 49443 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 14, 2025 20:34:09.403527975 CET | 53 | 49443 | 8.8.8.8 | 192.168.2.23 |
Jan 14, 2025 20:34:19.939968109 CET | 46069 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 14, 2025 20:34:20.041841984 CET | 53 | 46069 | 8.8.8.8 | 192.168.2.23 |
Jan 14, 2025 20:34:21.578975916 CET | 50341 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 14, 2025 20:34:21.586277962 CET | 53 | 50341 | 8.8.8.8 | 192.168.2.23 |
Jan 14, 2025 20:34:30.140861988 CET | 56092 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 14, 2025 20:34:30.148087025 CET | 53 | 56092 | 8.8.8.8 | 192.168.2.23 |
Jan 14, 2025 20:34:35.705708981 CET | 38183 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 14, 2025 20:34:35.803239107 CET | 53 | 38183 | 8.8.8.8 | 192.168.2.23 |
Jan 14, 2025 20:34:41.358580112 CET | 42575 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 14, 2025 20:34:41.366383076 CET | 53 | 42575 | 8.8.8.8 | 192.168.2.23 |
Jan 14, 2025 20:34:42.913049936 CET | 35079 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 14, 2025 20:34:42.920325994 CET | 53 | 35079 | 8.8.8.8 | 192.168.2.23 |
Jan 14, 2025 20:34:47.488488913 CET | 45993 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 14, 2025 20:34:47.497306108 CET | 53 | 45993 | 8.8.8.8 | 192.168.2.23 |
Jan 14, 2025 20:34:54.050956964 CET | 42577 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 14, 2025 20:34:54.058141947 CET | 53 | 42577 | 8.8.8.8 | 192.168.2.23 |
Jan 14, 2025 20:35:02.654442072 CET | 58812 | 53 | 192.168.2.23 | 8.8.8.8 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 14, 2025 20:32:57.552086115 CET | 192.168.2.23 | 8.8.8.8 | 0xacff | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:33:04.187455893 CET | 192.168.2.23 | 8.8.8.8 | 0xebf9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:33:06.842763901 CET | 192.168.2.23 | 8.8.8.8 | 0xb6b7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:33:13.473442078 CET | 192.168.2.23 | 8.8.8.8 | 0x6111 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:33:15.164414883 CET | 192.168.2.23 | 8.8.8.8 | 0xaefb | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:33:16.801248074 CET | 192.168.2.23 | 8.8.8.8 | 0xeba7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:33:23.369574070 CET | 192.168.2.23 | 8.8.8.8 | 0xa038 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:33:28.916681051 CET | 192.168.2.23 | 8.8.8.8 | 0x523c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:33:36.485308886 CET | 192.168.2.23 | 8.8.8.8 | 0x7af3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:33:46.046497107 CET | 192.168.2.23 | 8.8.8.8 | 0xefab | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:33:52.691833019 CET | 192.168.2.23 | 8.8.8.8 | 0xe1a6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:33:57.260929108 CET | 192.168.2.23 | 8.8.8.8 | 0x639a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:34:06.828860998 CET | 192.168.2.23 | 8.8.8.8 | 0x7f05 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:34:09.396348000 CET | 192.168.2.23 | 8.8.8.8 | 0xeb4c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:34:19.939968109 CET | 192.168.2.23 | 8.8.8.8 | 0xb6f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:34:21.578975916 CET | 192.168.2.23 | 8.8.8.8 | 0x216e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:34:30.140861988 CET | 192.168.2.23 | 8.8.8.8 | 0x9536 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:34:35.705708981 CET | 192.168.2.23 | 8.8.8.8 | 0xa8a0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:34:41.358580112 CET | 192.168.2.23 | 8.8.8.8 | 0x5d9a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:34:42.913049936 CET | 192.168.2.23 | 8.8.8.8 | 0x4068 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:34:47.488488913 CET | 192.168.2.23 | 8.8.8.8 | 0x77b3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:34:54.050956964 CET | 192.168.2.23 | 8.8.8.8 | 0x1612 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:35:02.654442072 CET | 192.168.2.23 | 8.8.8.8 | 0x63ad | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 14, 2025 20:32:57.650183916 CET | 8.8.8.8 | 192.168.2.23 | 0xacff | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:33:04.287273884 CET | 8.8.8.8 | 192.168.2.23 | 0xebf9 | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:33:06.939148903 CET | 8.8.8.8 | 192.168.2.23 | 0xb6b7 | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:33:13.573520899 CET | 8.8.8.8 | 192.168.2.23 | 0x6111 | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:33:15.261940002 CET | 8.8.8.8 | 192.168.2.23 | 0xaefb | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:33:16.808207989 CET | 8.8.8.8 | 192.168.2.23 | 0xeba7 | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:33:23.377022982 CET | 8.8.8.8 | 192.168.2.23 | 0xa038 | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:33:28.923578024 CET | 8.8.8.8 | 192.168.2.23 | 0x523c | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:33:36.492994070 CET | 8.8.8.8 | 192.168.2.23 | 0x7af3 | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:33:47.143910885 CET | 8.8.8.8 | 192.168.2.23 | 0xefab | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:33:52.699104071 CET | 8.8.8.8 | 192.168.2.23 | 0xe1a6 | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:33:57.268218040 CET | 8.8.8.8 | 192.168.2.23 | 0x639a | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:34:06.835469007 CET | 8.8.8.8 | 192.168.2.23 | 0x7f05 | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:34:09.403527975 CET | 8.8.8.8 | 192.168.2.23 | 0xeb4c | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:34:20.041841984 CET | 8.8.8.8 | 192.168.2.23 | 0xb6f | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:34:21.586277962 CET | 8.8.8.8 | 192.168.2.23 | 0x216e | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:34:30.148087025 CET | 8.8.8.8 | 192.168.2.23 | 0x9536 | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:34:35.803239107 CET | 8.8.8.8 | 192.168.2.23 | 0xa8a0 | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:34:41.366383076 CET | 8.8.8.8 | 192.168.2.23 | 0x5d9a | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:34:42.920325994 CET | 8.8.8.8 | 192.168.2.23 | 0x4068 | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:34:47.497306108 CET | 8.8.8.8 | 192.168.2.23 | 0x77b3 | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:34:54.058141947 CET | 8.8.8.8 | 192.168.2.23 | 0x1612 | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 19:32:56 |
Start date (UTC): | 14/01/2025 |
Path: | /tmp/bot.x86_64.elf |
Arguments: | /tmp/bot.x86_64.elf |
File size: | 139576 bytes |
MD5 hash: | f0b16f2bd1291806dfebe873a52cbbec |
Start time (UTC): | 19:32:56 |
Start date (UTC): | 14/01/2025 |
Path: | /tmp/bot.x86_64.elf |
Arguments: | - |
File size: | 139576 bytes |
MD5 hash: | f0b16f2bd1291806dfebe873a52cbbec |
Start time (UTC): | 19:32:56 |
Start date (UTC): | 14/01/2025 |
Path: | /tmp/bot.x86_64.elf |
Arguments: | - |
File size: | 139576 bytes |
MD5 hash: | f0b16f2bd1291806dfebe873a52cbbec |