Edit tour
Linux
Analysis Report
bot.x86.elf
Overview
General Information
Sample name: | bot.x86.elf |
Analysis ID: | 1591230 |
MD5: | 73e9f8adef7a11c9ef8cb1f04e3515b8 |
SHA1: | 924b5222423513793c01beb6b76f0db91d6285f0 |
SHA256: | c07b4d74b4a9d505d7e4f06d7ce14a0e2171491b5767091ae116848371e9a979 |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Mirai, Okiru
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Detected Mirai
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Mirai
Yara detected Okiru
Connects to many ports of the same IP (likely port scanning)
Machine Learning detection for sample
Uses dynamic DNS services
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Yara signature match
Classification
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1591230 |
Start date and time: | 2025-01-14 20:36:10 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 48s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | bot.x86.elf |
Detection: | MAL |
Classification: | mal100.troj.linELF@0/0@20/0 |
Command: | /tmp/bot.x86.elf |
PID: | 5834 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | done. |
Standard Error: |
- system is lnxubuntu20
- bot.x86.elf New Fork (PID: 5835, Parent: 5834)
- bot.x86.elf New Fork (PID: 5836, Parent: 5835)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Mirai | Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Okiru | Yara detected Okiru | Joe Security | ||
JoeSecurity_Mirai_3 | Yara detected Mirai | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
Linux_Trojan_Mirai_b14f4c5d | unknown | unknown |
| |
Click to see the 5 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Okiru | Yara detected Okiru | Joe Security | ||
JoeSecurity_Mirai_3 | Yara detected Mirai | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
Linux_Trojan_Mirai_b14f4c5d | unknown | unknown |
| |
Click to see the 9 entries |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-14T20:37:24.727928+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 55388 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:37:35.370762+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 55390 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:37:45.006309+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 55392 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:37:50.546830+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 55394 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:37:52.099783+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 55396 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:37:57.734862+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 55398 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:38:06.278886+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 55400 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:38:08.824357+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 55402 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:38:14.377175+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 55404 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:38:17.956654+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 55406 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:38:20.512227+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 55408 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:38:30.057293+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 55410 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:38:40.700544+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 55412 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:38:49.239997+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 55414 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:38:59.781262+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 55416 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:39:05.426137+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 55418 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:39:09.071604+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 55420 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:39:14.673529+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 55422 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:39:17.228980+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 55424 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:39:19.788254+0100 | 2030490 | 1 | Malware Command and Control Activity Detected | 192.168.2.15 | 55426 | 45.133.74.89 | 43957 | TCP |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Source: | Joe Sandbox ML: |
Source: | String: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | TCP traffic: |
Source: | DNS query: |
Source: | TCP traffic: |
Source: | DNS traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: |
Source: | .symtab present: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | Windows Management Instrumentation | 1 Scripting | Path Interception | Direct Volume Access | 1 OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Non-Standard Port | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 11 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
63% | ReversingLabs | Linux.Backdoor.Mirai | ||
100% | Avira | EXP/ELF.Mirai.Z.A | ||
100% | Joe Sandbox ML |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
crystalc2.duckdns.org | 45.133.74.89 | true | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
45.133.74.89 | crystalc2.duckdns.org | Germany | 202322 | EVERYONE-BANDWIDTH-INCDE | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
45.133.74.89 | Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | ||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | |||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
crystalc2.duckdns.org | Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| |
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
EVERYONE-BANDWIDTH-INCDE | Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| |
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 5.7150584816343315 |
TrID: |
|
File name: | bot.x86.elf |
File size: | 89'576 bytes |
MD5: | 73e9f8adef7a11c9ef8cb1f04e3515b8 |
SHA1: | 924b5222423513793c01beb6b76f0db91d6285f0 |
SHA256: | c07b4d74b4a9d505d7e4f06d7ce14a0e2171491b5767091ae116848371e9a979 |
SHA512: | 9b1eac7e08b41de7f3fc24a239a69c04e9cd62ba30150c2c8a0ac476c04b04049def3640cfbec126f610f6ce67e72262874dd0cee5e76bba28cd2fbf413ae485 |
SSDEEP: | 1536:xpmWc2AcighsZ82fJxfcLHH1mSsM8y6Q+gBQ9TnkISGtAdR0xZ:xpmX2riED2frfsHVmL1Q1Q9kVTR0x |
TLSH: | A2936CC5F683D4F5E89304B1613AEB339B33F0B52019EA43D7799932ECA1511EA16B6C |
File Content Preview: | .ELF....................d...4...X\......4. ...(......................................................G..8...........Q.td............................U..S........$...h........[]...$.............U......= ....t..5...................u........t....h............ |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 89176 |
Section Header Size: | 40 |
Number of Section Headers: | 10 |
Header String Table Index: | 9 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x8048094 | 0x94 | 0x1c | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.text | PROGBITS | 0x80480b0 | 0xb0 | 0xf136 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x80571e6 | 0xf1e6 | 0x17 | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.rodata | PROGBITS | 0x8057200 | 0xf200 | 0x2290 | 0x0 | 0x2 | A | 0 | 0 | 32 |
.ctors | PROGBITS | 0x805a494 | 0x11494 | 0xc | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x805a4a0 | 0x114a0 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x805a4c0 | 0x114c0 | 0x4758 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.bss | NOBITS | 0x805ec20 | 0x15c18 | 0x49ac | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.shstrtab | STRTAB | 0x0 | 0x15c18 | 0x3e | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8048000 | 0x8048000 | 0x11490 | 0x11490 | 6.5887 | 0x5 | R E | 0x1000 | .init .text .fini .rodata | |
LOAD | 0x11494 | 0x805a494 | 0x805a494 | 0x4784 | 0x9138 | 0.3643 | 0x6 | RW | 0x1000 | .ctors .dtors .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x4 |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-14T20:37:24.727928+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.15 | 55388 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:37:35.370762+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.15 | 55390 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:37:45.006309+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.15 | 55392 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:37:50.546830+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.15 | 55394 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:37:52.099783+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.15 | 55396 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:37:57.734862+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.15 | 55398 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:38:06.278886+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.15 | 55400 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:38:08.824357+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.15 | 55402 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:38:14.377175+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.15 | 55404 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:38:17.956654+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.15 | 55406 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:38:20.512227+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.15 | 55408 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:38:30.057293+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.15 | 55410 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:38:40.700544+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.15 | 55412 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:38:49.239997+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.15 | 55414 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:38:59.781262+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.15 | 55416 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:39:05.426137+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.15 | 55418 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:39:09.071604+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.15 | 55420 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:39:14.673529+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.15 | 55422 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:39:17.228980+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.15 | 55424 | 45.133.74.89 | 43957 | TCP |
2025-01-14T20:39:19.788254+0100 | 2030490 | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) | 1 | 192.168.2.15 | 55426 | 45.133.74.89 | 43957 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 14, 2025 20:37:24.723105907 CET | 55388 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:37:24.727842093 CET | 43957 | 55388 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:37:24.727890015 CET | 55388 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:37:24.727927923 CET | 55388 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:37:24.732701063 CET | 43957 | 55388 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:37:25.266922951 CET | 43957 | 55388 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:37:25.267002106 CET | 55388 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:37:25.271912098 CET | 43957 | 55388 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:37:35.365684986 CET | 55390 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:37:35.370668888 CET | 43957 | 55390 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:37:35.370727062 CET | 55390 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:37:35.370762110 CET | 55390 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:37:35.375649929 CET | 43957 | 55390 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:37:35.901154041 CET | 43957 | 55390 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:37:35.901410103 CET | 55390 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:37:35.906377077 CET | 43957 | 55390 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:37:45.000612974 CET | 55392 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:37:45.006124973 CET | 43957 | 55392 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:37:45.006309032 CET | 55392 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:37:45.006309032 CET | 55392 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:37:45.011365891 CET | 43957 | 55392 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:37:45.529922962 CET | 43957 | 55392 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:37:45.530307055 CET | 55392 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:37:45.535353899 CET | 43957 | 55392 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:37:50.541733027 CET | 55394 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:37:50.546700001 CET | 43957 | 55394 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:37:50.546780109 CET | 55394 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:37:50.546829939 CET | 55394 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:37:50.552706957 CET | 43957 | 55394 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:37:51.085534096 CET | 43957 | 55394 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:37:51.085834026 CET | 55394 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:37:51.090780973 CET | 43957 | 55394 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:37:52.094758034 CET | 55396 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:37:52.099687099 CET | 43957 | 55396 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:37:52.099782944 CET | 55396 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:37:52.099782944 CET | 55396 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:37:52.104736090 CET | 43957 | 55396 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:37:52.629226923 CET | 43957 | 55396 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:37:52.629518032 CET | 55396 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:37:52.634535074 CET | 43957 | 55396 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:37:57.729760885 CET | 55398 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:37:57.734603882 CET | 43957 | 55398 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:37:57.734862089 CET | 55398 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:37:57.734862089 CET | 55398 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:37:57.739713907 CET | 43957 | 55398 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:37:58.263026953 CET | 43957 | 55398 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:37:58.263355017 CET | 55398 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:37:58.268589020 CET | 43957 | 55398 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:06.273679018 CET | 55400 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:06.278691053 CET | 43957 | 55400 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:06.278886080 CET | 55400 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:06.278886080 CET | 55400 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:06.283802986 CET | 43957 | 55400 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:06.809222937 CET | 43957 | 55400 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:06.809469938 CET | 55400 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:06.814412117 CET | 43957 | 55400 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:08.819221020 CET | 55402 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:08.824244976 CET | 43957 | 55402 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:08.824316025 CET | 55402 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:08.824357033 CET | 55402 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:08.829242945 CET | 43957 | 55402 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:09.361947060 CET | 43957 | 55402 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:09.362232924 CET | 55402 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:09.367185116 CET | 43957 | 55402 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:14.371071100 CET | 55404 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:14.377057076 CET | 43957 | 55404 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:14.377130032 CET | 55404 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:14.377175093 CET | 55404 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:14.382709980 CET | 43957 | 55404 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:14.941592932 CET | 43957 | 55404 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:14.941982031 CET | 55404 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:14.946939945 CET | 43957 | 55404 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:17.951541901 CET | 55406 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:17.956501961 CET | 43957 | 55406 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:17.956610918 CET | 55406 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:17.956654072 CET | 55406 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:17.961599112 CET | 43957 | 55406 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:18.496646881 CET | 43957 | 55406 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:18.497020960 CET | 55406 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:18.501981020 CET | 43957 | 55406 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:20.507208109 CET | 55408 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:20.512088060 CET | 43957 | 55408 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:20.512190104 CET | 55408 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:20.512227058 CET | 55408 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:20.517091990 CET | 43957 | 55408 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:21.042881966 CET | 43957 | 55408 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:21.043028116 CET | 55408 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:21.047916889 CET | 43957 | 55408 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:30.052103996 CET | 55410 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:30.057176113 CET | 43957 | 55410 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:30.057254076 CET | 55410 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:30.057292938 CET | 55410 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:30.062464952 CET | 43957 | 55410 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:30.596189976 CET | 43957 | 55410 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:30.596383095 CET | 55410 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:30.601205111 CET | 43957 | 55410 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:40.695197105 CET | 55412 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:40.700460911 CET | 43957 | 55412 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:40.700544119 CET | 55412 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:40.700544119 CET | 55412 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:40.705789089 CET | 43957 | 55412 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:41.226474047 CET | 43957 | 55412 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:41.226643085 CET | 55412 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:41.231535912 CET | 43957 | 55412 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:49.234994888 CET | 55414 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:49.239898920 CET | 43957 | 55414 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:49.239955902 CET | 55414 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:49.239996910 CET | 55414 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:49.244807005 CET | 43957 | 55414 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:49.766938925 CET | 43957 | 55414 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:49.767087936 CET | 55414 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:49.772017956 CET | 43957 | 55414 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:59.776184082 CET | 55416 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:59.781096935 CET | 43957 | 55416 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:38:59.781203985 CET | 55416 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:59.781261921 CET | 55416 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:38:59.786075115 CET | 43957 | 55416 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:39:00.319036007 CET | 43957 | 55416 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:39:00.319363117 CET | 55416 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:39:00.324322939 CET | 43957 | 55416 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:39:05.420247078 CET | 55418 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:39:05.425728083 CET | 43957 | 55418 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:39:05.426096916 CET | 55418 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:39:05.426136971 CET | 55418 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:39:05.431484938 CET | 43957 | 55418 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:39:05.966200113 CET | 43957 | 55418 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:39:05.966830015 CET | 55418 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:39:05.972177029 CET | 43957 | 55418 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:39:09.066523075 CET | 55420 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:39:09.071512938 CET | 43957 | 55420 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:39:09.071573019 CET | 55420 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:39:09.071604013 CET | 55420 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:39:09.076446056 CET | 43957 | 55420 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:39:09.657113075 CET | 43957 | 55420 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:39:09.657300949 CET | 55420 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:39:09.662231922 CET | 43957 | 55420 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:39:14.667622089 CET | 55422 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:39:14.673396111 CET | 43957 | 55422 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:39:14.673465967 CET | 55422 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:39:14.673528910 CET | 55422 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:39:14.678379059 CET | 43957 | 55422 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:39:15.212419033 CET | 43957 | 55422 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:39:15.212543011 CET | 55422 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:39:15.217535973 CET | 43957 | 55422 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:39:17.223660946 CET | 55424 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:39:17.228785992 CET | 43957 | 55424 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:39:17.228905916 CET | 55424 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:39:17.228980064 CET | 55424 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:39:17.233814001 CET | 43957 | 55424 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:39:17.774198055 CET | 43957 | 55424 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:39:17.774399042 CET | 55424 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:39:17.779370070 CET | 43957 | 55424 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:39:19.783164024 CET | 55426 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:39:19.788144112 CET | 43957 | 55426 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:39:19.788216114 CET | 55426 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:39:19.788254023 CET | 55426 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:39:19.793112040 CET | 43957 | 55426 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:39:20.340271950 CET | 43957 | 55426 | 45.133.74.89 | 192.168.2.15 |
Jan 14, 2025 20:39:20.340482950 CET | 55426 | 43957 | 192.168.2.15 | 45.133.74.89 |
Jan 14, 2025 20:39:20.345446110 CET | 43957 | 55426 | 45.133.74.89 | 192.168.2.15 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 14, 2025 20:37:24.716737032 CET | 40795 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 14, 2025 20:37:24.723006010 CET | 53 | 40795 | 8.8.8.8 | 192.168.2.15 |
Jan 14, 2025 20:37:35.268481970 CET | 55112 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 14, 2025 20:37:35.365562916 CET | 53 | 55112 | 8.8.8.8 | 192.168.2.15 |
Jan 14, 2025 20:37:44.903337955 CET | 58952 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 14, 2025 20:37:45.000279903 CET | 53 | 58952 | 8.8.8.8 | 192.168.2.15 |
Jan 14, 2025 20:37:50.534187078 CET | 53040 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 14, 2025 20:37:50.541496038 CET | 53 | 53040 | 8.8.8.8 | 192.168.2.15 |
Jan 14, 2025 20:37:52.087220907 CET | 59719 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 14, 2025 20:37:52.094659090 CET | 53 | 59719 | 8.8.8.8 | 192.168.2.15 |
Jan 14, 2025 20:37:57.632221937 CET | 51280 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 14, 2025 20:37:57.729408026 CET | 53 | 51280 | 8.8.8.8 | 192.168.2.15 |
Jan 14, 2025 20:38:06.265815973 CET | 58564 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 14, 2025 20:38:06.273427010 CET | 53 | 58564 | 8.8.8.8 | 192.168.2.15 |
Jan 14, 2025 20:38:08.811674118 CET | 51480 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 14, 2025 20:38:08.819011927 CET | 53 | 51480 | 8.8.8.8 | 192.168.2.15 |
Jan 14, 2025 20:38:14.363720894 CET | 36465 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 14, 2025 20:38:14.370867014 CET | 53 | 36465 | 8.8.8.8 | 192.168.2.15 |
Jan 14, 2025 20:38:17.944104910 CET | 59232 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 14, 2025 20:38:17.951421022 CET | 53 | 59232 | 8.8.8.8 | 192.168.2.15 |
Jan 14, 2025 20:38:20.499516010 CET | 53918 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 14, 2025 20:38:20.507096052 CET | 53 | 53918 | 8.8.8.8 | 192.168.2.15 |
Jan 14, 2025 20:38:30.044518948 CET | 41688 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 14, 2025 20:38:30.051981926 CET | 53 | 41688 | 8.8.8.8 | 192.168.2.15 |
Jan 14, 2025 20:38:40.597631931 CET | 39638 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 14, 2025 20:38:40.694819927 CET | 53 | 39638 | 8.8.8.8 | 192.168.2.15 |
Jan 14, 2025 20:38:49.227827072 CET | 51533 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 14, 2025 20:38:49.234888077 CET | 53 | 51533 | 8.8.8.8 | 192.168.2.15 |
Jan 14, 2025 20:38:59.768842936 CET | 52222 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 14, 2025 20:38:59.776002884 CET | 53 | 52222 | 8.8.8.8 | 192.168.2.15 |
Jan 14, 2025 20:39:05.322098970 CET | 35736 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 14, 2025 20:39:05.419760942 CET | 53 | 35736 | 8.8.8.8 | 192.168.2.15 |
Jan 14, 2025 20:39:08.969317913 CET | 43771 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 14, 2025 20:39:09.066337109 CET | 53 | 43771 | 8.8.8.8 | 192.168.2.15 |
Jan 14, 2025 20:39:14.658611059 CET | 50160 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 14, 2025 20:39:14.667474031 CET | 53 | 50160 | 8.8.8.8 | 192.168.2.15 |
Jan 14, 2025 20:39:17.214061975 CET | 48359 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 14, 2025 20:39:17.223217010 CET | 53 | 48359 | 8.8.8.8 | 192.168.2.15 |
Jan 14, 2025 20:39:19.775985956 CET | 52249 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 14, 2025 20:39:19.783061981 CET | 53 | 52249 | 8.8.8.8 | 192.168.2.15 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 14, 2025 20:37:24.716737032 CET | 192.168.2.15 | 8.8.8.8 | 0x9697 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:37:35.268481970 CET | 192.168.2.15 | 8.8.8.8 | 0x58a1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:37:44.903337955 CET | 192.168.2.15 | 8.8.8.8 | 0x430f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:37:50.534187078 CET | 192.168.2.15 | 8.8.8.8 | 0x9cae | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:37:52.087220907 CET | 192.168.2.15 | 8.8.8.8 | 0x5c31 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:37:57.632221937 CET | 192.168.2.15 | 8.8.8.8 | 0x4208 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:38:06.265815973 CET | 192.168.2.15 | 8.8.8.8 | 0xcc15 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:38:08.811674118 CET | 192.168.2.15 | 8.8.8.8 | 0x24c3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:38:14.363720894 CET | 192.168.2.15 | 8.8.8.8 | 0xdd3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:38:17.944104910 CET | 192.168.2.15 | 8.8.8.8 | 0x9cd0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:38:20.499516010 CET | 192.168.2.15 | 8.8.8.8 | 0xab32 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:38:30.044518948 CET | 192.168.2.15 | 8.8.8.8 | 0xe5df | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:38:40.597631931 CET | 192.168.2.15 | 8.8.8.8 | 0xd712 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:38:49.227827072 CET | 192.168.2.15 | 8.8.8.8 | 0x5a52 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:38:59.768842936 CET | 192.168.2.15 | 8.8.8.8 | 0xe0c2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:39:05.322098970 CET | 192.168.2.15 | 8.8.8.8 | 0xcc1d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:39:08.969317913 CET | 192.168.2.15 | 8.8.8.8 | 0x2a2d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:39:14.658611059 CET | 192.168.2.15 | 8.8.8.8 | 0xeebb | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:39:17.214061975 CET | 192.168.2.15 | 8.8.8.8 | 0x92e8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 20:39:19.775985956 CET | 192.168.2.15 | 8.8.8.8 | 0x486f | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 14, 2025 20:37:24.723006010 CET | 8.8.8.8 | 192.168.2.15 | 0x9697 | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:37:35.365562916 CET | 8.8.8.8 | 192.168.2.15 | 0x58a1 | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:37:45.000279903 CET | 8.8.8.8 | 192.168.2.15 | 0x430f | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:37:50.541496038 CET | 8.8.8.8 | 192.168.2.15 | 0x9cae | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:37:52.094659090 CET | 8.8.8.8 | 192.168.2.15 | 0x5c31 | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:37:57.729408026 CET | 8.8.8.8 | 192.168.2.15 | 0x4208 | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:38:06.273427010 CET | 8.8.8.8 | 192.168.2.15 | 0xcc15 | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:38:08.819011927 CET | 8.8.8.8 | 192.168.2.15 | 0x24c3 | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:38:14.370867014 CET | 8.8.8.8 | 192.168.2.15 | 0xdd3 | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:38:17.951421022 CET | 8.8.8.8 | 192.168.2.15 | 0x9cd0 | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:38:20.507096052 CET | 8.8.8.8 | 192.168.2.15 | 0xab32 | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:38:30.051981926 CET | 8.8.8.8 | 192.168.2.15 | 0xe5df | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:38:40.694819927 CET | 8.8.8.8 | 192.168.2.15 | 0xd712 | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:38:49.234888077 CET | 8.8.8.8 | 192.168.2.15 | 0x5a52 | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:38:59.776002884 CET | 8.8.8.8 | 192.168.2.15 | 0xe0c2 | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:39:05.419760942 CET | 8.8.8.8 | 192.168.2.15 | 0xcc1d | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:39:09.066337109 CET | 8.8.8.8 | 192.168.2.15 | 0x2a2d | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:39:14.667474031 CET | 8.8.8.8 | 192.168.2.15 | 0xeebb | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:39:17.223217010 CET | 8.8.8.8 | 192.168.2.15 | 0x92e8 | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 20:39:19.783061981 CET | 8.8.8.8 | 192.168.2.15 | 0x486f | No error (0) | 45.133.74.89 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 19:37:23 |
Start date (UTC): | 14/01/2025 |
Path: | /tmp/bot.x86.elf |
Arguments: | /tmp/bot.x86.elf |
File size: | 89576 bytes |
MD5 hash: | 73e9f8adef7a11c9ef8cb1f04e3515b8 |
Start time (UTC): | 19:37:23 |
Start date (UTC): | 14/01/2025 |
Path: | /tmp/bot.x86.elf |
Arguments: | - |
File size: | 89576 bytes |
MD5 hash: | 73e9f8adef7a11c9ef8cb1f04e3515b8 |
Start time (UTC): | 19:37:23 |
Start date (UTC): | 14/01/2025 |
Path: | /tmp/bot.x86.elf |
Arguments: | - |
File size: | 89576 bytes |
MD5 hash: | 73e9f8adef7a11c9ef8cb1f04e3515b8 |