Linux
Analysis Report
zermpsl.elf
Overview
General Information
Detection
Score: | 52 |
Range: | 0 - 100 |
Signatures
Multi AV Scanner detection for submitted file
Sends malformed DNS queries
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1628748 |
Start date and time: | 2025-03-04 04:23:07 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 33s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | zermpsl.elf |
Detection: | MAL |
Classification: | mal52.troj.linELF@0/0@29/0 |
Command: | /tmp/zermpsl.elf |
PID: | 6212 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | gosh that chinese family at the other table sure ate a lot |
Standard Error: |
- system is lnxubuntu20
- zermpsl.elf New Fork (PID: 6214, Parent: 6212)
- zermpsl.elf New Fork (PID: 6216, Parent: 6214)
- cleanup
⊘No yara matches
⊘No Suricata rule has matched
- • AV Detection
- • Networking
- • System Summary
- • Malware Analysis System Evasion
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Networking |
---|
Source: | DNS traffic detected: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | .symtab present: |
Source: | Classification label: |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | Direct Volume Access | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 2 Application Layer Protocol | Traffic Duplication | Data Destruction |
⊘No configs have been found
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
25% | Virustotal | Browse | ||
34% | ReversingLabs | Linux.Backdoor.Mirai |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
watchmepull.dyn | 45.147.251.145 | true | false | high | |
ohlookthereismyboats.geek | 185.159.74.127 | true | false | high | |
watchmepull.dyn. [malformed] | unknown | unknown | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
46.19.143.10 | unknown | Switzerland | 51852 | PLI-ASCH | false | |
1.2.3.4 | unknown | Australia | 13335 | CLOUDFLARENETUS | false | |
185.159.74.127 | ohlookthereismyboats.geek | Georgia | 59447 | SAYFANETTR | false | |
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
91.189.91.43 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
45.147.251.145 | watchmepull.dyn | Germany | 197518 | RACKMARKTES | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
46.19.143.10 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
1.2.3.4 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Okiru | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Okiru | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | AveMaria, UACMe | Browse | |||
Get hash | malicious | Metasploit | Browse | |||
Get hash | malicious | AveMaria, PrivateLoader, UACMe | Browse | |||
185.159.74.127 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
109.202.202.202 | Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
ohlookthereismyboats.geek | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
PLI-ASCH | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Babadeda | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Amadey, LummaC Stealer, Stealc | Browse |
| ||
INIT7CH | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
SAYFANETTR | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 5.399832488579395 |
TrID: |
|
File name: | zermpsl.elf |
File size: | 68'500 bytes |
MD5: | 553506978318cd9eb7795d8bd63bcfc8 |
SHA1: | 5d6d356830abc1e434cb19d6d3ba9ebdb4e4ea57 |
SHA256: | 7fc62e1219ca209d36a0be4fbb500708aa1b06e47eef41d1d6b8f17e6ebf7db2 |
SHA512: | c15549a1ae128d5f890603d1b7a03132ee7ff6e9826d412ffb256fb74582ec131001e6e3fb06e006e0578a288af66b5005cbd3be5642353dd9826cf6cee94bf3 |
SSDEEP: | 1536:y0ReC9RimjXIfi9rDUcXttXLZIaxUPVvcqM:yxYRimjt/X+V |
TLSH: | 9263C615BB610EF7DCABCC3749B91B0529CCA51A21B92B36B934D82CF54B14F16E38B4 |
File Content Preview: | .ELF....................`.@.4...<.......4. ...(...............@...@.P...P...............T...T.E.T.E.|...\+..........Q.td...............................<...'!......'.......................<...'!... .........9'.. ........................<...'!.............9 |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 67900 |
Section Header Size: | 40 |
Number of Section Headers: | 15 |
Header String Table Index: | 14 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x400094 | 0x94 | 0x8c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x400120 | 0x120 | 0xf5e0 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x40f700 | 0xf700 | 0x5c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x40f760 | 0xf760 | 0x8f0 | 0x0 | 0x2 | A | 0 | 0 | 16 |
.ctors | PROGBITS | 0x450054 | 0x10054 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x45005c | 0x1005c | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.jcr | PROGBITS | 0x450064 | 0x10064 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data.rel.ro | PROGBITS | 0x450068 | 0x10068 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x450070 | 0x10070 | 0x320 | 0x0 | 0x3 | WA | 0 | 0 | 16 |
.got | PROGBITS | 0x450390 | 0x10390 | 0x540 | 0x4 | 0x10000003 | WAp | 0 | 0 | 16 |
.sbss | NOBITS | 0x4508d0 | 0x108d0 | 0x1c | 0x0 | 0x10000003 | WAp | 0 | 0 | 4 |
.bss | NOBITS | 0x4508f0 | 0x108d0 | 0x22c0 | 0x0 | 0x3 | WA | 0 | 0 | 16 |
.mdebug.abi32 | PROGBITS | 0xab0 | 0x108d0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0x108d0 | 0x69 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x400000 | 0x400000 | 0x10050 | 0x10050 | 5.4546 | 0x5 | R E | 0x10000 | .init .text .fini .rodata | |
LOAD | 0x10054 | 0x450054 | 0x450054 | 0x87c | 0x2b5c | 2.9684 | 0x6 | RW | 0x10000 | .ctors .dtors .jcr .data.rel.ro .data .got .sbss .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Download Network PCAP: filtered – full
- Total Packets: 83
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 4, 2025 04:23:45.264637947 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Mar 4, 2025 04:23:45.615936995 CET | 43796 | 1440 | 192.168.2.23 | 46.19.143.10 |
Mar 4, 2025 04:23:45.621231079 CET | 1440 | 43796 | 46.19.143.10 | 192.168.2.23 |
Mar 4, 2025 04:23:45.621292114 CET | 43796 | 1440 | 192.168.2.23 | 46.19.143.10 |
Mar 4, 2025 04:23:45.636694908 CET | 43796 | 1440 | 192.168.2.23 | 46.19.143.10 |
Mar 4, 2025 04:23:45.641814947 CET | 1440 | 43796 | 46.19.143.10 | 192.168.2.23 |
Mar 4, 2025 04:23:45.641899109 CET | 43796 | 1440 | 192.168.2.23 | 46.19.143.10 |
Mar 4, 2025 04:23:45.647006989 CET | 1440 | 43796 | 46.19.143.10 | 192.168.2.23 |
Mar 4, 2025 04:23:50.640038013 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Mar 4, 2025 04:23:51.919827938 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Mar 4, 2025 04:23:55.645914078 CET | 43796 | 1440 | 192.168.2.23 | 46.19.143.10 |
Mar 4, 2025 04:23:55.650996923 CET | 1440 | 43796 | 46.19.143.10 | 192.168.2.23 |
Mar 4, 2025 04:23:55.838150978 CET | 1440 | 43796 | 46.19.143.10 | 192.168.2.23 |
Mar 4, 2025 04:23:55.838835955 CET | 43796 | 1440 | 192.168.2.23 | 46.19.143.10 |
Mar 4, 2025 04:23:55.843924046 CET | 1440 | 43796 | 46.19.143.10 | 192.168.2.23 |
Mar 4, 2025 04:23:56.881902933 CET | 54354 | 1440 | 192.168.2.23 | 45.147.251.145 |
Mar 4, 2025 04:23:56.887026072 CET | 1440 | 54354 | 45.147.251.145 | 192.168.2.23 |
Mar 4, 2025 04:23:56.887109041 CET | 54354 | 1440 | 192.168.2.23 | 45.147.251.145 |
Mar 4, 2025 04:23:56.888246059 CET | 54354 | 1440 | 192.168.2.23 | 45.147.251.145 |
Mar 4, 2025 04:23:56.893228054 CET | 1440 | 54354 | 45.147.251.145 | 192.168.2.23 |
Mar 4, 2025 04:23:56.893295050 CET | 54354 | 1440 | 192.168.2.23 | 45.147.251.145 |
Mar 4, 2025 04:23:56.898490906 CET | 1440 | 54354 | 45.147.251.145 | 192.168.2.23 |
Mar 4, 2025 04:24:05.997880936 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Mar 4, 2025 04:24:07.569181919 CET | 1440 | 54354 | 45.147.251.145 | 192.168.2.23 |
Mar 4, 2025 04:24:07.569724083 CET | 54354 | 1440 | 192.168.2.23 | 45.147.251.145 |
Mar 4, 2025 04:24:07.574881077 CET | 1440 | 54354 | 45.147.251.145 | 192.168.2.23 |
Mar 4, 2025 04:24:08.683876038 CET | 54356 | 1440 | 192.168.2.23 | 45.147.251.145 |
Mar 4, 2025 04:24:08.688978910 CET | 1440 | 54356 | 45.147.251.145 | 192.168.2.23 |
Mar 4, 2025 04:24:08.689068079 CET | 54356 | 1440 | 192.168.2.23 | 45.147.251.145 |
Mar 4, 2025 04:24:08.690176964 CET | 54356 | 1440 | 192.168.2.23 | 45.147.251.145 |
Mar 4, 2025 04:24:08.695246935 CET | 1440 | 54356 | 45.147.251.145 | 192.168.2.23 |
Mar 4, 2025 04:24:08.695331097 CET | 54356 | 1440 | 192.168.2.23 | 45.147.251.145 |
Mar 4, 2025 04:24:08.700432062 CET | 1440 | 54356 | 45.147.251.145 | 192.168.2.23 |
Mar 4, 2025 04:24:16.236561060 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Mar 4, 2025 04:24:19.366619110 CET | 1440 | 54356 | 45.147.251.145 | 192.168.2.23 |
Mar 4, 2025 04:24:19.367366076 CET | 54356 | 1440 | 192.168.2.23 | 45.147.251.145 |
Mar 4, 2025 04:24:19.372503042 CET | 1440 | 54356 | 45.147.251.145 | 192.168.2.23 |
Mar 4, 2025 04:24:20.387672901 CET | 55314 | 1440 | 192.168.2.23 | 1.2.3.4 |
Mar 4, 2025 04:24:20.392779112 CET | 1440 | 55314 | 1.2.3.4 | 192.168.2.23 |
Mar 4, 2025 04:24:20.392838001 CET | 55314 | 1440 | 192.168.2.23 | 1.2.3.4 |
Mar 4, 2025 04:24:20.393778086 CET | 55314 | 1440 | 192.168.2.23 | 1.2.3.4 |
Mar 4, 2025 04:24:20.399561882 CET | 1440 | 55314 | 1.2.3.4 | 192.168.2.23 |
Mar 4, 2025 04:24:20.399610043 CET | 55314 | 1440 | 192.168.2.23 | 1.2.3.4 |
Mar 4, 2025 04:24:20.405636072 CET | 1440 | 55314 | 1.2.3.4 | 192.168.2.23 |
Mar 4, 2025 04:24:22.379681110 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Mar 4, 2025 04:24:41.750277042 CET | 1440 | 55314 | 1.2.3.4 | 192.168.2.23 |
Mar 4, 2025 04:24:41.750684023 CET | 55314 | 1440 | 192.168.2.23 | 1.2.3.4 |
Mar 4, 2025 04:24:41.755738974 CET | 1440 | 55314 | 1.2.3.4 | 192.168.2.23 |
Mar 4, 2025 04:24:42.862350941 CET | 55316 | 1440 | 192.168.2.23 | 1.2.3.4 |
Mar 4, 2025 04:24:42.867403984 CET | 1440 | 55316 | 1.2.3.4 | 192.168.2.23 |
Mar 4, 2025 04:24:42.867508888 CET | 55316 | 1440 | 192.168.2.23 | 1.2.3.4 |
Mar 4, 2025 04:24:42.868853092 CET | 55316 | 1440 | 192.168.2.23 | 1.2.3.4 |
Mar 4, 2025 04:24:42.873846054 CET | 1440 | 55316 | 1.2.3.4 | 192.168.2.23 |
Mar 4, 2025 04:24:42.873941898 CET | 55316 | 1440 | 192.168.2.23 | 1.2.3.4 |
Mar 4, 2025 04:24:42.878993034 CET | 1440 | 55316 | 1.2.3.4 | 192.168.2.23 |
Mar 4, 2025 04:24:46.952383041 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Mar 4, 2025 04:25:02.886472940 CET | 55316 | 1440 | 192.168.2.23 | 1.2.3.4 |
Mar 4, 2025 04:25:02.891669989 CET | 1440 | 55316 | 1.2.3.4 | 192.168.2.23 |
Mar 4, 2025 04:25:04.346463919 CET | 1440 | 55316 | 1.2.3.4 | 192.168.2.23 |
Mar 4, 2025 04:25:04.346944094 CET | 55316 | 1440 | 192.168.2.23 | 1.2.3.4 |
Mar 4, 2025 04:25:04.352158070 CET | 1440 | 55316 | 1.2.3.4 | 192.168.2.23 |
Mar 4, 2025 04:25:05.388782024 CET | 45814 | 1440 | 192.168.2.23 | 185.159.74.127 |
Mar 4, 2025 04:25:05.395380020 CET | 1440 | 45814 | 185.159.74.127 | 192.168.2.23 |
Mar 4, 2025 04:25:05.395479918 CET | 45814 | 1440 | 192.168.2.23 | 185.159.74.127 |
Mar 4, 2025 04:25:05.396769047 CET | 45814 | 1440 | 192.168.2.23 | 185.159.74.127 |
Mar 4, 2025 04:25:05.401880980 CET | 1440 | 45814 | 185.159.74.127 | 192.168.2.23 |
Mar 4, 2025 04:25:05.401957989 CET | 45814 | 1440 | 192.168.2.23 | 185.159.74.127 |
Mar 4, 2025 04:25:05.407037020 CET | 1440 | 45814 | 185.159.74.127 | 192.168.2.23 |
Mar 4, 2025 04:25:07.429635048 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Mar 4, 2025 04:25:16.227961063 CET | 1440 | 45814 | 185.159.74.127 | 192.168.2.23 |
Mar 4, 2025 04:25:16.228337049 CET | 45814 | 1440 | 192.168.2.23 | 185.159.74.127 |
Mar 4, 2025 04:25:16.233546972 CET | 1440 | 45814 | 185.159.74.127 | 192.168.2.23 |
Mar 4, 2025 04:25:17.394757986 CET | 45816 | 1440 | 192.168.2.23 | 185.159.74.127 |
Mar 4, 2025 04:25:17.399728060 CET | 1440 | 45816 | 185.159.74.127 | 192.168.2.23 |
Mar 4, 2025 04:25:17.399827957 CET | 45816 | 1440 | 192.168.2.23 | 185.159.74.127 |
Mar 4, 2025 04:25:17.400983095 CET | 45816 | 1440 | 192.168.2.23 | 185.159.74.127 |
Mar 4, 2025 04:25:17.406353951 CET | 1440 | 45816 | 185.159.74.127 | 192.168.2.23 |
Mar 4, 2025 04:25:17.406416893 CET | 45816 | 1440 | 192.168.2.23 | 185.159.74.127 |
Mar 4, 2025 04:25:17.411451101 CET | 1440 | 45816 | 185.159.74.127 | 192.168.2.23 |
Mar 4, 2025 04:25:28.185225964 CET | 1440 | 45816 | 185.159.74.127 | 192.168.2.23 |
Mar 4, 2025 04:25:28.185452938 CET | 45816 | 1440 | 192.168.2.23 | 185.159.74.127 |
Mar 4, 2025 04:25:28.190450907 CET | 1440 | 45816 | 185.159.74.127 | 192.168.2.23 |
Mar 4, 2025 04:25:29.275648117 CET | 45818 | 1440 | 192.168.2.23 | 185.159.74.127 |
Mar 4, 2025 04:25:29.280642033 CET | 1440 | 45818 | 185.159.74.127 | 192.168.2.23 |
Mar 4, 2025 04:25:29.280728102 CET | 45818 | 1440 | 192.168.2.23 | 185.159.74.127 |
Mar 4, 2025 04:25:29.281985044 CET | 45818 | 1440 | 192.168.2.23 | 185.159.74.127 |
Mar 4, 2025 04:25:29.286936045 CET | 1440 | 45818 | 185.159.74.127 | 192.168.2.23 |
Mar 4, 2025 04:25:29.286993980 CET | 45818 | 1440 | 192.168.2.23 | 185.159.74.127 |
Mar 4, 2025 04:25:29.295506001 CET | 1440 | 45818 | 185.159.74.127 | 192.168.2.23 |
Mar 4, 2025 04:25:40.233788967 CET | 1440 | 45818 | 185.159.74.127 | 192.168.2.23 |
Mar 4, 2025 04:25:40.233963966 CET | 45818 | 1440 | 192.168.2.23 | 185.159.74.127 |
Mar 4, 2025 04:25:40.239067078 CET | 1440 | 45818 | 185.159.74.127 | 192.168.2.23 |
Mar 4, 2025 04:25:41.400127888 CET | 45820 | 1440 | 192.168.2.23 | 185.159.74.127 |
Mar 4, 2025 04:25:41.405113935 CET | 1440 | 45820 | 185.159.74.127 | 192.168.2.23 |
Mar 4, 2025 04:25:41.405215025 CET | 45820 | 1440 | 192.168.2.23 | 185.159.74.127 |
Mar 4, 2025 04:25:41.406207085 CET | 45820 | 1440 | 192.168.2.23 | 185.159.74.127 |
Mar 4, 2025 04:25:41.411240101 CET | 1440 | 45820 | 185.159.74.127 | 192.168.2.23 |
Mar 4, 2025 04:25:41.411348104 CET | 45820 | 1440 | 192.168.2.23 | 185.159.74.127 |
Mar 4, 2025 04:25:41.416418076 CET | 1440 | 45820 | 185.159.74.127 | 192.168.2.23 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 4, 2025 04:23:45.580935955 CET | 39920 | 53 | 192.168.2.23 | 194.36.144.87 |
Mar 4, 2025 04:23:45.597963095 CET | 53 | 39920 | 194.36.144.87 | 192.168.2.23 |
Mar 4, 2025 04:23:56.843179941 CET | 48929 | 53 | 192.168.2.23 | 185.181.61.24 |
Mar 4, 2025 04:23:56.880934000 CET | 53 | 48929 | 185.181.61.24 | 192.168.2.23 |
Mar 4, 2025 04:24:08.572531939 CET | 55840 | 53 | 192.168.2.23 | 152.53.15.127 |
Mar 4, 2025 04:24:08.595964909 CET | 53 | 55840 | 152.53.15.127 | 192.168.2.23 |
Mar 4, 2025 04:24:08.597537994 CET | 40847 | 53 | 192.168.2.23 | 152.53.15.127 |
Mar 4, 2025 04:24:08.615211010 CET | 53 | 40847 | 152.53.15.127 | 192.168.2.23 |
Mar 4, 2025 04:24:08.616576910 CET | 52798 | 53 | 192.168.2.23 | 152.53.15.127 |
Mar 4, 2025 04:24:08.640011072 CET | 53 | 52798 | 152.53.15.127 | 192.168.2.23 |
Mar 4, 2025 04:24:08.641542912 CET | 38884 | 53 | 192.168.2.23 | 152.53.15.127 |
Mar 4, 2025 04:24:08.659006119 CET | 53 | 38884 | 152.53.15.127 | 192.168.2.23 |
Mar 4, 2025 04:24:08.660053015 CET | 45228 | 53 | 192.168.2.23 | 152.53.15.127 |
Mar 4, 2025 04:24:08.683060884 CET | 53 | 45228 | 152.53.15.127 | 192.168.2.23 |
Mar 4, 2025 04:24:20.370914936 CET | 37245 | 53 | 192.168.2.23 | 51.158.108.203 |
Mar 4, 2025 04:24:20.386893988 CET | 53 | 37245 | 51.158.108.203 | 192.168.2.23 |
Mar 4, 2025 04:24:42.754529953 CET | 38579 | 53 | 192.168.2.23 | 152.53.15.127 |
Mar 4, 2025 04:24:42.778753042 CET | 53 | 38579 | 152.53.15.127 | 192.168.2.23 |
Mar 4, 2025 04:24:42.780580044 CET | 39775 | 53 | 192.168.2.23 | 152.53.15.127 |
Mar 4, 2025 04:24:42.798054934 CET | 53 | 39775 | 152.53.15.127 | 192.168.2.23 |
Mar 4, 2025 04:24:42.799680948 CET | 54172 | 53 | 192.168.2.23 | 152.53.15.127 |
Mar 4, 2025 04:24:42.823007107 CET | 53 | 54172 | 152.53.15.127 | 192.168.2.23 |
Mar 4, 2025 04:24:42.824724913 CET | 51788 | 53 | 192.168.2.23 | 152.53.15.127 |
Mar 4, 2025 04:24:42.842022896 CET | 53 | 51788 | 152.53.15.127 | 192.168.2.23 |
Mar 4, 2025 04:24:42.843501091 CET | 57330 | 53 | 192.168.2.23 | 152.53.15.127 |
Mar 4, 2025 04:24:42.861534119 CET | 53 | 57330 | 152.53.15.127 | 192.168.2.23 |
Mar 4, 2025 04:25:05.350292921 CET | 34280 | 53 | 192.168.2.23 | 185.181.61.24 |
Mar 4, 2025 04:25:05.387885094 CET | 53 | 34280 | 185.181.61.24 | 192.168.2.23 |
Mar 4, 2025 04:25:17.231015921 CET | 55197 | 53 | 192.168.2.23 | 81.169.136.222 |
Mar 4, 2025 04:25:17.262423992 CET | 53 | 55197 | 81.169.136.222 | 192.168.2.23 |
Mar 4, 2025 04:25:17.263605118 CET | 59868 | 53 | 192.168.2.23 | 81.169.136.222 |
Mar 4, 2025 04:25:17.294959068 CET | 53 | 59868 | 81.169.136.222 | 192.168.2.23 |
Mar 4, 2025 04:25:17.295811892 CET | 43318 | 53 | 192.168.2.23 | 81.169.136.222 |
Mar 4, 2025 04:25:17.327111006 CET | 53 | 43318 | 81.169.136.222 | 192.168.2.23 |
Mar 4, 2025 04:25:17.328186989 CET | 36324 | 53 | 192.168.2.23 | 81.169.136.222 |
Mar 4, 2025 04:25:17.361453056 CET | 53 | 36324 | 81.169.136.222 | 192.168.2.23 |
Mar 4, 2025 04:25:17.362623930 CET | 39208 | 53 | 192.168.2.23 | 81.169.136.222 |
Mar 4, 2025 04:25:17.394045115 CET | 53 | 39208 | 81.169.136.222 | 192.168.2.23 |
Mar 4, 2025 04:25:29.189094067 CET | 50659 | 53 | 192.168.2.23 | 51.158.108.203 |
Mar 4, 2025 04:25:29.205159903 CET | 53 | 50659 | 51.158.108.203 | 192.168.2.23 |
Mar 4, 2025 04:25:29.206897020 CET | 39849 | 53 | 192.168.2.23 | 51.158.108.203 |
Mar 4, 2025 04:25:29.222845078 CET | 53 | 39849 | 51.158.108.203 | 192.168.2.23 |
Mar 4, 2025 04:25:29.224567890 CET | 34728 | 53 | 192.168.2.23 | 51.158.108.203 |
Mar 4, 2025 04:25:29.240294933 CET | 53 | 34728 | 51.158.108.203 | 192.168.2.23 |
Mar 4, 2025 04:25:29.242007017 CET | 55819 | 53 | 192.168.2.23 | 51.158.108.203 |
Mar 4, 2025 04:25:29.257641077 CET | 53 | 55819 | 51.158.108.203 | 192.168.2.23 |
Mar 4, 2025 04:25:29.259242058 CET | 59366 | 53 | 192.168.2.23 | 51.158.108.203 |
Mar 4, 2025 04:25:29.274979115 CET | 53 | 59366 | 51.158.108.203 | 192.168.2.23 |
Mar 4, 2025 04:25:41.236815929 CET | 38161 | 53 | 192.168.2.23 | 81.169.136.222 |
Mar 4, 2025 04:25:41.268102884 CET | 53 | 38161 | 81.169.136.222 | 192.168.2.23 |
Mar 4, 2025 04:25:41.269634962 CET | 52402 | 53 | 192.168.2.23 | 81.169.136.222 |
Mar 4, 2025 04:25:41.300932884 CET | 53 | 52402 | 81.169.136.222 | 192.168.2.23 |
Mar 4, 2025 04:25:41.302401066 CET | 33884 | 53 | 192.168.2.23 | 81.169.136.222 |
Mar 4, 2025 04:25:41.333853960 CET | 53 | 33884 | 81.169.136.222 | 192.168.2.23 |
Mar 4, 2025 04:25:41.335120916 CET | 57670 | 53 | 192.168.2.23 | 81.169.136.222 |
Mar 4, 2025 04:25:41.366358042 CET | 53 | 57670 | 81.169.136.222 | 192.168.2.23 |
Mar 4, 2025 04:25:41.367847919 CET | 57177 | 53 | 192.168.2.23 | 81.169.136.222 |
Mar 4, 2025 04:25:41.399152040 CET | 53 | 57177 | 81.169.136.222 | 192.168.2.23 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Mar 4, 2025 04:23:45.580935955 CET | 192.168.2.23 | 194.36.144.87 | 0xab03 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 4, 2025 04:23:56.843179941 CET | 192.168.2.23 | 185.181.61.24 | 0x6699 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 4, 2025 04:24:08.572531939 CET | 192.168.2.23 | 152.53.15.127 | 0x9e97 | Standard query (0) | 256 | 344 | false | |
Mar 4, 2025 04:24:08.597537994 CET | 192.168.2.23 | 152.53.15.127 | 0x9e97 | Standard query (0) | 256 | 344 | false | |
Mar 4, 2025 04:24:08.616576910 CET | 192.168.2.23 | 152.53.15.127 | 0x9e97 | Standard query (0) | 256 | 344 | false | |
Mar 4, 2025 04:24:08.641542912 CET | 192.168.2.23 | 152.53.15.127 | 0x9e97 | Standard query (0) | 256 | 344 | false | |
Mar 4, 2025 04:24:08.660053015 CET | 192.168.2.23 | 152.53.15.127 | 0x9e97 | Standard query (0) | 256 | 344 | false | |
Mar 4, 2025 04:24:20.370914936 CET | 192.168.2.23 | 51.158.108.203 | 0x93a8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 4, 2025 04:24:42.754529953 CET | 192.168.2.23 | 152.53.15.127 | 0x759b | Standard query (0) | 256 | 378 | false | |
Mar 4, 2025 04:24:42.780580044 CET | 192.168.2.23 | 152.53.15.127 | 0x759b | Standard query (0) | 256 | 378 | false | |
Mar 4, 2025 04:24:42.799680948 CET | 192.168.2.23 | 152.53.15.127 | 0x759b | Standard query (0) | 256 | 378 | false | |
Mar 4, 2025 04:24:42.824724913 CET | 192.168.2.23 | 152.53.15.127 | 0x759b | Standard query (0) | 256 | 378 | false | |
Mar 4, 2025 04:24:42.843501091 CET | 192.168.2.23 | 152.53.15.127 | 0x759b | Standard query (0) | 256 | 378 | false | |
Mar 4, 2025 04:25:05.350292921 CET | 192.168.2.23 | 185.181.61.24 | 0x55e9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 4, 2025 04:25:17.231015921 CET | 192.168.2.23 | 81.169.136.222 | 0xdd27 | Standard query (0) | 256 | 413 | false | |
Mar 4, 2025 04:25:17.263605118 CET | 192.168.2.23 | 81.169.136.222 | 0xdd27 | Standard query (0) | 256 | 413 | false | |
Mar 4, 2025 04:25:17.295811892 CET | 192.168.2.23 | 81.169.136.222 | 0xdd27 | Standard query (0) | 256 | 413 | false | |
Mar 4, 2025 04:25:17.328186989 CET | 192.168.2.23 | 81.169.136.222 | 0xdd27 | Standard query (0) | 256 | 413 | false | |
Mar 4, 2025 04:25:17.362623930 CET | 192.168.2.23 | 81.169.136.222 | 0xdd27 | Standard query (0) | 256 | 413 | false | |
Mar 4, 2025 04:25:29.189094067 CET | 192.168.2.23 | 51.158.108.203 | 0x9729 | Standard query (0) | 256 | 425 | false | |
Mar 4, 2025 04:25:29.206897020 CET | 192.168.2.23 | 51.158.108.203 | 0x9729 | Standard query (0) | 256 | 425 | false | |
Mar 4, 2025 04:25:29.224567890 CET | 192.168.2.23 | 51.158.108.203 | 0x9729 | Standard query (0) | 256 | 425 | false | |
Mar 4, 2025 04:25:29.242007017 CET | 192.168.2.23 | 51.158.108.203 | 0x9729 | Standard query (0) | 256 | 425 | false | |
Mar 4, 2025 04:25:29.259242058 CET | 192.168.2.23 | 51.158.108.203 | 0x9729 | Standard query (0) | 256 | 425 | false | |
Mar 4, 2025 04:25:41.236815929 CET | 192.168.2.23 | 81.169.136.222 | 0x8c02 | Standard query (0) | 256 | 437 | false | |
Mar 4, 2025 04:25:41.269634962 CET | 192.168.2.23 | 81.169.136.222 | 0x8c02 | Standard query (0) | 256 | 437 | false | |
Mar 4, 2025 04:25:41.302401066 CET | 192.168.2.23 | 81.169.136.222 | 0x8c02 | Standard query (0) | 256 | 437 | false | |
Mar 4, 2025 04:25:41.335120916 CET | 192.168.2.23 | 81.169.136.222 | 0x8c02 | Standard query (0) | 256 | 437 | false | |
Mar 4, 2025 04:25:41.367847919 CET | 192.168.2.23 | 81.169.136.222 | 0x8c02 | Standard query (0) | 256 | 437 | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Mar 4, 2025 04:23:45.597963095 CET | 194.36.144.87 | 192.168.2.23 | 0xab03 | No error (0) | 45.147.251.145 | A (IP address) | IN (0x0001) | false | ||
Mar 4, 2025 04:23:45.597963095 CET | 194.36.144.87 | 192.168.2.23 | 0xab03 | No error (0) | 185.159.74.127 | A (IP address) | IN (0x0001) | false | ||
Mar 4, 2025 04:23:45.597963095 CET | 194.36.144.87 | 192.168.2.23 | 0xab03 | No error (0) | 46.19.143.10 | A (IP address) | IN (0x0001) | false | ||
Mar 4, 2025 04:23:56.880934000 CET | 185.181.61.24 | 192.168.2.23 | 0x6699 | No error (0) | 185.159.74.127 | A (IP address) | IN (0x0001) | false | ||
Mar 4, 2025 04:23:56.880934000 CET | 185.181.61.24 | 192.168.2.23 | 0x6699 | No error (0) | 45.147.251.145 | A (IP address) | IN (0x0001) | false | ||
Mar 4, 2025 04:23:56.880934000 CET | 185.181.61.24 | 192.168.2.23 | 0x6699 | No error (0) | 46.19.143.10 | A (IP address) | IN (0x0001) | false | ||
Mar 4, 2025 04:24:08.595964909 CET | 152.53.15.127 | 192.168.2.23 | 0x9e97 | Format error (1) | none | none | 256 | 344 | false | |
Mar 4, 2025 04:24:08.615211010 CET | 152.53.15.127 | 192.168.2.23 | 0x9e97 | Format error (1) | none | none | 256 | 344 | false | |
Mar 4, 2025 04:24:08.640011072 CET | 152.53.15.127 | 192.168.2.23 | 0x9e97 | Format error (1) | none | none | 256 | 344 | false | |
Mar 4, 2025 04:24:08.659006119 CET | 152.53.15.127 | 192.168.2.23 | 0x9e97 | Format error (1) | none | none | 256 | 344 | false | |
Mar 4, 2025 04:24:08.683060884 CET | 152.53.15.127 | 192.168.2.23 | 0x9e97 | Format error (1) | none | none | 256 | 344 | false | |
Mar 4, 2025 04:24:20.386893988 CET | 51.158.108.203 | 192.168.2.23 | 0x93a8 | No error (0) | 1.2.3.4 | A (IP address) | IN (0x0001) | false | ||
Mar 4, 2025 04:24:42.778753042 CET | 152.53.15.127 | 192.168.2.23 | 0x759b | Format error (1) | none | none | 256 | 378 | false | |
Mar 4, 2025 04:24:42.798054934 CET | 152.53.15.127 | 192.168.2.23 | 0x759b | Format error (1) | none | none | 256 | 378 | false | |
Mar 4, 2025 04:24:42.823007107 CET | 152.53.15.127 | 192.168.2.23 | 0x759b | Format error (1) | none | none | 256 | 378 | false | |
Mar 4, 2025 04:24:42.842022896 CET | 152.53.15.127 | 192.168.2.23 | 0x759b | Format error (1) | none | none | 256 | 378 | false | |
Mar 4, 2025 04:24:42.861534119 CET | 152.53.15.127 | 192.168.2.23 | 0x759b | Format error (1) | none | none | 256 | 378 | false | |
Mar 4, 2025 04:25:05.387885094 CET | 185.181.61.24 | 192.168.2.23 | 0x55e9 | No error (0) | 185.159.74.127 | A (IP address) | IN (0x0001) | false | ||
Mar 4, 2025 04:25:05.387885094 CET | 185.181.61.24 | 192.168.2.23 | 0x55e9 | No error (0) | 46.19.143.10 | A (IP address) | IN (0x0001) | false | ||
Mar 4, 2025 04:25:05.387885094 CET | 185.181.61.24 | 192.168.2.23 | 0x55e9 | No error (0) | 45.147.251.145 | A (IP address) | IN (0x0001) | false | ||
Mar 4, 2025 04:25:29.205159903 CET | 51.158.108.203 | 192.168.2.23 | 0x9729 | Format error (1) | none | none | 256 | 425 | false | |
Mar 4, 2025 04:25:29.222845078 CET | 51.158.108.203 | 192.168.2.23 | 0x9729 | Format error (1) | none | none | 256 | 425 | false | |
Mar 4, 2025 04:25:29.240294933 CET | 51.158.108.203 | 192.168.2.23 | 0x9729 | Format error (1) | none | none | 256 | 425 | false | |
Mar 4, 2025 04:25:29.257641077 CET | 51.158.108.203 | 192.168.2.23 | 0x9729 | Format error (1) | none | none | 256 | 425 | false | |
Mar 4, 2025 04:25:29.274979115 CET | 51.158.108.203 | 192.168.2.23 | 0x9729 | Format error (1) | none | none | 256 | 425 | false |
System Behavior
Start time (UTC): | 03:23:44 |
Start date (UTC): | 04/03/2025 |
Path: | /tmp/zermpsl.elf |
Arguments: | /tmp/zermpsl.elf |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 03:23:44 |
Start date (UTC): | 04/03/2025 |
Path: | /tmp/zermpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 03:23:44 |
Start date (UTC): | 04/03/2025 |
Path: | /tmp/zermpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |