Linux
Analysis Report
boatnet.spc.elf
Overview
General Information
Detection
Mirai
Score: | 76 |
Range: | 0 - 100 |
Signatures
Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Sample tries to kill multiple processes (SIGKILL)
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Sample tries to kill a process (SIGKILL)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match
Classification
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1642308 |
Start date and time: | 2025-03-19 01:51:44 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 3s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | boatnet.spc.elf |
Detection: | MAL |
Classification: | mal76.spre.troj.linELF@0/0@2/0 |
Command: | /tmp/boatnet.spc.elf |
PID: | 5457 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | lzrd cock fest"/proc/"/exe |
Standard Error: |
- system is lnxubuntu20
- boatnet.spc.elf New Fork (PID: 5459, Parent: 5457)
- boatnet.spc.elf New Fork (PID: 5460, Parent: 5457)
- boatnet.spc.elf New Fork (PID: 5463, Parent: 5457)
- xfce4-panel New Fork (PID: 5467, Parent: 3147)
- xfce4-panel New Fork (PID: 5468, Parent: 3147)
- xfce4-panel New Fork (PID: 5469, Parent: 3147)
- xfce4-panel New Fork (PID: 5470, Parent: 3147)
- xfce4-panel New Fork (PID: 5471, Parent: 3147)
- xfce4-panel New Fork (PID: 5472, Parent: 3147)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Mirai | Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
Linux_Trojan_Gafgyt_ea92cca8 | unknown | unknown |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
Linux_Trojan_Gafgyt_ea92cca8 | unknown | unknown |
| |
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
Linux_Trojan_Gafgyt_28a2fe0c | unknown | unknown |
| |
Click to see the 7 entries |
⊘No Suricata rule has matched
- • AV Detection
- • Networking
- • System Summary
- • Persistence and Installation Behavior
- • Malware Analysis System Evasion
- • Stealing of Sensitive Information
- • Remote Access Functionality
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior |
Source: | .symtab present: |
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | Direct Volume Access | 1 OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Non-Standard Port | Exfiltration Over Other Network Medium | 1 Service Stop |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
64% | Virustotal | Browse | ||
73% | ReversingLabs | Linux.Backdoor.Mirai | ||
100% | Avira | EXP/ELF.Gafgyt.D |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
daisy.ubuntu.com | 162.213.35.25 | true | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
209.141.59.9 | unknown | United States | 53667 | PONYNETUS | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
209.141.59.9 | Get hash | malicious | Mirai | Browse | ||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
daisy.ubuntu.com | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
PONYNETUS | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | ScreenConnect Tool | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 6.066283632806456 |
TrID: |
|
File name: | boatnet.spc.elf |
File size: | 58'376 bytes |
MD5: | 8079ef3e397bdc16d6187d377fed7a23 |
SHA1: | 87d822df1bebdafd5009a2470c8b6a4de5bba405 |
SHA256: | c040aeb560b7156f4c635db4635a69d11ae46c791962708e420d4c899499908a |
SHA512: | 90bc6e9f9a1bde035c46e46ea27a0d2cd0a569783c9199d3d3c65191adb8091b21125732789c196fdf81c645239ce7e7e6ab29d84273e22d01dd8acad86d892c |
SSDEEP: | 768:RqowmZPu9wtnfbltWgC6BSJsBcfDSbFwuQKqgESnmC/xO+KpAw2:RqtmZPuutfbltZFBSJsBcfDSbFw+BE2 |
TLSH: | 9F432921B53A1F13D0E0A47D21FB4B59B1A15ADE26A4C64E7D720F4FFF11A80A943DB8 |
File Content Preview: | .ELF...........................4...x.....4. ...(.......................................................8...P........dt.Q................................@..(....@.2.................#.....b8..`.....!..... ...@.....".........`......$ ... ...@...........`.... |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 57976 |
Section Header Size: | 40 |
Number of Section Headers: | 10 |
Header String Table Index: | 9 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x10094 | 0x94 | 0x1c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x100b0 | 0xb0 | 0xc888 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.fini | PROGBITS | 0x1c938 | 0xc938 | 0x14 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x1c950 | 0xc950 | 0x11b0 | 0x0 | 0x2 | A | 0 | 0 | 8 |
.ctors | PROGBITS | 0x2e000 | 0xe000 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x2e008 | 0xe008 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x2e018 | 0xe018 | 0x220 | 0x0 | 0x3 | WA | 0 | 0 | 8 |
.bss | NOBITS | 0x2e238 | 0xe238 | 0x318 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.shstrtab | STRTAB | 0x0 | 0xe238 | 0x3e | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x10000 | 0x10000 | 0xdb00 | 0xdb00 | 6.1728 | 0x5 | R E | 0x10000 | .init .text .fini .rodata | |
LOAD | 0xe000 | 0x2e000 | 0x2e000 | 0x238 | 0x550 | 2.9229 | 0x6 | RW | 0x10000 | .ctors .dtors .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x4 |
Download Network PCAP: filtered – full
- Total Packets: 140
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 19, 2025 01:52:34.180566072 CET | 37600 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:34.185333014 CET | 3778 | 37600 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:34.185391903 CET | 37600 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:34.202043056 CET | 37600 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:34.206832886 CET | 3778 | 37600 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:34.206912041 CET | 37600 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:34.211596966 CET | 3778 | 37600 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:34.804344893 CET | 3778 | 37600 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:34.804572105 CET | 37600 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:34.804672003 CET | 37600 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:34.807125092 CET | 37602 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:34.811851978 CET | 3778 | 37602 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:34.811929941 CET | 37602 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:34.818361044 CET | 37602 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:34.823064089 CET | 3778 | 37602 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:34.823107958 CET | 37602 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:34.827975035 CET | 3778 | 37602 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:35.447367907 CET | 3778 | 37602 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:35.447719097 CET | 37602 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:35.447719097 CET | 37602 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:35.455053091 CET | 37604 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:35.459847927 CET | 3778 | 37604 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:35.459943056 CET | 37604 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:35.463150978 CET | 37604 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:35.469204903 CET | 3778 | 37604 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:35.469263077 CET | 37604 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:35.475631952 CET | 3778 | 37604 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:36.075026035 CET | 3778 | 37604 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:36.075124025 CET | 37604 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:36.075124025 CET | 37604 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:36.077174902 CET | 37606 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:36.081938982 CET | 3778 | 37606 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:36.082007885 CET | 37606 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:36.083972931 CET | 37606 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:36.088607073 CET | 3778 | 37606 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:36.088648081 CET | 37606 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:36.093311071 CET | 3778 | 37606 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:36.682610035 CET | 3778 | 37606 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:36.682730913 CET | 37606 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:36.682780027 CET | 37606 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:36.683621883 CET | 37608 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:36.688272953 CET | 3778 | 37608 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:36.688344955 CET | 37608 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:36.690073967 CET | 37608 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:36.694717884 CET | 3778 | 37608 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:36.694761992 CET | 37608 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:36.699373007 CET | 3778 | 37608 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:37.310252905 CET | 3778 | 37608 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:37.310420990 CET | 37608 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:37.310420990 CET | 37608 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:37.326659918 CET | 37610 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:37.331352949 CET | 3778 | 37610 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:37.331479073 CET | 37610 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:37.354990005 CET | 37610 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:37.359795094 CET | 3778 | 37610 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:37.359885931 CET | 37610 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:37.364594936 CET | 3778 | 37610 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:37.980901003 CET | 3778 | 37610 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:37.980973959 CET | 37610 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:37.981071949 CET | 37610 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:37.982147932 CET | 37612 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:37.986877918 CET | 3778 | 37612 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:37.986958981 CET | 37612 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:37.989502907 CET | 37612 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:37.994174957 CET | 3778 | 37612 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:37.994224072 CET | 37612 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:37.998985052 CET | 3778 | 37612 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:38.628134012 CET | 3778 | 37612 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:38.628217936 CET | 37612 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:38.628267050 CET | 37612 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:38.632338047 CET | 37614 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:38.637058020 CET | 3778 | 37614 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:38.637222052 CET | 37614 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:38.640084028 CET | 37614 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:38.644723892 CET | 3778 | 37614 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:38.644788980 CET | 37614 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:38.649415970 CET | 3778 | 37614 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:39.275722980 CET | 3778 | 37614 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:39.276027918 CET | 37614 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:39.276057959 CET | 37614 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:39.276688099 CET | 37616 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:39.281491995 CET | 3778 | 37616 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:39.281560898 CET | 37616 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:39.282963991 CET | 37616 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:39.287609100 CET | 3778 | 37616 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:39.287951946 CET | 37616 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:39.292587042 CET | 3778 | 37616 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:39.920280933 CET | 3778 | 37616 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:39.920383930 CET | 37616 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:39.920418978 CET | 37616 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:39.920999050 CET | 37618 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:39.925704002 CET | 3778 | 37618 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:39.925766945 CET | 37618 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:39.927774906 CET | 37618 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:39.932450056 CET | 3778 | 37618 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:39.932503939 CET | 37618 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:39.937191010 CET | 3778 | 37618 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:40.584908962 CET | 3778 | 37618 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:40.585086107 CET | 37618 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:40.585140944 CET | 37618 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:40.586136103 CET | 37620 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:40.591641903 CET | 3778 | 37620 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:40.591711998 CET | 37620 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:40.595896006 CET | 37620 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:40.600572109 CET | 3778 | 37620 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:40.600611925 CET | 37620 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:40.605217934 CET | 3778 | 37620 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:41.213855028 CET | 3778 | 37620 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:41.213932991 CET | 37620 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:41.214032888 CET | 37620 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:41.214613914 CET | 37622 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:41.219286919 CET | 3778 | 37622 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:41.219351053 CET | 37622 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:41.220825911 CET | 37622 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:41.225475073 CET | 3778 | 37622 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:41.225518942 CET | 37622 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:41.230210066 CET | 3778 | 37622 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:41.844624996 CET | 3778 | 37622 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:41.844754934 CET | 37622 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:41.844754934 CET | 37622 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:41.845707893 CET | 37624 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:41.850419044 CET | 3778 | 37624 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:41.850629091 CET | 37624 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:41.853339911 CET | 37624 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:41.859194040 CET | 3778 | 37624 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:41.859766960 CET | 37624 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:41.864588022 CET | 3778 | 37624 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:42.490737915 CET | 3778 | 37624 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:42.490802050 CET | 37624 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:42.490844011 CET | 37624 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:42.491744995 CET | 37626 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:42.496450901 CET | 3778 | 37626 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:42.496654987 CET | 37626 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:42.498461008 CET | 37626 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:42.503071070 CET | 3778 | 37626 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:42.503120899 CET | 37626 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:42.507742882 CET | 3778 | 37626 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:43.099530935 CET | 3778 | 37626 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:43.102397919 CET | 37626 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:43.102435112 CET | 37626 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:43.110393047 CET | 37628 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:43.115078926 CET | 3778 | 37628 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:43.115147114 CET | 37628 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:43.116590023 CET | 37628 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:43.121210098 CET | 3778 | 37628 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:43.121282101 CET | 37628 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:43.125977993 CET | 3778 | 37628 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:43.762913942 CET | 3778 | 37628 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:43.763047934 CET | 37628 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:43.763083935 CET | 37628 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:43.768670082 CET | 37630 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:43.773375988 CET | 3778 | 37630 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:43.773432016 CET | 37630 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:43.785526991 CET | 37630 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:43.790196896 CET | 3778 | 37630 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:43.794477940 CET | 37630 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:43.799166918 CET | 3778 | 37630 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:44.423548937 CET | 3778 | 37630 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:44.423650026 CET | 37630 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:44.423677921 CET | 37630 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:44.424372911 CET | 37632 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:44.429054976 CET | 3778 | 37632 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:44.429214954 CET | 37632 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:44.430324078 CET | 37632 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:44.434948921 CET | 3778 | 37632 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:44.434998989 CET | 37632 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:44.439624071 CET | 3778 | 37632 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:45.023637056 CET | 3778 | 37632 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:45.023782969 CET | 37632 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:45.023833036 CET | 37632 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:45.024496078 CET | 37634 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:45.029186964 CET | 3778 | 37634 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:45.029306889 CET | 37634 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:45.030213118 CET | 37634 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:45.034862041 CET | 3778 | 37634 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:45.034933090 CET | 37634 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:45.039587975 CET | 3778 | 37634 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:45.668524981 CET | 3778 | 37634 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:45.668651104 CET | 37634 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:45.668693066 CET | 37634 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:45.669187069 CET | 37636 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:45.673938990 CET | 3778 | 37636 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:45.674015045 CET | 37636 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:45.674792051 CET | 37636 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:45.679403067 CET | 3778 | 37636 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:45.679449081 CET | 37636 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:45.684168100 CET | 3778 | 37636 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:46.342468977 CET | 3778 | 37636 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:46.342573881 CET | 37636 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:46.342612028 CET | 37636 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:46.343144894 CET | 37638 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:46.347760916 CET | 3778 | 37638 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:46.347814083 CET | 37638 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:46.348555088 CET | 37638 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:46.353230953 CET | 3778 | 37638 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:46.353286982 CET | 37638 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:46.357944965 CET | 3778 | 37638 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:47.007317066 CET | 3778 | 37638 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:47.007437944 CET | 37638 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:47.007496119 CET | 37638 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:47.008280039 CET | 37640 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:47.012981892 CET | 3778 | 37640 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:47.013035059 CET | 37640 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:47.014592886 CET | 37640 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:47.019311905 CET | 3778 | 37640 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:47.019357920 CET | 37640 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:47.024077892 CET | 3778 | 37640 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:47.614001989 CET | 3778 | 37640 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:47.614141941 CET | 37640 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:47.614234924 CET | 37640 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:47.615632057 CET | 37642 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:47.620367050 CET | 3778 | 37642 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:47.620465994 CET | 37642 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:47.621524096 CET | 37642 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:47.626132011 CET | 3778 | 37642 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:47.626188993 CET | 37642 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:47.630886078 CET | 3778 | 37642 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:57.631000996 CET | 37642 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:52:57.635756969 CET | 3778 | 37642 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:57.796569109 CET | 3778 | 37642 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:52:57.796694040 CET | 37642 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:53:57.844885111 CET | 37642 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:53:57.849661112 CET | 3778 | 37642 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:53:58.013434887 CET | 3778 | 37642 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:53:58.013746023 CET | 37642 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:54:58.060718060 CET | 37642 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:54:58.065581083 CET | 3778 | 37642 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:54:58.227781057 CET | 3778 | 37642 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:54:58.227844954 CET | 37642 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:55:58.276443005 CET | 37642 | 3778 | 192.168.2.13 | 209.141.59.9 |
Mar 19, 2025 01:55:58.281569958 CET | 3778 | 37642 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:55:58.446180105 CET | 3778 | 37642 | 209.141.59.9 | 192.168.2.13 |
Mar 19, 2025 01:55:58.446338892 CET | 37642 | 3778 | 192.168.2.13 | 209.141.59.9 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 19, 2025 01:55:16.394879103 CET | 55858 | 53 | 192.168.2.13 | 8.8.8.8 |
Mar 19, 2025 01:55:16.395001888 CET | 59216 | 53 | 192.168.2.13 | 8.8.8.8 |
Mar 19, 2025 01:55:16.401256084 CET | 53 | 55858 | 8.8.8.8 | 192.168.2.13 |
Mar 19, 2025 01:55:16.401410103 CET | 53 | 59216 | 8.8.8.8 | 192.168.2.13 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Mar 19, 2025 01:55:16.394879103 CET | 192.168.2.13 | 8.8.8.8 | 0x6a1a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 19, 2025 01:55:16.395001888 CET | 192.168.2.13 | 8.8.8.8 | 0x10e1 | Standard query (0) | 28 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Mar 19, 2025 01:55:16.401256084 CET | 8.8.8.8 | 192.168.2.13 | 0x6a1a | No error (0) | 162.213.35.25 | A (IP address) | IN (0x0001) | false | ||
Mar 19, 2025 01:55:16.401256084 CET | 8.8.8.8 | 192.168.2.13 | 0x6a1a | No error (0) | 162.213.35.24 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 00:52:32 |
Start date (UTC): | 19/03/2025 |
Path: | /tmp/boatnet.spc.elf |
Arguments: | /tmp/boatnet.spc.elf |
File size: | 4379400 bytes |
MD5 hash: | 7dc1c0e23cd5e102bb12e5c29403410e |
Start time (UTC): | 00:52:32 |
Start date (UTC): | 19/03/2025 |
Path: | /tmp/boatnet.spc.elf |
Arguments: | - |
File size: | 4379400 bytes |
MD5 hash: | 7dc1c0e23cd5e102bb12e5c29403410e |
Start time (UTC): | 00:52:32 |
Start date (UTC): | 19/03/2025 |
Path: | /tmp/boatnet.spc.elf |
Arguments: | - |
File size: | 4379400 bytes |
MD5 hash: | 7dc1c0e23cd5e102bb12e5c29403410e |
Start time (UTC): | 00:52:32 |
Start date (UTC): | 19/03/2025 |
Path: | /tmp/boatnet.spc.elf |
Arguments: | - |
File size: | 4379400 bytes |
MD5 hash: | 7dc1c0e23cd5e102bb12e5c29403410e |
Start time (UTC): | 00:52:33 |
Start date (UTC): | 19/03/2025 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 00:52:33 |
Start date (UTC): | 19/03/2025 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 00:52:33 |
Start date (UTC): | 19/03/2025 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 00:52:33 |
Start date (UTC): | 19/03/2025 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 00:52:33 |
Start date (UTC): | 19/03/2025 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 00:52:33 |
Start date (UTC): | 19/03/2025 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 00:52:33 |
Start date (UTC): | 19/03/2025 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 00:52:33 |
Start date (UTC): | 19/03/2025 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 00:52:33 |
Start date (UTC): | 19/03/2025 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 00:52:33 |
Start date (UTC): | 19/03/2025 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |
Start time (UTC): | 00:52:33 |
Start date (UTC): | 19/03/2025 |
Path: | /usr/bin/xfce4-panel |
Arguments: | - |
File size: | 375768 bytes |
MD5 hash: | a15b657c7d54ac1385f1f15004ea6784 |
Start time (UTC): | 00:52:33 |
Start date (UTC): | 19/03/2025 |
Path: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 |
Arguments: | /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions" |
File size: | 35136 bytes |
MD5 hash: | ac0b8a906f359a8ae102244738682e76 |