Linux
Analysis Report
hiss.arm5.elf
Overview
General Information
Sample name: | hiss.arm5.elf |
Analysis ID: | 1643952 |
MD5: | d53d8286d70b3d24f69a3c00120fb859 |
SHA1: | e0ec269bb83f995c23d04f00af38e172abcaeae1 |
SHA256: | 68620c56f240a0020ef82de07c4c129b5c399c1bacc359ca20f9f29270198669 |
Tags: | elfMiraiuser-abuse_ch |
Infos: |
Detection
Score: | 52 |
Range: | 0 - 100 |
Signatures
Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Found strings indicative of a multi-platform dropper
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1643952 |
Start date and time: | 2025-03-20 09:46:03 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 47s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | hiss.arm5.elf |
Detection: | MAL |
Classification: | mal52.troj.linELF@0/1@29/0 |
- VT rate limit hit for: horse.ipcamlover.ru
Command: | /tmp/hiss.arm5.elf |
PID: | 6250 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | |
Standard Error: |
- system is lnxubuntu20
- hiss.arm5.elf New Fork (PID: 6252, Parent: 6250)
- hiss.arm5.elf New Fork (PID: 6253, Parent: 6250)
- hiss.arm5.elf New Fork (PID: 6256, Parent: 6250)
- dash New Fork (PID: 6318, Parent: 4331)
- dash New Fork (PID: 6319, Parent: 4331)
- cleanup
⊘No yara matches
⊘No Suricata rule has matched
- • AV Detection
- • Spreading
- • Networking
- • System Summary
- • Persistence and Installation Behavior
- • Malware Analysis System Evasion
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | String: |
Networking |
---|
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | .symtab present: |
Source: | Classification label: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | Windows Management Instrumentation | 1 Scripting | Path Interception | 1 File Deletion | 1 OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 2 Application Layer Protocol | Traffic Duplication | Data Destruction |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
14% | Virustotal | Browse | ||
17% | ReversingLabs | Linux.Backdoor.Mirai |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
horse.ipcamlover.ru | 77.232.42.137 | true | true | unknown | |
fish.dvrhelpers.su | 77.232.41.24 | true | false | unknown | |
dog.xlabsecurity.ru | 146.112.61.108 | true | false | unknown | |
kitty.xlabresearch.ru | unknown | unknown | false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
77.232.39.221 | unknown | Russian Federation | 28968 | EUT-ASEUTIPNetworkRU | false | |
77.232.41.24 | fish.dvrhelpers.su | Russian Federation | 28968 | EUT-ASEUTIPNetworkRU | false | |
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
91.142.78.22 | unknown | Russian Federation | 48720 | VTSL1-ASRU | false | |
34.249.145.219 | unknown | United States | 16509 | AMAZON-02US | false | |
91.189.91.43 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
77.232.42.137 | horse.ipcamlover.ru | Russian Federation | 28968 | EUT-ASEUTIPNetworkRU | true | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
34.249.145.219 | Get hash | malicious | Mirai | Browse | ||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Prometei | Browse | |||
109.202.202.202 | Get hash | malicious | Unknown | Browse |
| |
91.189.91.43 | Get hash | malicious | Mirai | Browse | ||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
77.232.42.137 | Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
dog.xlabsecurity.ru | Get hash | malicious | Unknown | Browse |
| |
horse.ipcamlover.ru | Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
EUT-ASEUTIPNetworkRU | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
INIT7CH | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
EUT-ASEUTIPNetworkRU | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
VTSL1-ASRU | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | GO Backdoor | Browse |
| ||
Get hash | malicious | GO Backdoor | Browse |
| ||
Get hash | malicious | GO Backdoor | Browse |
| ||
Get hash | malicious | Amadey, GO Backdoor | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
Process: | /tmp/hiss.arm5.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 307 |
Entropy (8bit): | 3.5155040099364117 |
Encrypted: | false |
SSDEEP: | 6:QVDFVYz7Y/VUS/FYDFVYA/VVmSY/VjmsVot/VOArB/VH:QVUS/FQdlbl |
MD5: | 8FD5A265718244C944355144E147CD33 |
SHA1: | FB5C82E2BAB66044E892722DD328F9351E323F05 |
SHA-256: | F2BD85B38B72F493CE141AE7477FA3F690BD441177D79D6E4AF85ED57030432C |
SHA-512: | FFBEA369EF8F9A978EE52CE01AEB1F3E94F68496F3D7D69661B7E500CF850ECE3B2F55B7E711BB3D56CF30795EB4EFFDBA278BD402D7E8C6B9F163A0FFFC6BF7 |
Malicious: | false |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 6.0999881625018215 |
TrID: |
|
File name: | hiss.arm5.elf |
File size: | 79'996 bytes |
MD5: | d53d8286d70b3d24f69a3c00120fb859 |
SHA1: | e0ec269bb83f995c23d04f00af38e172abcaeae1 |
SHA256: | 68620c56f240a0020ef82de07c4c129b5c399c1bacc359ca20f9f29270198669 |
SHA512: | 5d7928705b1b826d214b675f7a5654a26b71bc34390632c5b0c5d4266bc5570672932d6f05926c5518f036e6fc84ff6ed24f564c87270afe861cdd0a7fbfe0b2 |
SSDEEP: | 1536:XbndMlhYtwl9IzRDiJxW4+D8fEfx5dy5n+MhDq3jNdjb5ADKbYrM7AhOaLZpAWN7:hMwtzv1WEfH0tq3jN97CZpA8Whm6a |
TLSH: | 47732A96BC419B26D5E017BAFE1E428D33131FB8E2E932029D156F207BDA91F0E7B541 |
File Content Preview: | .ELF..............(.....l...4...$6......4. ...(........p84..8...8....................................5...5...............5...5...5.......'..........Q.td.............................@-..@............/..@-.,@...0....S..... 0....S.........../..0...0...@..../ |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 4 |
Section Header Offset: | 79396 |
Section Header Size: | 40 |
Number of Section Headers: | 15 |
Header String Table Index: | 14 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x80b4 | 0xb4 | 0x14 | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.text | PROGBITS | 0x80c8 | 0xc8 | 0x12078 | 0x0 | 0x6 | AX | 0 | 0 | 8 |
.fini | PROGBITS | 0x1a140 | 0x12140 | 0x14 | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.rodata | PROGBITS | 0x1a154 | 0x12154 | 0x12e4 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ARM.exidx | ARM_EXIDX | 0x1b438 | 0x13438 | 0xc8 | 0x0 | 0x82 | AL | 2 | 0 | 4 |
.eh_frame | PROGBITS | 0x23500 | 0x13500 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.init_array | INIT_ARRAY | 0x23504 | 0x13504 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.fini_array | FINI_ARRAY | 0x23508 | 0x13508 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.jcr | PROGBITS | 0x2350c | 0x1350c | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.got | PROGBITS | 0x23510 | 0x13510 | 0x28 | 0x4 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x23538 | 0x13538 | 0x60 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x23598 | 0x13598 | 0x2750 | 0x0 | 0x3 | WA | 0 | 0 | 8 |
.ARM.attributes | ARM_ATTRIBUTES | 0x0 | 0x13598 | 0x14 | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0x135ac | 0x77 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
EXIDX | 0x13438 | 0x1b438 | 0x1b438 | 0xc8 | 0xc8 | 4.3899 | 0x4 | R | 0x4 | .ARM.exidx | |
LOAD | 0x0 | 0x8000 | 0x8000 | 0x13500 | 0x13500 | 6.1140 | 0x5 | R E | 0x8000 | .init .text .fini .rodata .ARM.exidx | |
LOAD | 0x13500 | 0x23500 | 0x23500 | 0x98 | 0x27e8 | 3.2474 | 0x6 | RW | 0x8000 | .eh_frame .init_array .fini_array .jcr .got .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Download Network PCAP: filtered – full
- Total Packets: 69
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 20, 2025 09:46:52.259460926 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Mar 20, 2025 09:46:52.376337051 CET | 54620 | 443 | 192.168.2.23 | 77.232.41.24 |
Mar 20, 2025 09:46:52.376394033 CET | 443 | 54620 | 77.232.41.24 | 192.168.2.23 |
Mar 20, 2025 09:46:52.376440048 CET | 54620 | 443 | 192.168.2.23 | 77.232.41.24 |
Mar 20, 2025 09:46:54.379061937 CET | 54620 | 443 | 192.168.2.23 | 77.232.41.24 |
Mar 20, 2025 09:46:54.379093885 CET | 443 | 54620 | 77.232.41.24 | 192.168.2.23 |
Mar 20, 2025 09:46:54.379158974 CET | 443 | 54620 | 77.232.41.24 | 192.168.2.23 |
Mar 20, 2025 09:46:54.379175901 CET | 54620 | 443 | 192.168.2.23 | 77.232.41.24 |
Mar 20, 2025 09:46:54.379190922 CET | 443 | 54620 | 77.232.41.24 | 192.168.2.23 |
Mar 20, 2025 09:46:57.634829998 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Mar 20, 2025 09:46:59.170592070 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Mar 20, 2025 09:47:04.494416952 CET | 37314 | 8443 | 192.168.2.23 | 77.232.39.221 |
Mar 20, 2025 09:47:04.853538036 CET | 8443 | 37314 | 77.232.39.221 | 192.168.2.23 |
Mar 20, 2025 09:47:04.853878021 CET | 37314 | 8443 | 192.168.2.23 | 77.232.39.221 |
Mar 20, 2025 09:47:06.855911016 CET | 37314 | 8443 | 192.168.2.23 | 77.232.39.221 |
Mar 20, 2025 09:47:07.210453033 CET | 8443 | 37314 | 77.232.39.221 | 192.168.2.23 |
Mar 20, 2025 09:47:07.210793018 CET | 37314 | 8443 | 192.168.2.23 | 77.232.39.221 |
Mar 20, 2025 09:47:07.565526962 CET | 8443 | 37314 | 77.232.39.221 | 192.168.2.23 |
Mar 20, 2025 09:47:07.565548897 CET | 8443 | 37314 | 77.232.39.221 | 192.168.2.23 |
Mar 20, 2025 09:47:07.569230080 CET | 37314 | 8443 | 192.168.2.23 | 77.232.39.221 |
Mar 20, 2025 09:47:10.953130007 CET | 39250 | 443 | 192.168.2.23 | 34.249.145.219 |
Mar 20, 2025 09:47:10.953227997 CET | 443 | 39250 | 34.249.145.219 | 192.168.2.23 |
Mar 20, 2025 09:47:10.953320026 CET | 39250 | 443 | 192.168.2.23 | 34.249.145.219 |
Mar 20, 2025 09:47:10.953515053 CET | 39250 | 443 | 192.168.2.23 | 34.249.145.219 |
Mar 20, 2025 09:47:10.953543901 CET | 443 | 39250 | 34.249.145.219 | 192.168.2.23 |
Mar 20, 2025 09:47:12.992604017 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Mar 20, 2025 09:47:17.568037033 CET | 37314 | 8443 | 192.168.2.23 | 77.232.39.221 |
Mar 20, 2025 09:47:17.923782110 CET | 8443 | 37314 | 77.232.39.221 | 192.168.2.23 |
Mar 20, 2025 09:47:23.231096029 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Mar 20, 2025 09:47:29.374186039 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Mar 20, 2025 09:47:36.254255056 CET | 40410 | 17845 | 192.168.2.23 | 77.232.42.137 |
Mar 20, 2025 09:47:36.611963987 CET | 17845 | 40410 | 77.232.42.137 | 192.168.2.23 |
Mar 20, 2025 09:47:36.612202883 CET | 40410 | 17845 | 192.168.2.23 | 77.232.42.137 |
Mar 20, 2025 09:47:38.613866091 CET | 40410 | 17845 | 192.168.2.23 | 77.232.42.137 |
Mar 20, 2025 09:47:38.972238064 CET | 17845 | 40410 | 77.232.42.137 | 192.168.2.23 |
Mar 20, 2025 09:47:38.972474098 CET | 40410 | 17845 | 192.168.2.23 | 77.232.42.137 |
Mar 20, 2025 09:47:39.329938889 CET | 17845 | 40410 | 77.232.42.137 | 192.168.2.23 |
Mar 20, 2025 09:47:39.329997063 CET | 17845 | 40410 | 77.232.42.137 | 192.168.2.23 |
Mar 20, 2025 09:47:39.332683086 CET | 40410 | 17845 | 192.168.2.23 | 77.232.42.137 |
Mar 20, 2025 09:47:49.341603994 CET | 40410 | 17845 | 192.168.2.23 | 77.232.42.137 |
Mar 20, 2025 09:47:49.699911118 CET | 17845 | 40410 | 77.232.42.137 | 192.168.2.23 |
Mar 20, 2025 09:47:53.946779013 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Mar 20, 2025 09:48:10.945003033 CET | 39250 | 443 | 192.168.2.23 | 34.249.145.219 |
Mar 20, 2025 09:48:10.992324114 CET | 443 | 39250 | 34.249.145.219 | 192.168.2.23 |
Mar 20, 2025 09:48:14.423722982 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Mar 20, 2025 09:48:16.020292044 CET | 37402 | 179 | 192.168.2.23 | 91.142.78.22 |
Mar 20, 2025 09:48:16.377285004 CET | 179 | 37402 | 91.142.78.22 | 192.168.2.23 |
Mar 20, 2025 09:48:16.377507925 CET | 37402 | 179 | 192.168.2.23 | 91.142.78.22 |
Mar 20, 2025 09:48:18.378906012 CET | 37402 | 179 | 192.168.2.23 | 91.142.78.22 |
Mar 20, 2025 09:48:18.735266924 CET | 179 | 37402 | 91.142.78.22 | 192.168.2.23 |
Mar 20, 2025 09:48:18.735348940 CET | 37402 | 179 | 192.168.2.23 | 91.142.78.22 |
Mar 20, 2025 09:48:19.092778921 CET | 179 | 37402 | 91.142.78.22 | 192.168.2.23 |
Mar 20, 2025 09:48:19.092803001 CET | 179 | 37402 | 91.142.78.22 | 192.168.2.23 |
Mar 20, 2025 09:48:19.095001936 CET | 37402 | 179 | 192.168.2.23 | 91.142.78.22 |
Mar 20, 2025 09:48:29.104368925 CET | 37402 | 179 | 192.168.2.23 | 91.142.78.22 |
Mar 20, 2025 09:48:29.465003014 CET | 179 | 37402 | 91.142.78.22 | 192.168.2.23 |
Mar 20, 2025 09:48:39.303940058 CET | 55088 | 1080 | 192.168.2.23 | 77.232.42.137 |
Mar 20, 2025 09:48:39.659672976 CET | 1080 | 55088 | 77.232.42.137 | 192.168.2.23 |
Mar 20, 2025 09:48:39.659812927 CET | 55088 | 1080 | 192.168.2.23 | 77.232.42.137 |
Mar 20, 2025 09:48:41.660872936 CET | 55088 | 1080 | 192.168.2.23 | 77.232.42.137 |
Mar 20, 2025 09:48:42.016782045 CET | 1080 | 55088 | 77.232.42.137 | 192.168.2.23 |
Mar 20, 2025 09:48:42.016904116 CET | 55088 | 1080 | 192.168.2.23 | 77.232.42.137 |
Mar 20, 2025 09:48:42.372945070 CET | 1080 | 55088 | 77.232.42.137 | 192.168.2.23 |
Mar 20, 2025 09:48:42.372967958 CET | 1080 | 55088 | 77.232.42.137 | 192.168.2.23 |
Mar 20, 2025 09:48:42.375658989 CET | 55088 | 1080 | 192.168.2.23 | 77.232.42.137 |
Mar 20, 2025 09:48:52.379601002 CET | 55088 | 1080 | 192.168.2.23 | 77.232.42.137 |
Mar 20, 2025 09:48:52.736237049 CET | 1080 | 55088 | 77.232.42.137 | 192.168.2.23 |
Mar 20, 2025 09:48:55.203713894 CET | 443 | 39250 | 34.249.145.219 | 192.168.2.23 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 20, 2025 09:46:52.264062881 CET | 34434 | 53 | 192.168.2.23 | 8.8.8.8 |
Mar 20, 2025 09:46:52.365818977 CET | 53 | 34434 | 8.8.8.8 | 192.168.2.23 |
Mar 20, 2025 09:47:04.394740105 CET | 45450 | 53 | 192.168.2.23 | 8.8.8.8 |
Mar 20, 2025 09:47:04.493182898 CET | 53 | 45450 | 8.8.8.8 | 192.168.2.23 |
Mar 20, 2025 09:47:27.583106041 CET | 58144 | 53 | 192.168.2.23 | 8.8.8.8 |
Mar 20, 2025 09:47:28.129271030 CET | 53 | 58144 | 8.8.8.8 | 192.168.2.23 |
Mar 20, 2025 09:47:28.131366968 CET | 54482 | 53 | 192.168.2.23 | 1.1.1.1 |
Mar 20, 2025 09:47:28.232347965 CET | 53 | 54482 | 1.1.1.1 | 192.168.2.23 |
Mar 20, 2025 09:47:28.234298944 CET | 51084 | 53 | 192.168.2.23 | 208.67.222.222 |
Mar 20, 2025 09:47:28.328232050 CET | 53 | 51084 | 208.67.222.222 | 192.168.2.23 |
Mar 20, 2025 09:47:28.330421925 CET | 44723 | 53 | 192.168.2.23 | 208.67.220.220 |
Mar 20, 2025 09:47:28.423242092 CET | 53 | 44723 | 208.67.220.220 | 192.168.2.23 |
Mar 20, 2025 09:47:28.425280094 CET | 48945 | 53 | 192.168.2.23 | 9.9.9.9 |
Mar 20, 2025 09:47:28.729376078 CET | 53 | 48945 | 9.9.9.9 | 192.168.2.23 |
Mar 20, 2025 09:47:28.732355118 CET | 52437 | 53 | 192.168.2.23 | 4.2.2.1 |
Mar 20, 2025 09:47:28.827341080 CET | 53 | 52437 | 4.2.2.1 | 192.168.2.23 |
Mar 20, 2025 09:47:28.829195023 CET | 48179 | 53 | 192.168.2.23 | 180.76.76.76 |
Mar 20, 2025 09:47:29.141407013 CET | 53 | 48179 | 180.76.76.76 | 192.168.2.23 |
Mar 20, 2025 09:47:29.143887043 CET | 45393 | 53 | 192.168.2.23 | 185.85.15.34 |
Mar 20, 2025 09:47:36.151617050 CET | 60521 | 53 | 192.168.2.23 | 8.8.8.8 |
Mar 20, 2025 09:47:36.253298044 CET | 53 | 60521 | 8.8.8.8 | 192.168.2.23 |
Mar 20, 2025 09:47:59.353658915 CET | 35466 | 53 | 192.168.2.23 | 8.8.8.8 |
Mar 20, 2025 09:47:59.688524961 CET | 53 | 35466 | 8.8.8.8 | 192.168.2.23 |
Mar 20, 2025 09:47:59.690275908 CET | 38760 | 53 | 192.168.2.23 | 1.1.1.1 |
Mar 20, 2025 09:47:59.909028053 CET | 53 | 38760 | 1.1.1.1 | 192.168.2.23 |
Mar 20, 2025 09:47:59.910495043 CET | 52109 | 53 | 192.168.2.23 | 208.67.222.222 |
Mar 20, 2025 09:48:00.000171900 CET | 53 | 52109 | 208.67.222.222 | 192.168.2.23 |
Mar 20, 2025 09:48:00.002302885 CET | 58080 | 53 | 192.168.2.23 | 208.67.220.220 |
Mar 20, 2025 09:48:00.092624903 CET | 53 | 58080 | 208.67.220.220 | 192.168.2.23 |
Mar 20, 2025 09:48:00.093971968 CET | 36228 | 53 | 192.168.2.23 | 9.9.9.9 |
Mar 20, 2025 09:48:00.342847109 CET | 53 | 36228 | 9.9.9.9 | 192.168.2.23 |
Mar 20, 2025 09:48:00.344156981 CET | 43700 | 53 | 192.168.2.23 | 4.2.2.1 |
Mar 20, 2025 09:48:00.439666986 CET | 53 | 43700 | 4.2.2.1 | 192.168.2.23 |
Mar 20, 2025 09:48:00.441142082 CET | 39046 | 53 | 192.168.2.23 | 180.76.76.76 |
Mar 20, 2025 09:48:00.772586107 CET | 53 | 39046 | 180.76.76.76 | 192.168.2.23 |
Mar 20, 2025 09:48:00.774036884 CET | 41688 | 53 | 192.168.2.23 | 185.85.15.34 |
Mar 20, 2025 09:48:07.780976057 CET | 43567 | 53 | 192.168.2.23 | 8.8.8.8 |
Mar 20, 2025 09:48:08.114160061 CET | 53 | 43567 | 8.8.8.8 | 192.168.2.23 |
Mar 20, 2025 09:48:08.116017103 CET | 40343 | 53 | 192.168.2.23 | 1.1.1.1 |
Mar 20, 2025 09:48:08.215010881 CET | 53 | 40343 | 1.1.1.1 | 192.168.2.23 |
Mar 20, 2025 09:48:08.216334105 CET | 52876 | 53 | 192.168.2.23 | 208.67.222.222 |
Mar 20, 2025 09:48:08.305141926 CET | 53 | 52876 | 208.67.222.222 | 192.168.2.23 |
Mar 20, 2025 09:48:08.308326960 CET | 44653 | 53 | 192.168.2.23 | 208.67.220.220 |
Mar 20, 2025 09:48:08.399389029 CET | 53 | 44653 | 208.67.220.220 | 192.168.2.23 |
Mar 20, 2025 09:48:08.401139975 CET | 54401 | 53 | 192.168.2.23 | 9.9.9.9 |
Mar 20, 2025 09:48:08.490597010 CET | 53 | 54401 | 9.9.9.9 | 192.168.2.23 |
Mar 20, 2025 09:48:08.492800951 CET | 34419 | 53 | 192.168.2.23 | 4.2.2.1 |
Mar 20, 2025 09:48:08.587095976 CET | 53 | 34419 | 4.2.2.1 | 192.168.2.23 |
Mar 20, 2025 09:48:08.589167118 CET | 53945 | 53 | 192.168.2.23 | 180.76.76.76 |
Mar 20, 2025 09:48:08.908600092 CET | 53 | 53945 | 180.76.76.76 | 192.168.2.23 |
Mar 20, 2025 09:48:08.909734011 CET | 52017 | 53 | 192.168.2.23 | 185.85.15.34 |
Mar 20, 2025 09:48:15.917438984 CET | 40476 | 53 | 192.168.2.23 | 8.8.8.8 |
Mar 20, 2025 09:48:16.019160032 CET | 53 | 40476 | 8.8.8.8 | 192.168.2.23 |
Mar 20, 2025 09:48:39.117322922 CET | 36919 | 53 | 192.168.2.23 | 8.8.8.8 |
Mar 20, 2025 09:48:39.302892923 CET | 53 | 36919 | 8.8.8.8 | 192.168.2.23 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Mar 20, 2025 09:46:52.264062881 CET | 192.168.2.23 | 8.8.8.8 | 0x59be | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:47:04.394740105 CET | 192.168.2.23 | 8.8.8.8 | 0x144a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:47:27.583106041 CET | 192.168.2.23 | 8.8.8.8 | 0x80fc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:47:28.131366968 CET | 192.168.2.23 | 1.1.1.1 | 0x80fc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:47:28.234298944 CET | 192.168.2.23 | 208.67.222.222 | 0x80fc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:47:28.330421925 CET | 192.168.2.23 | 208.67.220.220 | 0x80fc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:47:28.425280094 CET | 192.168.2.23 | 9.9.9.9 | 0x80fc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:47:28.732355118 CET | 192.168.2.23 | 4.2.2.1 | 0x80fc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:47:28.829195023 CET | 192.168.2.23 | 180.76.76.76 | 0x80fc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:47:29.143887043 CET | 192.168.2.23 | 185.85.15.34 | 0x80fc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:47:36.151617050 CET | 192.168.2.23 | 8.8.8.8 | 0x10 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:47:59.353658915 CET | 192.168.2.23 | 8.8.8.8 | 0x20b8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:47:59.690275908 CET | 192.168.2.23 | 1.1.1.1 | 0x20b8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:47:59.910495043 CET | 192.168.2.23 | 208.67.222.222 | 0x20b8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:48:00.002302885 CET | 192.168.2.23 | 208.67.220.220 | 0x20b8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:48:00.093971968 CET | 192.168.2.23 | 9.9.9.9 | 0x20b8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:48:00.344156981 CET | 192.168.2.23 | 4.2.2.1 | 0x20b8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:48:00.441142082 CET | 192.168.2.23 | 180.76.76.76 | 0x20b8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:48:00.774036884 CET | 192.168.2.23 | 185.85.15.34 | 0x20b8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:48:07.780976057 CET | 192.168.2.23 | 8.8.8.8 | 0x8968 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:48:08.116017103 CET | 192.168.2.23 | 1.1.1.1 | 0x8968 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:48:08.216334105 CET | 192.168.2.23 | 208.67.222.222 | 0x8968 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:48:08.308326960 CET | 192.168.2.23 | 208.67.220.220 | 0x8968 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:48:08.401139975 CET | 192.168.2.23 | 9.9.9.9 | 0x8968 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:48:08.492800951 CET | 192.168.2.23 | 4.2.2.1 | 0x8968 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:48:08.589167118 CET | 192.168.2.23 | 180.76.76.76 | 0x8968 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:48:08.909734011 CET | 192.168.2.23 | 185.85.15.34 | 0x8968 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:48:15.917438984 CET | 192.168.2.23 | 8.8.8.8 | 0x903 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:48:39.117322922 CET | 192.168.2.23 | 8.8.8.8 | 0x53dc | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Mar 20, 2025 09:46:52.365818977 CET | 8.8.8.8 | 192.168.2.23 | 0x59be | No error (0) | 77.232.41.24 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:46:52.365818977 CET | 8.8.8.8 | 192.168.2.23 | 0x59be | No error (0) | 77.232.39.221 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:46:52.365818977 CET | 8.8.8.8 | 192.168.2.23 | 0x59be | No error (0) | 185.173.37.56 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:46:52.365818977 CET | 8.8.8.8 | 192.168.2.23 | 0x59be | No error (0) | 77.232.36.152 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:46:52.365818977 CET | 8.8.8.8 | 192.168.2.23 | 0x59be | No error (0) | 77.232.42.137 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:46:52.365818977 CET | 8.8.8.8 | 192.168.2.23 | 0x59be | No error (0) | 91.142.78.22 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:46:52.365818977 CET | 8.8.8.8 | 192.168.2.23 | 0x59be | No error (0) | 77.232.36.191 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:46:52.365818977 CET | 8.8.8.8 | 192.168.2.23 | 0x59be | No error (0) | 91.142.77.79 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:46:52.365818977 CET | 8.8.8.8 | 192.168.2.23 | 0x59be | No error (0) | 77.232.39.139 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:46:52.365818977 CET | 8.8.8.8 | 192.168.2.23 | 0x59be | No error (0) | 91.142.77.13 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:47:04.493182898 CET | 8.8.8.8 | 192.168.2.23 | 0x144a | No error (0) | 77.232.39.221 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:47:04.493182898 CET | 8.8.8.8 | 192.168.2.23 | 0x144a | No error (0) | 91.142.77.79 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:47:04.493182898 CET | 8.8.8.8 | 192.168.2.23 | 0x144a | No error (0) | 77.232.41.24 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:47:04.493182898 CET | 8.8.8.8 | 192.168.2.23 | 0x144a | No error (0) | 91.142.77.13 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:47:04.493182898 CET | 8.8.8.8 | 192.168.2.23 | 0x144a | No error (0) | 185.173.37.56 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:47:04.493182898 CET | 8.8.8.8 | 192.168.2.23 | 0x144a | No error (0) | 77.232.36.191 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:47:04.493182898 CET | 8.8.8.8 | 192.168.2.23 | 0x144a | No error (0) | 91.142.78.22 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:47:04.493182898 CET | 8.8.8.8 | 192.168.2.23 | 0x144a | No error (0) | 77.232.42.137 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:47:04.493182898 CET | 8.8.8.8 | 192.168.2.23 | 0x144a | No error (0) | 77.232.39.139 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:47:04.493182898 CET | 8.8.8.8 | 192.168.2.23 | 0x144a | No error (0) | 77.232.36.152 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:47:28.129271030 CET | 8.8.8.8 | 192.168.2.23 | 0x80fc | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:47:28.232347965 CET | 1.1.1.1 | 192.168.2.23 | 0x80fc | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:47:28.328232050 CET | 208.67.222.222 | 192.168.2.23 | 0x80fc | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:47:28.423242092 CET | 208.67.220.220 | 192.168.2.23 | 0x80fc | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:47:28.729376078 CET | 9.9.9.9 | 192.168.2.23 | 0x80fc | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:47:28.827341080 CET | 4.2.2.1 | 192.168.2.23 | 0x80fc | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:47:29.141407013 CET | 180.76.76.76 | 192.168.2.23 | 0x80fc | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:47:36.253298044 CET | 8.8.8.8 | 192.168.2.23 | 0x10 | No error (0) | 77.232.42.137 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:47:36.253298044 CET | 8.8.8.8 | 192.168.2.23 | 0x10 | No error (0) | 77.232.36.152 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:47:36.253298044 CET | 8.8.8.8 | 192.168.2.23 | 0x10 | No error (0) | 77.232.36.191 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:47:36.253298044 CET | 8.8.8.8 | 192.168.2.23 | 0x10 | No error (0) | 91.142.78.22 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:47:36.253298044 CET | 8.8.8.8 | 192.168.2.23 | 0x10 | No error (0) | 91.142.77.13 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:47:36.253298044 CET | 8.8.8.8 | 192.168.2.23 | 0x10 | No error (0) | 77.232.39.139 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:47:36.253298044 CET | 8.8.8.8 | 192.168.2.23 | 0x10 | No error (0) | 77.232.41.24 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:47:36.253298044 CET | 8.8.8.8 | 192.168.2.23 | 0x10 | No error (0) | 77.232.39.221 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:47:36.253298044 CET | 8.8.8.8 | 192.168.2.23 | 0x10 | No error (0) | 185.173.37.56 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:47:36.253298044 CET | 8.8.8.8 | 192.168.2.23 | 0x10 | No error (0) | 91.142.77.79 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:47:59.688524961 CET | 8.8.8.8 | 192.168.2.23 | 0x20b8 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:47:59.909028053 CET | 1.1.1.1 | 192.168.2.23 | 0x20b8 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:48:00.000171900 CET | 208.67.222.222 | 192.168.2.23 | 0x20b8 | No error (0) | 146.112.61.108 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:48:00.092624903 CET | 208.67.220.220 | 192.168.2.23 | 0x20b8 | No error (0) | 146.112.61.108 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:48:00.342847109 CET | 9.9.9.9 | 192.168.2.23 | 0x20b8 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:48:00.439666986 CET | 4.2.2.1 | 192.168.2.23 | 0x20b8 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:48:00.772586107 CET | 180.76.76.76 | 192.168.2.23 | 0x20b8 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:48:08.114160061 CET | 8.8.8.8 | 192.168.2.23 | 0x8968 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:48:08.215010881 CET | 1.1.1.1 | 192.168.2.23 | 0x8968 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:48:08.305141926 CET | 208.67.222.222 | 192.168.2.23 | 0x8968 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:48:08.399389029 CET | 208.67.220.220 | 192.168.2.23 | 0x8968 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:48:08.490597010 CET | 9.9.9.9 | 192.168.2.23 | 0x8968 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:48:08.587095976 CET | 4.2.2.1 | 192.168.2.23 | 0x8968 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:48:08.908600092 CET | 180.76.76.76 | 192.168.2.23 | 0x8968 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 09:48:16.019160032 CET | 8.8.8.8 | 192.168.2.23 | 0x903 | No error (0) | 91.142.78.22 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:48:16.019160032 CET | 8.8.8.8 | 192.168.2.23 | 0x903 | No error (0) | 91.142.77.79 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:48:16.019160032 CET | 8.8.8.8 | 192.168.2.23 | 0x903 | No error (0) | 77.232.36.191 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:48:16.019160032 CET | 8.8.8.8 | 192.168.2.23 | 0x903 | No error (0) | 77.232.39.221 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:48:16.019160032 CET | 8.8.8.8 | 192.168.2.23 | 0x903 | No error (0) | 77.232.36.152 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:48:16.019160032 CET | 8.8.8.8 | 192.168.2.23 | 0x903 | No error (0) | 77.232.42.137 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:48:16.019160032 CET | 8.8.8.8 | 192.168.2.23 | 0x903 | No error (0) | 91.142.77.13 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:48:16.019160032 CET | 8.8.8.8 | 192.168.2.23 | 0x903 | No error (0) | 77.232.41.24 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:48:16.019160032 CET | 8.8.8.8 | 192.168.2.23 | 0x903 | No error (0) | 77.232.39.139 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:48:16.019160032 CET | 8.8.8.8 | 192.168.2.23 | 0x903 | No error (0) | 185.173.37.56 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:48:39.302892923 CET | 8.8.8.8 | 192.168.2.23 | 0x53dc | No error (0) | 77.232.42.137 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:48:39.302892923 CET | 8.8.8.8 | 192.168.2.23 | 0x53dc | No error (0) | 91.142.77.79 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:48:39.302892923 CET | 8.8.8.8 | 192.168.2.23 | 0x53dc | No error (0) | 77.232.41.24 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:48:39.302892923 CET | 8.8.8.8 | 192.168.2.23 | 0x53dc | No error (0) | 77.232.36.191 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:48:39.302892923 CET | 8.8.8.8 | 192.168.2.23 | 0x53dc | No error (0) | 91.142.77.13 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:48:39.302892923 CET | 8.8.8.8 | 192.168.2.23 | 0x53dc | No error (0) | 77.232.39.221 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:48:39.302892923 CET | 8.8.8.8 | 192.168.2.23 | 0x53dc | No error (0) | 91.142.78.22 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:48:39.302892923 CET | 8.8.8.8 | 192.168.2.23 | 0x53dc | No error (0) | 77.232.36.152 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:48:39.302892923 CET | 8.8.8.8 | 192.168.2.23 | 0x53dc | No error (0) | 185.173.37.56 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 09:48:39.302892923 CET | 8.8.8.8 | 192.168.2.23 | 0x53dc | No error (0) | 77.232.39.139 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 08:46:51 |
Start date (UTC): | 20/03/2025 |
Path: | /tmp/hiss.arm5.elf |
Arguments: | /tmp/hiss.arm5.elf |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 08:46:51 |
Start date (UTC): | 20/03/2025 |
Path: | /tmp/hiss.arm5.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 08:46:51 |
Start date (UTC): | 20/03/2025 |
Path: | /tmp/hiss.arm5.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 08:46:51 |
Start date (UTC): | 20/03/2025 |
Path: | /tmp/hiss.arm5.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 08:48:09 |
Start date (UTC): | 20/03/2025 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 08:48:09 |
Start date (UTC): | 20/03/2025 |
Path: | /usr/bin/rm |
Arguments: | rm -f /tmp/tmp.HhsizMsbmp /tmp/tmp.ALtfi5tFGo /tmp/tmp.5HXK2JqvZR |
File size: | 72056 bytes |
MD5 hash: | aa2b5496fdbfd88e38791ab81f90b95b |
Start time (UTC): | 08:48:09 |
Start date (UTC): | 20/03/2025 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 08:48:09 |
Start date (UTC): | 20/03/2025 |
Path: | /usr/bin/rm |
Arguments: | rm -f /tmp/tmp.HhsizMsbmp /tmp/tmp.ALtfi5tFGo /tmp/tmp.5HXK2JqvZR |
File size: | 72056 bytes |
MD5 hash: | aa2b5496fdbfd88e38791ab81f90b95b |