Linux
Analysis Report
hiss.arm7.elf
Overview
General Information
Sample name: | hiss.arm7.elf |
Analysis ID: | 1644027 |
MD5: | 8f9ef18e6dfd335426f1fc75e9d1dfa2 |
SHA1: | 30dfb908321571f95b54f3c63e3fa2e9d6982b5f |
SHA256: | dd486cbb6ad776e7894291d1edc51697d67a855fcacbf2f6ab98c19c127cbdd2 |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Score: | 48 |
Range: | 0 - 100 |
Signatures
Multi AV Scanner detection for submitted file
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Found strings indicative of a multi-platform dropper
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1644027 |
Start date and time: | 2025-03-20 10:21:06 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 45s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | hiss.arm7.elf |
Detection: | MAL |
Classification: | mal48.linELF@0/1@44/0 |
- VT rate limit hit for: horse.ipcamlover.ru
Command: | /tmp/hiss.arm7.elf |
PID: | 5477 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | |
Standard Error: |
- system is lnxubuntu20
- hiss.arm7.elf New Fork (PID: 5479, Parent: 5477)
- hiss.arm7.elf New Fork (PID: 5480, Parent: 5477)
- hiss.arm7.elf New Fork (PID: 5483, Parent: 5477)
- dash New Fork (PID: 5554, Parent: 3632)
- dash New Fork (PID: 5555, Parent: 3632)
- cleanup
⊘No yara matches
⊘No Suricata rule has matched
- • AV Detection
- • Spreading
- • Networking
- • System Summary
- • Persistence and Installation Behavior
- • Malware Analysis System Evasion
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | String: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | .symtab present: |
Source: | Classification label: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | Windows Management Instrumentation | 1 Scripting | Path Interception | 1 File Deletion | 1 OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 2 Application Layer Protocol | Traffic Duplication | Data Destruction |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
19% | Virustotal | Browse | ||
22% | ReversingLabs | Linux.Backdoor.Mirai |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
horse.ipcamlover.ru | 77.232.36.152 | true | false | unknown | |
fish.dvrhelpers.su | 77.232.42.137 | true | false | unknown | |
dog.xlabsecurity.ru | 146.112.61.108 | true | false | unknown | |
kitty.xlabresearch.ru | unknown | unknown | false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
91.142.77.79 | unknown | Russian Federation | 48720 | VTSL1-ASRU | false | |
34.254.182.186 | unknown | United States | 16509 | AMAZON-02US | false | |
77.232.41.24 | unknown | Russian Federation | 28968 | EUT-ASEUTIPNetworkRU | false | |
91.142.78.22 | unknown | Russian Federation | 48720 | VTSL1-ASRU | false | |
185.125.190.26 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
34.243.160.129 | unknown | United States | 16509 | AMAZON-02US | false | |
77.232.36.152 | horse.ipcamlover.ru | Russian Federation | 28968 | EUT-ASEUTIPNetworkRU | false | |
77.232.42.137 | fish.dvrhelpers.su | Russian Federation | 28968 | EUT-ASEUTIPNetworkRU | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
91.142.77.79 | Get hash | malicious | Unknown | Browse | ||
185.125.190.26 | Get hash | malicious | Mirai | Browse | ||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Prometei | Browse | |||
34.254.182.186 | Get hash | malicious | Mirai | Browse | ||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Prometei | Browse | |||
77.232.41.24 | Get hash | malicious | Unknown | Browse | ||
91.142.78.22 | Get hash | malicious | Unknown | Browse | ||
34.243.160.129 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Tsunami | Browse | |||
77.232.36.152 | Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
horse.ipcamlover.ru | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
dog.xlabsecurity.ru | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
fish.dvrhelpers.su | Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AMAZON-02US | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
EUT-ASEUTIPNetworkRU | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
VTSL1-ASRU | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | GO Backdoor | Browse |
| ||
Get hash | malicious | GO Backdoor | Browse |
| ||
Get hash | malicious | GO Backdoor | Browse |
| ||
Get hash | malicious | Amadey, GO Backdoor | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
VTSL1-ASRU | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | GO Backdoor | Browse |
| ||
Get hash | malicious | GO Backdoor | Browse |
| ||
Get hash | malicious | GO Backdoor | Browse |
| ||
Get hash | malicious | Amadey, GO Backdoor | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
Process: | /tmp/hiss.arm7.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 272 |
Entropy (8bit): | 3.545320343800884 |
Encrypted: | false |
SSDEEP: | 6:GYgDFV+JXM/VUT4DFV+//IQ3j/VjmsVot/VOArB/VH:+uJXNcuYQSl |
MD5: | 99D88BEBC7D9D25119522F037CD7DDD9 |
SHA1: | EFAEB3FF0DE9B4D182AA115388A975A1AAD7FBFB |
SHA-256: | 0BC962A2A13EB65E533A68E2E36676BCA7921BCF8561BD56F09238042AA1327F |
SHA-512: | 59F3433914D278A569344724B75DB4523E5BC41589BEE98F60EC86B914E87CC0EB6126752D48B0E7D19910311DFFB320A9D23BE946F0127E233FDF9B8418A725 |
Malicious: | false |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 6.085235758750268 |
TrID: |
|
File name: | hiss.arm7.elf |
File size: | 91'728 bytes |
MD5: | 8f9ef18e6dfd335426f1fc75e9d1dfa2 |
SHA1: | 30dfb908321571f95b54f3c63e3fa2e9d6982b5f |
SHA256: | dd486cbb6ad776e7894291d1edc51697d67a855fcacbf2f6ab98c19c127cbdd2 |
SHA512: | 5a3d0a8ee36ab877485a6baf30024ccf9d0e3f9aab81f8ea3e3ae3f8adb4992f27757f7e1dab9ce2c14c0e87dcef700f6d6ebc8662ee8619d1d707d71bb5ff29 |
SSDEEP: | 1536:FAnV0MTSxLdTzh6NWkzcBBOMSyZRf1tn+Q+z/BlXW8OlJy42iL1Ca7Pz2wY7SYvq:e0M8x3h6QkzcrNJfbn9+z/Bl4j1Ca7LQ |
TLSH: | EC932A5ABC81AB11D5D522BAFE1E128D33535B6CE3EE7212DD245F1027CA92B0F7B502 |
File Content Preview: | .ELF..............(.........4....c......4. ...(........p.^..........................................._..._...............`...`...`......\S...............`...`...`..................Q.td..................................-...L..................G.F.G.F.G.F.G. |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 5 |
Section Header Offset: | 91048 |
Section Header Size: | 40 |
Number of Section Headers: | 17 |
Header String Table Index: | 16 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x80d4 | 0xd4 | 0x10 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x80f0 | 0xf0 | 0x14690 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x1c780 | 0x14780 | 0x10 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x1c790 | 0x14790 | 0x1718 | 0x0 | 0x2 | A | 0 | 0 | 8 |
.ARM.extab | PROGBITS | 0x1dea8 | 0x15ea8 | 0x18 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ARM.exidx | ARM_EXIDX | 0x1dec0 | 0x15ec0 | 0x118 | 0x0 | 0x82 | AL | 2 | 0 | 4 |
.eh_frame | PROGBITS | 0x26000 | 0x16000 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.tbss | NOBITS | 0x26004 | 0x16004 | 0x8 | 0x0 | 0x403 | WAT | 0 | 0 | 4 |
.init_array | INIT_ARRAY | 0x26004 | 0x16004 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.fini_array | FINI_ARRAY | 0x26008 | 0x16008 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.jcr | PROGBITS | 0x2600c | 0x1600c | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.got | PROGBITS | 0x26010 | 0x16010 | 0xa8 | 0x4 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x260b8 | 0x160b8 | 0x250 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x26308 | 0x16308 | 0x5054 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.ARM.attributes | ARM_ATTRIBUTES | 0x0 | 0x16308 | 0x16 | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0x1631e | 0x88 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
EXIDX | 0x15ec0 | 0x1dec0 | 0x1dec0 | 0x118 | 0x118 | 4.5299 | 0x4 | R | 0x4 | .ARM.exidx | |
LOAD | 0x0 | 0x8000 | 0x8000 | 0x15fd8 | 0x15fd8 | 6.1039 | 0x5 | R E | 0x8000 | .init .text .fini .rodata .ARM.extab .ARM.exidx | |
LOAD | 0x16000 | 0x26000 | 0x26000 | 0x308 | 0x535c | 4.1505 | 0x6 | RW | 0x8000 | .eh_frame .tbss .init_array .fini_array .jcr .got .data .bss | |
TLS | 0x16004 | 0x26004 | 0x26004 | 0x0 | 0x8 | 0.0000 | 0x4 | R | 0x4 | .tbss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Download Network PCAP: filtered – full
- Total Packets: 77
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 20, 2025 10:21:49.169081926 CET | 42470 | 443 | 192.168.2.14 | 34.243.160.129 |
Mar 20, 2025 10:21:55.824771881 CET | 46540 | 443 | 192.168.2.14 | 185.125.190.26 |
Mar 20, 2025 10:22:03.821739912 CET | 40546 | 1900 | 192.168.2.14 | 77.232.36.152 |
Mar 20, 2025 10:22:04.848453045 CET | 40546 | 1900 | 192.168.2.14 | 77.232.36.152 |
Mar 20, 2025 10:22:06.864398956 CET | 40546 | 1900 | 192.168.2.14 | 77.232.36.152 |
Mar 20, 2025 10:22:10.831083059 CET | 47908 | 8443 | 192.168.2.14 | 91.142.78.22 |
Mar 20, 2025 10:22:11.184906006 CET | 8443 | 47908 | 91.142.78.22 | 192.168.2.14 |
Mar 20, 2025 10:22:11.185235977 CET | 47908 | 8443 | 192.168.2.14 | 91.142.78.22 |
Mar 20, 2025 10:22:13.188580990 CET | 47908 | 8443 | 192.168.2.14 | 91.142.78.22 |
Mar 20, 2025 10:22:13.547174931 CET | 8443 | 47908 | 91.142.78.22 | 192.168.2.14 |
Mar 20, 2025 10:22:13.547347069 CET | 47908 | 8443 | 192.168.2.14 | 91.142.78.22 |
Mar 20, 2025 10:22:13.903518915 CET | 8443 | 47908 | 91.142.78.22 | 192.168.2.14 |
Mar 20, 2025 10:22:13.903557062 CET | 8443 | 47908 | 91.142.78.22 | 192.168.2.14 |
Mar 20, 2025 10:22:13.904011965 CET | 47908 | 8443 | 192.168.2.14 | 91.142.78.22 |
Mar 20, 2025 10:22:17.773844004 CET | 59334 | 443 | 192.168.2.14 | 34.254.182.186 |
Mar 20, 2025 10:22:17.773894072 CET | 443 | 59334 | 34.254.182.186 | 192.168.2.14 |
Mar 20, 2025 10:22:17.774000883 CET | 59334 | 443 | 192.168.2.14 | 34.254.182.186 |
Mar 20, 2025 10:22:17.775409937 CET | 59334 | 443 | 192.168.2.14 | 34.254.182.186 |
Mar 20, 2025 10:22:17.775423050 CET | 443 | 59334 | 34.254.182.186 | 192.168.2.14 |
Mar 20, 2025 10:22:23.913196087 CET | 47908 | 8443 | 192.168.2.14 | 91.142.78.22 |
Mar 20, 2025 10:22:24.278415918 CET | 8443 | 47908 | 91.142.78.22 | 192.168.2.14 |
Mar 20, 2025 10:22:26.287591934 CET | 46540 | 443 | 192.168.2.14 | 185.125.190.26 |
Mar 20, 2025 10:22:34.052880049 CET | 57408 | 1080 | 192.168.2.14 | 77.232.42.137 |
Mar 20, 2025 10:22:34.443789959 CET | 1080 | 57408 | 77.232.42.137 | 192.168.2.14 |
Mar 20, 2025 10:22:34.444081068 CET | 57408 | 1080 | 192.168.2.14 | 77.232.42.137 |
Mar 20, 2025 10:22:36.446259022 CET | 57408 | 1080 | 192.168.2.14 | 77.232.42.137 |
Mar 20, 2025 10:22:36.835279942 CET | 1080 | 57408 | 77.232.42.137 | 192.168.2.14 |
Mar 20, 2025 10:22:36.835489988 CET | 57408 | 1080 | 192.168.2.14 | 77.232.42.137 |
Mar 20, 2025 10:22:37.223882914 CET | 1080 | 57408 | 77.232.42.137 | 192.168.2.14 |
Mar 20, 2025 10:22:37.223949909 CET | 1080 | 57408 | 77.232.42.137 | 192.168.2.14 |
Mar 20, 2025 10:22:37.227138042 CET | 57408 | 1080 | 192.168.2.14 | 77.232.42.137 |
Mar 20, 2025 10:22:47.236223936 CET | 57408 | 1080 | 192.168.2.14 | 77.232.42.137 |
Mar 20, 2025 10:22:47.236263990 CET | 57408 | 1080 | 192.168.2.14 | 77.232.42.137 |
Mar 20, 2025 10:22:47.594511032 CET | 1080 | 57408 | 77.232.42.137 | 192.168.2.14 |
Mar 20, 2025 10:22:47.594578981 CET | 1080 | 57408 | 77.232.42.137 | 192.168.2.14 |
Mar 20, 2025 10:22:57.346457958 CET | 41618 | 1900 | 192.168.2.14 | 77.232.41.24 |
Mar 20, 2025 10:22:58.350394964 CET | 41618 | 1900 | 192.168.2.14 | 77.232.41.24 |
Mar 20, 2025 10:23:00.366297960 CET | 41618 | 1900 | 192.168.2.14 | 77.232.41.24 |
Mar 20, 2025 10:23:04.353219986 CET | 59602 | 8080 | 192.168.2.14 | 91.142.77.79 |
Mar 20, 2025 10:23:04.716413021 CET | 8080 | 59602 | 91.142.77.79 | 192.168.2.14 |
Mar 20, 2025 10:23:04.716730118 CET | 59602 | 8080 | 192.168.2.14 | 91.142.77.79 |
Mar 20, 2025 10:23:06.718957901 CET | 59602 | 8080 | 192.168.2.14 | 91.142.77.79 |
Mar 20, 2025 10:23:07.085093975 CET | 8080 | 59602 | 91.142.77.79 | 192.168.2.14 |
Mar 20, 2025 10:23:07.085237980 CET | 59602 | 8080 | 192.168.2.14 | 91.142.77.79 |
Mar 20, 2025 10:23:07.459502935 CET | 8080 | 59602 | 91.142.77.79 | 192.168.2.14 |
Mar 20, 2025 10:23:07.459574938 CET | 8080 | 59602 | 91.142.77.79 | 192.168.2.14 |
Mar 20, 2025 10:23:07.462081909 CET | 59602 | 8080 | 192.168.2.14 | 91.142.77.79 |
Mar 20, 2025 10:23:17.473220110 CET | 59602 | 8080 | 192.168.2.14 | 91.142.77.79 |
Mar 20, 2025 10:23:17.772136927 CET | 59334 | 443 | 192.168.2.14 | 34.254.182.186 |
Mar 20, 2025 10:23:17.816330910 CET | 443 | 59334 | 34.254.182.186 | 192.168.2.14 |
Mar 20, 2025 10:23:17.835478067 CET | 8080 | 59602 | 91.142.77.79 | 192.168.2.14 |
Mar 20, 2025 10:23:51.319591999 CET | 443 | 59334 | 34.254.182.186 | 192.168.2.14 |
Mar 20, 2025 10:23:52.382281065 CET | 48740 | 53847 | 192.168.2.14 | 77.232.42.137 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 20, 2025 10:21:46.847572088 CET | 56927 | 53 | 192.168.2.14 | 8.8.8.8 |
Mar 20, 2025 10:21:47.144064903 CET | 53 | 56927 | 8.8.8.8 | 192.168.2.14 |
Mar 20, 2025 10:21:47.174808979 CET | 50560 | 53 | 192.168.2.14 | 1.1.1.1 |
Mar 20, 2025 10:21:47.273695946 CET | 53 | 50560 | 1.1.1.1 | 192.168.2.14 |
Mar 20, 2025 10:21:47.275284052 CET | 60521 | 53 | 192.168.2.14 | 208.67.222.222 |
Mar 20, 2025 10:21:47.364981890 CET | 53 | 60521 | 208.67.222.222 | 192.168.2.14 |
Mar 20, 2025 10:21:47.366811037 CET | 54152 | 53 | 192.168.2.14 | 208.67.220.220 |
Mar 20, 2025 10:21:47.614489079 CET | 53 | 54152 | 208.67.220.220 | 192.168.2.14 |
Mar 20, 2025 10:21:47.615823984 CET | 49825 | 53 | 192.168.2.14 | 9.9.9.9 |
Mar 20, 2025 10:21:47.814487934 CET | 53 | 49825 | 9.9.9.9 | 192.168.2.14 |
Mar 20, 2025 10:21:47.817322969 CET | 49408 | 53 | 192.168.2.14 | 4.2.2.1 |
Mar 20, 2025 10:21:47.918853998 CET | 53 | 49408 | 4.2.2.1 | 192.168.2.14 |
Mar 20, 2025 10:21:47.920614004 CET | 60989 | 53 | 192.168.2.14 | 180.76.76.76 |
Mar 20, 2025 10:21:48.222465992 CET | 53 | 60989 | 180.76.76.76 | 192.168.2.14 |
Mar 20, 2025 10:21:48.225738049 CET | 39372 | 53 | 192.168.2.14 | 185.85.15.34 |
Mar 20, 2025 10:21:55.233217001 CET | 60844 | 53 | 192.168.2.14 | 8.8.8.8 |
Mar 20, 2025 10:21:55.783859968 CET | 53 | 60844 | 8.8.8.8 | 192.168.2.14 |
Mar 20, 2025 10:21:55.786212921 CET | 53099 | 53 | 192.168.2.14 | 1.1.1.1 |
Mar 20, 2025 10:21:56.016938925 CET | 53 | 53099 | 1.1.1.1 | 192.168.2.14 |
Mar 20, 2025 10:21:56.018903017 CET | 33945 | 53 | 192.168.2.14 | 208.67.222.222 |
Mar 20, 2025 10:21:56.109606028 CET | 53 | 33945 | 208.67.222.222 | 192.168.2.14 |
Mar 20, 2025 10:21:56.111500978 CET | 42915 | 53 | 192.168.2.14 | 208.67.220.220 |
Mar 20, 2025 10:21:56.202219009 CET | 53 | 42915 | 208.67.220.220 | 192.168.2.14 |
Mar 20, 2025 10:21:56.203895092 CET | 37861 | 53 | 192.168.2.14 | 9.9.9.9 |
Mar 20, 2025 10:21:56.293184996 CET | 53 | 37861 | 9.9.9.9 | 192.168.2.14 |
Mar 20, 2025 10:21:56.294796944 CET | 33741 | 53 | 192.168.2.14 | 4.2.2.1 |
Mar 20, 2025 10:21:56.388943911 CET | 53 | 33741 | 4.2.2.1 | 192.168.2.14 |
Mar 20, 2025 10:21:56.390516996 CET | 41336 | 53 | 192.168.2.14 | 180.76.76.76 |
Mar 20, 2025 10:21:56.709707975 CET | 53 | 41336 | 180.76.76.76 | 192.168.2.14 |
Mar 20, 2025 10:21:56.711922884 CET | 60647 | 53 | 192.168.2.14 | 185.85.15.34 |
Mar 20, 2025 10:22:03.720177889 CET | 51962 | 53 | 192.168.2.14 | 8.8.8.8 |
Mar 20, 2025 10:22:03.820553064 CET | 53 | 51962 | 8.8.8.8 | 192.168.2.14 |
Mar 20, 2025 10:22:33.927144051 CET | 45072 | 53 | 192.168.2.14 | 8.8.8.8 |
Mar 20, 2025 10:22:34.051877022 CET | 53 | 45072 | 8.8.8.8 | 192.168.2.14 |
Mar 20, 2025 10:22:57.249438047 CET | 56926 | 53 | 192.168.2.14 | 8.8.8.8 |
Mar 20, 2025 10:22:57.345278978 CET | 53 | 56926 | 8.8.8.8 | 192.168.2.14 |
Mar 20, 2025 10:23:27.487025023 CET | 42333 | 53 | 192.168.2.14 | 8.8.8.8 |
Mar 20, 2025 10:23:27.782386065 CET | 53 | 42333 | 8.8.8.8 | 192.168.2.14 |
Mar 20, 2025 10:23:27.784739971 CET | 33291 | 53 | 192.168.2.14 | 1.1.1.1 |
Mar 20, 2025 10:23:28.002958059 CET | 53 | 33291 | 1.1.1.1 | 192.168.2.14 |
Mar 20, 2025 10:23:28.006055117 CET | 60171 | 53 | 192.168.2.14 | 208.67.222.222 |
Mar 20, 2025 10:23:28.095468044 CET | 53 | 60171 | 208.67.222.222 | 192.168.2.14 |
Mar 20, 2025 10:23:28.098166943 CET | 57724 | 53 | 192.168.2.14 | 208.67.220.220 |
Mar 20, 2025 10:23:28.187886953 CET | 53 | 57724 | 208.67.220.220 | 192.168.2.14 |
Mar 20, 2025 10:23:28.190485001 CET | 55334 | 53 | 192.168.2.14 | 9.9.9.9 |
Mar 20, 2025 10:23:28.280018091 CET | 53 | 55334 | 9.9.9.9 | 192.168.2.14 |
Mar 20, 2025 10:23:28.281835079 CET | 39509 | 53 | 192.168.2.14 | 4.2.2.1 |
Mar 20, 2025 10:23:28.376868010 CET | 53 | 39509 | 4.2.2.1 | 192.168.2.14 |
Mar 20, 2025 10:23:28.378521919 CET | 50084 | 53 | 192.168.2.14 | 180.76.76.76 |
Mar 20, 2025 10:23:28.699127913 CET | 53 | 50084 | 180.76.76.76 | 192.168.2.14 |
Mar 20, 2025 10:23:28.700829029 CET | 43018 | 53 | 192.168.2.14 | 185.85.15.34 |
Mar 20, 2025 10:23:35.709156036 CET | 60671 | 53 | 192.168.2.14 | 8.8.8.8 |
Mar 20, 2025 10:23:36.035931110 CET | 53 | 60671 | 8.8.8.8 | 192.168.2.14 |
Mar 20, 2025 10:23:36.038250923 CET | 49316 | 53 | 192.168.2.14 | 1.1.1.1 |
Mar 20, 2025 10:23:36.265458107 CET | 53 | 49316 | 1.1.1.1 | 192.168.2.14 |
Mar 20, 2025 10:23:36.267591000 CET | 53797 | 53 | 192.168.2.14 | 208.67.222.222 |
Mar 20, 2025 10:23:36.359885931 CET | 53 | 53797 | 208.67.222.222 | 192.168.2.14 |
Mar 20, 2025 10:23:36.361749887 CET | 41413 | 53 | 192.168.2.14 | 208.67.220.220 |
Mar 20, 2025 10:23:36.454483032 CET | 53 | 41413 | 208.67.220.220 | 192.168.2.14 |
Mar 20, 2025 10:23:36.456042051 CET | 54515 | 53 | 192.168.2.14 | 9.9.9.9 |
Mar 20, 2025 10:23:36.546492100 CET | 53 | 54515 | 9.9.9.9 | 192.168.2.14 |
Mar 20, 2025 10:23:36.549379110 CET | 44171 | 53 | 192.168.2.14 | 4.2.2.1 |
Mar 20, 2025 10:23:36.643956900 CET | 53 | 44171 | 4.2.2.1 | 192.168.2.14 |
Mar 20, 2025 10:23:36.646393061 CET | 52253 | 53 | 192.168.2.14 | 180.76.76.76 |
Mar 20, 2025 10:23:36.956720114 CET | 53 | 52253 | 180.76.76.76 | 192.168.2.14 |
Mar 20, 2025 10:23:36.958728075 CET | 36057 | 53 | 192.168.2.14 | 185.85.15.34 |
Mar 20, 2025 10:23:43.967400074 CET | 44947 | 53 | 192.168.2.14 | 8.8.8.8 |
Mar 20, 2025 10:23:44.293323040 CET | 53 | 44947 | 8.8.8.8 | 192.168.2.14 |
Mar 20, 2025 10:23:44.295754910 CET | 58209 | 53 | 192.168.2.14 | 1.1.1.1 |
Mar 20, 2025 10:23:44.514497995 CET | 53 | 58209 | 1.1.1.1 | 192.168.2.14 |
Mar 20, 2025 10:23:44.516638994 CET | 56126 | 53 | 192.168.2.14 | 208.67.222.222 |
Mar 20, 2025 10:23:44.606328011 CET | 53 | 56126 | 208.67.222.222 | 192.168.2.14 |
Mar 20, 2025 10:23:44.608522892 CET | 45187 | 53 | 192.168.2.14 | 208.67.220.220 |
Mar 20, 2025 10:23:44.698710918 CET | 53 | 45187 | 208.67.220.220 | 192.168.2.14 |
Mar 20, 2025 10:23:44.700403929 CET | 39157 | 53 | 192.168.2.14 | 9.9.9.9 |
Mar 20, 2025 10:23:44.789787054 CET | 53 | 39157 | 9.9.9.9 | 192.168.2.14 |
Mar 20, 2025 10:23:44.792078972 CET | 32810 | 53 | 192.168.2.14 | 4.2.2.1 |
Mar 20, 2025 10:23:44.888271093 CET | 53 | 32810 | 4.2.2.1 | 192.168.2.14 |
Mar 20, 2025 10:23:44.890384912 CET | 41487 | 53 | 192.168.2.14 | 180.76.76.76 |
Mar 20, 2025 10:23:45.213430882 CET | 53 | 41487 | 180.76.76.76 | 192.168.2.14 |
Mar 20, 2025 10:23:45.215389013 CET | 53057 | 53 | 192.168.2.14 | 185.85.15.34 |
Mar 20, 2025 10:23:52.220839024 CET | 57418 | 53 | 192.168.2.14 | 8.8.8.8 |
Mar 20, 2025 10:23:52.380983114 CET | 53 | 57418 | 8.8.8.8 | 192.168.2.14 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Mar 20, 2025 10:21:46.847572088 CET | 192.168.2.14 | 8.8.8.8 | 0x7f8b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:21:47.174808979 CET | 192.168.2.14 | 1.1.1.1 | 0x7f8b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:21:47.275284052 CET | 192.168.2.14 | 208.67.222.222 | 0x7f8b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:21:47.366811037 CET | 192.168.2.14 | 208.67.220.220 | 0x7f8b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:21:47.615823984 CET | 192.168.2.14 | 9.9.9.9 | 0x7f8b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:21:47.817322969 CET | 192.168.2.14 | 4.2.2.1 | 0x7f8b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:21:47.920614004 CET | 192.168.2.14 | 180.76.76.76 | 0x7f8b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:21:48.225738049 CET | 192.168.2.14 | 185.85.15.34 | 0x7f8b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:21:55.233217001 CET | 192.168.2.14 | 8.8.8.8 | 0x309f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:21:55.786212921 CET | 192.168.2.14 | 1.1.1.1 | 0x309f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:21:56.018903017 CET | 192.168.2.14 | 208.67.222.222 | 0x309f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:21:56.111500978 CET | 192.168.2.14 | 208.67.220.220 | 0x309f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:21:56.203895092 CET | 192.168.2.14 | 9.9.9.9 | 0x309f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:21:56.294796944 CET | 192.168.2.14 | 4.2.2.1 | 0x309f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:21:56.390516996 CET | 192.168.2.14 | 180.76.76.76 | 0x309f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:21:56.711922884 CET | 192.168.2.14 | 185.85.15.34 | 0x309f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:22:03.720177889 CET | 192.168.2.14 | 8.8.8.8 | 0xfd20 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:22:33.927144051 CET | 192.168.2.14 | 8.8.8.8 | 0x76c8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:22:57.249438047 CET | 192.168.2.14 | 8.8.8.8 | 0x4b09 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:27.487025023 CET | 192.168.2.14 | 8.8.8.8 | 0x42e7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:27.784739971 CET | 192.168.2.14 | 1.1.1.1 | 0x42e7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:28.006055117 CET | 192.168.2.14 | 208.67.222.222 | 0x42e7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:28.098166943 CET | 192.168.2.14 | 208.67.220.220 | 0x42e7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:28.190485001 CET | 192.168.2.14 | 9.9.9.9 | 0x42e7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:28.281835079 CET | 192.168.2.14 | 4.2.2.1 | 0x42e7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:28.378521919 CET | 192.168.2.14 | 180.76.76.76 | 0x42e7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:28.700829029 CET | 192.168.2.14 | 185.85.15.34 | 0x42e7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:35.709156036 CET | 192.168.2.14 | 8.8.8.8 | 0x992b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:36.038250923 CET | 192.168.2.14 | 1.1.1.1 | 0x992b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:36.267591000 CET | 192.168.2.14 | 208.67.222.222 | 0x992b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:36.361749887 CET | 192.168.2.14 | 208.67.220.220 | 0x992b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:36.456042051 CET | 192.168.2.14 | 9.9.9.9 | 0x992b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:36.549379110 CET | 192.168.2.14 | 4.2.2.1 | 0x992b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:36.646393061 CET | 192.168.2.14 | 180.76.76.76 | 0x992b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:36.958728075 CET | 192.168.2.14 | 185.85.15.34 | 0x992b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:43.967400074 CET | 192.168.2.14 | 8.8.8.8 | 0x6450 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:44.295754910 CET | 192.168.2.14 | 1.1.1.1 | 0x6450 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:44.516638994 CET | 192.168.2.14 | 208.67.222.222 | 0x6450 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:44.608522892 CET | 192.168.2.14 | 208.67.220.220 | 0x6450 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:44.700403929 CET | 192.168.2.14 | 9.9.9.9 | 0x6450 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:44.792078972 CET | 192.168.2.14 | 4.2.2.1 | 0x6450 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:44.890384912 CET | 192.168.2.14 | 180.76.76.76 | 0x6450 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:45.215389013 CET | 192.168.2.14 | 185.85.15.34 | 0x6450 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:52.220839024 CET | 192.168.2.14 | 8.8.8.8 | 0x8d1 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Mar 20, 2025 10:21:47.144064903 CET | 8.8.8.8 | 192.168.2.14 | 0x7f8b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:21:47.273695946 CET | 1.1.1.1 | 192.168.2.14 | 0x7f8b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:21:47.364981890 CET | 208.67.222.222 | 192.168.2.14 | 0x7f8b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:21:47.614489079 CET | 208.67.220.220 | 192.168.2.14 | 0x7f8b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:21:47.814487934 CET | 9.9.9.9 | 192.168.2.14 | 0x7f8b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:21:47.918853998 CET | 4.2.2.1 | 192.168.2.14 | 0x7f8b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:21:48.222465992 CET | 180.76.76.76 | 192.168.2.14 | 0x7f8b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:21:55.783859968 CET | 8.8.8.8 | 192.168.2.14 | 0x309f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:21:56.016938925 CET | 1.1.1.1 | 192.168.2.14 | 0x309f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:21:56.109606028 CET | 208.67.222.222 | 192.168.2.14 | 0x309f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:21:56.202219009 CET | 208.67.220.220 | 192.168.2.14 | 0x309f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:21:56.293184996 CET | 9.9.9.9 | 192.168.2.14 | 0x309f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:21:56.388943911 CET | 4.2.2.1 | 192.168.2.14 | 0x309f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:21:56.709707975 CET | 180.76.76.76 | 192.168.2.14 | 0x309f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:22:03.820553064 CET | 8.8.8.8 | 192.168.2.14 | 0xfd20 | No error (0) | 77.232.36.152 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:03.820553064 CET | 8.8.8.8 | 192.168.2.14 | 0xfd20 | No error (0) | 91.142.78.22 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:03.820553064 CET | 8.8.8.8 | 192.168.2.14 | 0xfd20 | No error (0) | 77.232.41.24 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:03.820553064 CET | 8.8.8.8 | 192.168.2.14 | 0xfd20 | No error (0) | 91.142.77.13 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:03.820553064 CET | 8.8.8.8 | 192.168.2.14 | 0xfd20 | No error (0) | 77.232.39.221 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:03.820553064 CET | 8.8.8.8 | 192.168.2.14 | 0xfd20 | No error (0) | 77.232.42.137 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:03.820553064 CET | 8.8.8.8 | 192.168.2.14 | 0xfd20 | No error (0) | 77.232.39.139 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:03.820553064 CET | 8.8.8.8 | 192.168.2.14 | 0xfd20 | No error (0) | 77.232.36.191 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:03.820553064 CET | 8.8.8.8 | 192.168.2.14 | 0xfd20 | No error (0) | 185.173.37.56 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:03.820553064 CET | 8.8.8.8 | 192.168.2.14 | 0xfd20 | No error (0) | 91.142.77.79 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:34.051877022 CET | 8.8.8.8 | 192.168.2.14 | 0x76c8 | No error (0) | 77.232.42.137 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:34.051877022 CET | 8.8.8.8 | 192.168.2.14 | 0x76c8 | No error (0) | 91.142.77.79 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:34.051877022 CET | 8.8.8.8 | 192.168.2.14 | 0x76c8 | No error (0) | 77.232.39.221 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:34.051877022 CET | 8.8.8.8 | 192.168.2.14 | 0x76c8 | No error (0) | 77.232.39.139 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:34.051877022 CET | 8.8.8.8 | 192.168.2.14 | 0x76c8 | No error (0) | 91.142.78.22 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:34.051877022 CET | 8.8.8.8 | 192.168.2.14 | 0x76c8 | No error (0) | 77.232.36.152 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:34.051877022 CET | 8.8.8.8 | 192.168.2.14 | 0x76c8 | No error (0) | 185.173.37.56 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:34.051877022 CET | 8.8.8.8 | 192.168.2.14 | 0x76c8 | No error (0) | 91.142.77.13 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:34.051877022 CET | 8.8.8.8 | 192.168.2.14 | 0x76c8 | No error (0) | 77.232.36.191 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:34.051877022 CET | 8.8.8.8 | 192.168.2.14 | 0x76c8 | No error (0) | 77.232.41.24 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:57.345278978 CET | 8.8.8.8 | 192.168.2.14 | 0x4b09 | No error (0) | 77.232.41.24 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:57.345278978 CET | 8.8.8.8 | 192.168.2.14 | 0x4b09 | No error (0) | 91.142.77.79 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:57.345278978 CET | 8.8.8.8 | 192.168.2.14 | 0x4b09 | No error (0) | 77.232.36.152 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:57.345278978 CET | 8.8.8.8 | 192.168.2.14 | 0x4b09 | No error (0) | 77.232.36.191 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:57.345278978 CET | 8.8.8.8 | 192.168.2.14 | 0x4b09 | No error (0) | 91.142.78.22 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:57.345278978 CET | 8.8.8.8 | 192.168.2.14 | 0x4b09 | No error (0) | 77.232.39.221 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:57.345278978 CET | 8.8.8.8 | 192.168.2.14 | 0x4b09 | No error (0) | 91.142.77.13 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:57.345278978 CET | 8.8.8.8 | 192.168.2.14 | 0x4b09 | No error (0) | 185.173.37.56 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:57.345278978 CET | 8.8.8.8 | 192.168.2.14 | 0x4b09 | No error (0) | 77.232.42.137 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:22:57.345278978 CET | 8.8.8.8 | 192.168.2.14 | 0x4b09 | No error (0) | 77.232.39.139 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:23:27.782386065 CET | 8.8.8.8 | 192.168.2.14 | 0x42e7 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:28.002958059 CET | 1.1.1.1 | 192.168.2.14 | 0x42e7 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:28.095468044 CET | 208.67.222.222 | 192.168.2.14 | 0x42e7 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:28.187886953 CET | 208.67.220.220 | 192.168.2.14 | 0x42e7 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:28.280018091 CET | 9.9.9.9 | 192.168.2.14 | 0x42e7 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:28.376868010 CET | 4.2.2.1 | 192.168.2.14 | 0x42e7 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:28.699127913 CET | 180.76.76.76 | 192.168.2.14 | 0x42e7 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:36.035931110 CET | 8.8.8.8 | 192.168.2.14 | 0x992b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:36.265458107 CET | 1.1.1.1 | 192.168.2.14 | 0x992b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:36.359885931 CET | 208.67.222.222 | 192.168.2.14 | 0x992b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:36.454483032 CET | 208.67.220.220 | 192.168.2.14 | 0x992b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:36.546492100 CET | 9.9.9.9 | 192.168.2.14 | 0x992b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:36.643956900 CET | 4.2.2.1 | 192.168.2.14 | 0x992b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:36.956720114 CET | 180.76.76.76 | 192.168.2.14 | 0x992b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:44.293323040 CET | 8.8.8.8 | 192.168.2.14 | 0x6450 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:44.514497995 CET | 1.1.1.1 | 192.168.2.14 | 0x6450 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:44.606328011 CET | 208.67.222.222 | 192.168.2.14 | 0x6450 | No error (0) | 146.112.61.108 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:23:44.698710918 CET | 208.67.220.220 | 192.168.2.14 | 0x6450 | No error (0) | 146.112.61.108 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:23:44.789787054 CET | 9.9.9.9 | 192.168.2.14 | 0x6450 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:44.888271093 CET | 4.2.2.1 | 192.168.2.14 | 0x6450 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:45.213430882 CET | 180.76.76.76 | 192.168.2.14 | 0x6450 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 10:23:52.380983114 CET | 8.8.8.8 | 192.168.2.14 | 0x8d1 | No error (0) | 77.232.42.137 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:23:52.380983114 CET | 8.8.8.8 | 192.168.2.14 | 0x8d1 | No error (0) | 77.232.36.152 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:23:52.380983114 CET | 8.8.8.8 | 192.168.2.14 | 0x8d1 | No error (0) | 77.232.39.221 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:23:52.380983114 CET | 8.8.8.8 | 192.168.2.14 | 0x8d1 | No error (0) | 185.173.37.56 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:23:52.380983114 CET | 8.8.8.8 | 192.168.2.14 | 0x8d1 | No error (0) | 77.232.41.24 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:23:52.380983114 CET | 8.8.8.8 | 192.168.2.14 | 0x8d1 | No error (0) | 91.142.77.13 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:23:52.380983114 CET | 8.8.8.8 | 192.168.2.14 | 0x8d1 | No error (0) | 91.142.78.22 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:23:52.380983114 CET | 8.8.8.8 | 192.168.2.14 | 0x8d1 | No error (0) | 77.232.39.139 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:23:52.380983114 CET | 8.8.8.8 | 192.168.2.14 | 0x8d1 | No error (0) | 91.142.77.79 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 10:23:52.380983114 CET | 8.8.8.8 | 192.168.2.14 | 0x8d1 | No error (0) | 77.232.36.191 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 09:21:46 |
Start date (UTC): | 20/03/2025 |
Path: | /tmp/hiss.arm7.elf |
Arguments: | /tmp/hiss.arm7.elf |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 09:21:46 |
Start date (UTC): | 20/03/2025 |
Path: | /tmp/hiss.arm7.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 09:21:46 |
Start date (UTC): | 20/03/2025 |
Path: | /tmp/hiss.arm7.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 09:21:46 |
Start date (UTC): | 20/03/2025 |
Path: | /tmp/hiss.arm7.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 09:23:17 |
Start date (UTC): | 20/03/2025 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 09:23:17 |
Start date (UTC): | 20/03/2025 |
Path: | /usr/bin/rm |
Arguments: | rm -f /tmp/tmp.t1zqtW19UR /tmp/tmp.lpFdIwojIb /tmp/tmp.SpSRDDLadQ |
File size: | 72056 bytes |
MD5 hash: | aa2b5496fdbfd88e38791ab81f90b95b |
Start time (UTC): | 09:23:17 |
Start date (UTC): | 20/03/2025 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 09:23:17 |
Start date (UTC): | 20/03/2025 |
Path: | /usr/bin/rm |
Arguments: | rm -f /tmp/tmp.t1zqtW19UR /tmp/tmp.lpFdIwojIb /tmp/tmp.SpSRDDLadQ |
File size: | 72056 bytes |
MD5 hash: | aa2b5496fdbfd88e38791ab81f90b95b |