Edit tour
Linux
Analysis Report
SecuriteInfo.com.ELF.Mirai-CVD.30330.5069.elf
Overview
General Information
Sample name: | SecuriteInfo.com.ELF.Mirai-CVD.30330.5069.elf |
Analysis ID: | 1528452 |
MD5: | 20e936a36fac2fccaa27d081556cda28 |
SHA1: | b177cfe525b78f07f97bb031165f5704579ec752 |
SHA256: | 88caf6c4d21f2ed55c56aa451d3fced4b7f24248a9d196af588d644e5ea8d400 |
Tags: | elf |
Infos: |
Detection
Score: | 60 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Connects to many ports of the same IP (likely port scanning)
Opens /sys/class/net/* files useful for querying network interface information
Performs DNS TXT record lookups
Sample deletes itself
Sample scans a subnet
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1528452 |
Start date and time: | 2024-10-07 22:53:23 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 45s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | SecuriteInfo.com.ELF.Mirai-CVD.30330.5069.elf |
Detection: | MAL |
Classification: | mal60.spre.troj.spyw.evad.linELF@0/0@1/0 |
- VT rate limit hit for: SecuriteInfo.com.ELF.Mirai-CVD.30330.5069.elf
Command: | /tmp/SecuriteInfo.com.ELF.Mirai-CVD.30330.5069.elf |
PID: | 5446 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | Firmware update in progress |
Standard Error: |
- system is lnxubuntu20
- SecuriteInfo.com.ELF.Mirai-CVD.30330.5069.elf New Fork (PID: 5448, Parent: 5446)
- SecuriteInfo.com.ELF.Mirai-CVD.30330.5069.elf New Fork (PID: 5450, Parent: 5448)
- cleanup
⊘No yara matches
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
Networking |
---|
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Opens: | Jump to behavior | ||
Source: | Opens: | Jump to behavior | ||
Source: | Opens: | Jump to behavior | ||
Source: | Opens: | Jump to behavior | ||
Source: | Opens: | Jump to behavior |
Source: | Subnet 5.230.228.0/24: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | .symtab present: |
Source: | Classification label: |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | DNS traffic detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | 1 File Deletion | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | 1 Network Service Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 2 Application Layer Protocol | Traffic Duplication | Data Destruction |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
5% | ReversingLabs | Linux.Trojan.Mirai |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
iranistrash.libre | unknown | unknown | true | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
5.230.171.9 | unknown | Germany | 12586 | ASGHOSTNETDE | false | |
5.230.122.81 | unknown | Germany | 12586 | ASGHOSTNETDE | false | |
5.230.122.82 | unknown | Germany | 12586 | ASGHOSTNETDE | true | |
5.230.122.80 | unknown | Germany | 12586 | ASGHOSTNETDE | true | |
5.230.228.47 | unknown | Germany | 12586 | ASGHOSTNETDE | true | |
172.217.192.127 | unknown | United States | 15169 | GOOGLEUS | false | |
5.230.228.42 | unknown | Germany | 12586 | ASGHOSTNETDE | true | |
5.230.228.23 | unknown | Germany | 12586 | ASGHOSTNETDE | true | |
5.230.228.44 | unknown | Germany | 12586 | ASGHOSTNETDE | true | |
185.248.144.209 | unknown | France | 31531 | POINT-ASUA | false | |
5.230.229.83 | unknown | Germany | 12586 | ASGHOSTNETDE | true | |
5.230.228.62 | unknown | Germany | 12586 | ASGHOSTNETDE | true | |
194.156.98.15 | unknown | Russian Federation | 135330 | ADCDATACOM-AS-APADCDATACOMHK | true | |
5.230.118.247 | unknown | Germany | 12586 | ASGHOSTNETDE | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
5.230.228.42 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
5.230.171.9 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
5.230.122.81 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
5.230.122.82 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
5.230.122.80 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
5.230.228.47 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
⊘No context
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
ASGHOSTNETDE | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Phisher | Browse |
| ||
ASGHOSTNETDE | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Phisher | Browse |
| ||
ASGHOSTNETDE | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Phisher | Browse |
| ||
ASGHOSTNETDE | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Phisher | Browse |
| ||
ASGHOSTNETDE | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Phisher | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 6.247501727193921 |
TrID: |
|
File name: | SecuriteInfo.com.ELF.Mirai-CVD.30330.5069.elf |
File size: | 66'548 bytes |
MD5: | 20e936a36fac2fccaa27d081556cda28 |
SHA1: | b177cfe525b78f07f97bb031165f5704579ec752 |
SHA256: | 88caf6c4d21f2ed55c56aa451d3fced4b7f24248a9d196af588d644e5ea8d400 |
SHA512: | e2e94ddd981e65208bf199923a65caec9a7aa40cd9b57cf5bd2dd24653d498b13ac63e47d704de8e38657df844f186c0b8f1bdd3c7b39183addf517a6a89a466 |
SSDEEP: | 1536:in3D3b343qZzWKxmgITpJZMaZW5D0fB9QP1SLkp3+I:in3D3b3434ySIVjMND4U9SLkpOI |
TLSH: | AB535B42726C0C53D1A75AB4393F27E4D3EEE6A025B0BB89254FAB4AC635D7500C6EDC |
File Content Preview: | .ELF...........................4.........4. ...(..........................................................%.........dt.Q.............................!..|......$H...H..m...$8!. |...N.. .!..|.......?.............../...@..\?........+../...A..$8...})......N.. |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 66028 |
Section Header Size: | 40 |
Number of Section Headers: | 13 |
Header String Table Index: | 12 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x10000094 | 0x94 | 0x24 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x100000b8 | 0xb8 | 0xf4c4 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.fini | PROGBITS | 0x1000f57c | 0xf57c | 0x20 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x1000f59c | 0xf59c | 0x770 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.eh_frame | PROGBITS | 0x1000fd0c | 0xfd0c | 0x4 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ctors | PROGBITS | 0x10010000 | 0x10000 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x10010008 | 0x10008 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x10010018 | 0x10018 | 0x158 | 0x0 | 0x3 | WA | 0 | 0 | 8 |
.sdata | PROGBITS | 0x10010170 | 0x10170 | 0x24 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.sbss | NOBITS | 0x10010194 | 0x10194 | 0x7c | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x10010210 | 0x10194 | 0x239c | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.shstrtab | STRTAB | 0x0 | 0x10194 | 0x55 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x10000000 | 0x10000000 | 0xfd10 | 0xfd10 | 6.3312 | 0x5 | R E | 0x10000 | .init .text .fini .rodata .eh_frame | |
LOAD | 0x10000 | 0x10010000 | 0x10010000 | 0x194 | 0x25ac | 1.2354 | 0x6 | RW | 0x10000 | .ctors .dtors .data .sdata .sbss .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 7, 2024 22:54:24.330672979 CEST | 57436 | 34567 | 192.168.2.13 | 5.230.122.80 |
Oct 7, 2024 22:54:24.335769892 CEST | 34567 | 57436 | 5.230.122.80 | 192.168.2.13 |
Oct 7, 2024 22:54:24.335827112 CEST | 57436 | 34567 | 192.168.2.13 | 5.230.122.80 |
Oct 7, 2024 22:54:24.336276054 CEST | 57436 | 34567 | 192.168.2.13 | 5.230.122.80 |
Oct 7, 2024 22:54:24.341237068 CEST | 34567 | 57436 | 5.230.122.80 | 192.168.2.13 |
Oct 7, 2024 22:54:26.532083035 CEST | 34567 | 57436 | 5.230.122.80 | 192.168.2.13 |
Oct 7, 2024 22:54:26.532500029 CEST | 57436 | 34567 | 192.168.2.13 | 5.230.122.80 |
Oct 7, 2024 22:54:26.532644987 CEST | 57436 | 34567 | 192.168.2.13 | 5.230.122.80 |
Oct 7, 2024 22:54:26.537733078 CEST | 34567 | 57436 | 5.230.122.80 | 192.168.2.13 |
Oct 7, 2024 22:54:28.535244942 CEST | 33740 | 3724 | 192.168.2.13 | 5.230.228.62 |
Oct 7, 2024 22:54:28.540477991 CEST | 3724 | 33740 | 5.230.228.62 | 192.168.2.13 |
Oct 7, 2024 22:54:28.540589094 CEST | 33740 | 3724 | 192.168.2.13 | 5.230.228.62 |
Oct 7, 2024 22:54:28.540589094 CEST | 33740 | 3724 | 192.168.2.13 | 5.230.228.62 |
Oct 7, 2024 22:54:28.545866013 CEST | 3724 | 33740 | 5.230.228.62 | 192.168.2.13 |
Oct 7, 2024 22:54:30.230602026 CEST | 3724 | 33740 | 5.230.228.62 | 192.168.2.13 |
Oct 7, 2024 22:54:30.231237888 CEST | 33740 | 3724 | 192.168.2.13 | 5.230.228.62 |
Oct 7, 2024 22:54:30.236650944 CEST | 3724 | 33740 | 5.230.228.62 | 192.168.2.13 |
Oct 7, 2024 22:54:31.233231068 CEST | 33782 | 9000 | 192.168.2.13 | 5.230.118.247 |
Oct 7, 2024 22:54:31.407123089 CEST | 9000 | 33782 | 5.230.118.247 | 192.168.2.13 |
Oct 7, 2024 22:54:31.407218933 CEST | 33782 | 9000 | 192.168.2.13 | 5.230.118.247 |
Oct 7, 2024 22:54:31.407360077 CEST | 33782 | 9000 | 192.168.2.13 | 5.230.118.247 |
Oct 7, 2024 22:54:31.412734032 CEST | 9000 | 33782 | 5.230.118.247 | 192.168.2.13 |
Oct 7, 2024 22:54:33.303133965 CEST | 9000 | 33782 | 5.230.118.247 | 192.168.2.13 |
Oct 7, 2024 22:54:33.303842068 CEST | 33782 | 9000 | 192.168.2.13 | 5.230.118.247 |
Oct 7, 2024 22:54:33.308862925 CEST | 9000 | 33782 | 5.230.118.247 | 192.168.2.13 |
Oct 7, 2024 22:54:36.306809902 CEST | 53896 | 35000 | 192.168.2.13 | 5.230.122.80 |
Oct 7, 2024 22:54:36.312177896 CEST | 35000 | 53896 | 5.230.122.80 | 192.168.2.13 |
Oct 7, 2024 22:54:36.312280893 CEST | 53896 | 35000 | 192.168.2.13 | 5.230.122.80 |
Oct 7, 2024 22:54:36.312356949 CEST | 53896 | 35000 | 192.168.2.13 | 5.230.122.80 |
Oct 7, 2024 22:54:36.317241907 CEST | 35000 | 53896 | 5.230.122.80 | 192.168.2.13 |
Oct 7, 2024 22:54:38.495609999 CEST | 35000 | 53896 | 5.230.122.80 | 192.168.2.13 |
Oct 7, 2024 22:54:38.496104956 CEST | 53896 | 35000 | 192.168.2.13 | 5.230.122.80 |
Oct 7, 2024 22:54:38.502336025 CEST | 35000 | 53896 | 5.230.122.80 | 192.168.2.13 |
Oct 7, 2024 22:54:39.499243021 CEST | 44374 | 554 | 192.168.2.13 | 5.230.122.80 |
Oct 7, 2024 22:54:39.504581928 CEST | 554 | 44374 | 5.230.122.80 | 192.168.2.13 |
Oct 7, 2024 22:54:39.504677057 CEST | 44374 | 554 | 192.168.2.13 | 5.230.122.80 |
Oct 7, 2024 22:54:39.504764080 CEST | 44374 | 554 | 192.168.2.13 | 5.230.122.80 |
Oct 7, 2024 22:54:39.509695053 CEST | 554 | 44374 | 5.230.122.80 | 192.168.2.13 |
Oct 7, 2024 22:54:41.707293987 CEST | 554 | 44374 | 5.230.122.80 | 192.168.2.13 |
Oct 7, 2024 22:54:41.707984924 CEST | 44374 | 554 | 192.168.2.13 | 5.230.122.80 |
Oct 7, 2024 22:54:41.716512918 CEST | 554 | 44374 | 5.230.122.80 | 192.168.2.13 |
Oct 7, 2024 22:54:44.710541010 CEST | 55364 | 5000 | 192.168.2.13 | 5.230.171.9 |
Oct 7, 2024 22:54:44.715775967 CEST | 5000 | 55364 | 5.230.171.9 | 192.168.2.13 |
Oct 7, 2024 22:54:44.715852022 CEST | 55364 | 5000 | 192.168.2.13 | 5.230.171.9 |
Oct 7, 2024 22:54:44.715900898 CEST | 55364 | 5000 | 192.168.2.13 | 5.230.171.9 |
Oct 7, 2024 22:54:44.720951080 CEST | 5000 | 55364 | 5.230.171.9 | 192.168.2.13 |
Oct 7, 2024 22:54:46.586050987 CEST | 5000 | 55364 | 5.230.171.9 | 192.168.2.13 |
Oct 7, 2024 22:54:46.586479902 CEST | 55364 | 5000 | 192.168.2.13 | 5.230.171.9 |
Oct 7, 2024 22:54:46.591468096 CEST | 5000 | 55364 | 5.230.171.9 | 192.168.2.13 |
Oct 7, 2024 22:54:48.588829041 CEST | 33746 | 10001 | 192.168.2.13 | 5.230.228.62 |
Oct 7, 2024 22:54:48.594183922 CEST | 10001 | 33746 | 5.230.228.62 | 192.168.2.13 |
Oct 7, 2024 22:54:48.594278097 CEST | 33746 | 10001 | 192.168.2.13 | 5.230.228.62 |
Oct 7, 2024 22:54:48.594321012 CEST | 33746 | 10001 | 192.168.2.13 | 5.230.228.62 |
Oct 7, 2024 22:54:48.599411011 CEST | 10001 | 33746 | 5.230.228.62 | 192.168.2.13 |
Oct 7, 2024 22:54:50.491262913 CEST | 10001 | 33746 | 5.230.228.62 | 192.168.2.13 |
Oct 7, 2024 22:54:50.492368937 CEST | 33746 | 10001 | 192.168.2.13 | 5.230.228.62 |
Oct 7, 2024 22:54:50.498527050 CEST | 10001 | 33746 | 5.230.228.62 | 192.168.2.13 |
Oct 7, 2024 22:54:53.494745970 CEST | 49748 | 554 | 192.168.2.13 | 5.230.122.81 |
Oct 7, 2024 22:54:53.709748983 CEST | 554 | 49748 | 5.230.122.81 | 192.168.2.13 |
Oct 7, 2024 22:54:53.709952116 CEST | 49748 | 554 | 192.168.2.13 | 5.230.122.81 |
Oct 7, 2024 22:54:53.709952116 CEST | 49748 | 554 | 192.168.2.13 | 5.230.122.81 |
Oct 7, 2024 22:54:53.714993000 CEST | 554 | 49748 | 5.230.122.81 | 192.168.2.13 |
Oct 7, 2024 22:55:03.720153093 CEST | 49748 | 554 | 192.168.2.13 | 5.230.122.81 |
Oct 7, 2024 22:55:03.768018961 CEST | 554 | 49748 | 5.230.122.81 | 192.168.2.13 |
Oct 7, 2024 22:55:06.722767115 CEST | 38452 | 10554 | 192.168.2.13 | 5.230.228.44 |
Oct 7, 2024 22:55:06.728101969 CEST | 10554 | 38452 | 5.230.228.44 | 192.168.2.13 |
Oct 7, 2024 22:55:06.728188038 CEST | 38452 | 10554 | 192.168.2.13 | 5.230.228.44 |
Oct 7, 2024 22:55:06.728250980 CEST | 38452 | 10554 | 192.168.2.13 | 5.230.228.44 |
Oct 7, 2024 22:55:06.733278036 CEST | 10554 | 38452 | 5.230.228.44 | 192.168.2.13 |
Oct 7, 2024 22:55:07.712327957 CEST | 554 | 49748 | 5.230.122.81 | 192.168.2.13 |
Oct 7, 2024 22:55:07.712429047 CEST | 49748 | 554 | 192.168.2.13 | 5.230.122.81 |
Oct 7, 2024 22:55:08.405745983 CEST | 10554 | 38452 | 5.230.228.44 | 192.168.2.13 |
Oct 7, 2024 22:55:08.406464100 CEST | 38452 | 10554 | 192.168.2.13 | 5.230.228.44 |
Oct 7, 2024 22:55:08.411428928 CEST | 10554 | 38452 | 5.230.228.44 | 192.168.2.13 |
Oct 7, 2024 22:55:11.409215927 CEST | 60672 | 3544 | 192.168.2.13 | 5.230.118.247 |
Oct 7, 2024 22:55:12.225435972 CEST | 3544 | 60672 | 5.230.118.247 | 192.168.2.13 |
Oct 7, 2024 22:55:12.225800037 CEST | 60672 | 3544 | 192.168.2.13 | 5.230.118.247 |
Oct 7, 2024 22:55:12.225800037 CEST | 60672 | 3544 | 192.168.2.13 | 5.230.118.247 |
Oct 7, 2024 22:55:12.231852055 CEST | 3544 | 60672 | 5.230.118.247 | 192.168.2.13 |
Oct 7, 2024 22:55:14.081060886 CEST | 3544 | 60672 | 5.230.118.247 | 192.168.2.13 |
Oct 7, 2024 22:55:14.082010984 CEST | 60672 | 3544 | 192.168.2.13 | 5.230.118.247 |
Oct 7, 2024 22:55:14.087338924 CEST | 3544 | 60672 | 5.230.118.247 | 192.168.2.13 |
Oct 7, 2024 22:55:15.084295034 CEST | 40298 | 37777 | 192.168.2.13 | 5.230.122.82 |
Oct 7, 2024 22:55:15.089704990 CEST | 37777 | 40298 | 5.230.122.82 | 192.168.2.13 |
Oct 7, 2024 22:55:15.089823008 CEST | 40298 | 37777 | 192.168.2.13 | 5.230.122.82 |
Oct 7, 2024 22:55:15.089859009 CEST | 40298 | 37777 | 192.168.2.13 | 5.230.122.82 |
Oct 7, 2024 22:55:15.094748974 CEST | 37777 | 40298 | 5.230.122.82 | 192.168.2.13 |
Oct 7, 2024 22:55:17.301497936 CEST | 37777 | 40298 | 5.230.122.82 | 192.168.2.13 |
Oct 7, 2024 22:55:17.302309990 CEST | 40298 | 37777 | 192.168.2.13 | 5.230.122.82 |
Oct 7, 2024 22:55:17.308147907 CEST | 37777 | 40298 | 5.230.122.82 | 192.168.2.13 |
Oct 7, 2024 22:55:18.305381060 CEST | 59748 | 993 | 192.168.2.13 | 185.248.144.209 |
Oct 7, 2024 22:55:18.310424089 CEST | 993 | 59748 | 185.248.144.209 | 192.168.2.13 |
Oct 7, 2024 22:55:18.310561895 CEST | 59748 | 993 | 192.168.2.13 | 185.248.144.209 |
Oct 7, 2024 22:55:18.310606003 CEST | 59748 | 993 | 192.168.2.13 | 185.248.144.209 |
Oct 7, 2024 22:55:18.315479040 CEST | 993 | 59748 | 185.248.144.209 | 192.168.2.13 |
Oct 7, 2024 22:55:20.009318113 CEST | 993 | 59748 | 185.248.144.209 | 192.168.2.13 |
Oct 7, 2024 22:55:20.009927988 CEST | 59748 | 993 | 192.168.2.13 | 185.248.144.209 |
Oct 7, 2024 22:55:20.015213966 CEST | 993 | 59748 | 185.248.144.209 | 192.168.2.13 |
Oct 7, 2024 22:55:21.012618065 CEST | 54706 | 34567 | 192.168.2.13 | 194.156.98.15 |
Oct 7, 2024 22:55:21.017899990 CEST | 34567 | 54706 | 194.156.98.15 | 192.168.2.13 |
Oct 7, 2024 22:55:21.018110991 CEST | 54706 | 34567 | 192.168.2.13 | 194.156.98.15 |
Oct 7, 2024 22:55:21.018110991 CEST | 54706 | 34567 | 192.168.2.13 | 194.156.98.15 |
Oct 7, 2024 22:55:21.023011923 CEST | 34567 | 54706 | 194.156.98.15 | 192.168.2.13 |
Oct 7, 2024 22:55:23.001308918 CEST | 34567 | 54706 | 194.156.98.15 | 192.168.2.13 |
Oct 7, 2024 22:55:23.002077103 CEST | 54706 | 34567 | 192.168.2.13 | 194.156.98.15 |
Oct 7, 2024 22:55:23.008429050 CEST | 34567 | 54706 | 194.156.98.15 | 192.168.2.13 |
Oct 7, 2024 22:55:26.004729986 CEST | 40980 | 27015 | 192.168.2.13 | 5.230.171.9 |
Oct 7, 2024 22:55:26.010088921 CEST | 27015 | 40980 | 5.230.171.9 | 192.168.2.13 |
Oct 7, 2024 22:55:26.010178089 CEST | 40980 | 27015 | 192.168.2.13 | 5.230.171.9 |
Oct 7, 2024 22:55:26.010236025 CEST | 40980 | 27015 | 192.168.2.13 | 5.230.171.9 |
Oct 7, 2024 22:55:26.015048981 CEST | 27015 | 40980 | 5.230.171.9 | 192.168.2.13 |
Oct 7, 2024 22:55:28.031265020 CEST | 27015 | 40980 | 5.230.171.9 | 192.168.2.13 |
Oct 7, 2024 22:55:28.031824112 CEST | 40980 | 27015 | 192.168.2.13 | 5.230.171.9 |
Oct 7, 2024 22:55:28.036931038 CEST | 27015 | 40980 | 5.230.171.9 | 192.168.2.13 |
Oct 7, 2024 22:55:31.034636021 CEST | 37526 | 1935 | 192.168.2.13 | 5.230.122.82 |
Oct 7, 2024 22:55:31.040014029 CEST | 1935 | 37526 | 5.230.122.82 | 192.168.2.13 |
Oct 7, 2024 22:55:31.040110111 CEST | 37526 | 1935 | 192.168.2.13 | 5.230.122.82 |
Oct 7, 2024 22:55:31.040129900 CEST | 37526 | 1935 | 192.168.2.13 | 5.230.122.82 |
Oct 7, 2024 22:55:31.045099974 CEST | 1935 | 37526 | 5.230.122.82 | 192.168.2.13 |
Oct 7, 2024 22:55:33.237685919 CEST | 1935 | 37526 | 5.230.122.82 | 192.168.2.13 |
Oct 7, 2024 22:55:33.238061905 CEST | 37526 | 1935 | 192.168.2.13 | 5.230.122.82 |
Oct 7, 2024 22:55:33.244127035 CEST | 1935 | 37526 | 5.230.122.82 | 192.168.2.13 |
Oct 7, 2024 22:55:34.240395069 CEST | 56326 | 443 | 192.168.2.13 | 194.156.98.15 |
Oct 7, 2024 22:55:34.240458965 CEST | 443 | 56326 | 194.156.98.15 | 192.168.2.13 |
Oct 7, 2024 22:55:34.240514040 CEST | 56326 | 443 | 192.168.2.13 | 194.156.98.15 |
Oct 7, 2024 22:55:34.240771055 CEST | 56326 | 443 | 192.168.2.13 | 194.156.98.15 |
Oct 7, 2024 22:55:34.240783930 CEST | 443 | 56326 | 194.156.98.15 | 192.168.2.13 |
Oct 7, 2024 22:55:34.240842104 CEST | 443 | 56326 | 194.156.98.15 | 192.168.2.13 |
Oct 7, 2024 22:55:35.243110895 CEST | 52882 | 37777 | 192.168.2.13 | 5.230.122.81 |
Oct 7, 2024 22:55:35.248502016 CEST | 37777 | 52882 | 5.230.122.81 | 192.168.2.13 |
Oct 7, 2024 22:55:35.248635054 CEST | 52882 | 37777 | 192.168.2.13 | 5.230.122.81 |
Oct 7, 2024 22:55:35.248667955 CEST | 52882 | 37777 | 192.168.2.13 | 5.230.122.81 |
Oct 7, 2024 22:55:35.253592014 CEST | 37777 | 52882 | 5.230.122.81 | 192.168.2.13 |
Oct 7, 2024 22:55:37.415621996 CEST | 37777 | 52882 | 5.230.122.81 | 192.168.2.13 |
Oct 7, 2024 22:55:37.416568041 CEST | 52882 | 37777 | 192.168.2.13 | 5.230.122.81 |
Oct 7, 2024 22:55:37.421554089 CEST | 37777 | 52882 | 5.230.122.81 | 192.168.2.13 |
Oct 7, 2024 22:55:40.420120001 CEST | 36506 | 5000 | 192.168.2.13 | 5.230.228.47 |
Oct 7, 2024 22:55:40.425345898 CEST | 5000 | 36506 | 5.230.228.47 | 192.168.2.13 |
Oct 7, 2024 22:55:40.425482988 CEST | 36506 | 5000 | 192.168.2.13 | 5.230.228.47 |
Oct 7, 2024 22:55:40.425517082 CEST | 36506 | 5000 | 192.168.2.13 | 5.230.228.47 |
Oct 7, 2024 22:55:40.430466890 CEST | 5000 | 36506 | 5.230.228.47 | 192.168.2.13 |
Oct 7, 2024 22:55:42.112235069 CEST | 5000 | 36506 | 5.230.228.47 | 192.168.2.13 |
Oct 7, 2024 22:55:42.112648964 CEST | 36506 | 5000 | 192.168.2.13 | 5.230.228.47 |
Oct 7, 2024 22:55:42.117631912 CEST | 5000 | 36506 | 5.230.228.47 | 192.168.2.13 |
Oct 7, 2024 22:55:43.115163088 CEST | 42870 | 9000 | 192.168.2.13 | 185.248.144.209 |
Oct 7, 2024 22:55:43.120578051 CEST | 9000 | 42870 | 185.248.144.209 | 192.168.2.13 |
Oct 7, 2024 22:55:43.120723963 CEST | 42870 | 9000 | 192.168.2.13 | 185.248.144.209 |
Oct 7, 2024 22:55:43.120764017 CEST | 42870 | 9000 | 192.168.2.13 | 185.248.144.209 |
Oct 7, 2024 22:55:43.125730038 CEST | 9000 | 42870 | 185.248.144.209 | 192.168.2.13 |
Oct 7, 2024 22:55:44.885979891 CEST | 9000 | 42870 | 185.248.144.209 | 192.168.2.13 |
Oct 7, 2024 22:55:44.886423111 CEST | 42870 | 9000 | 192.168.2.13 | 185.248.144.209 |
Oct 7, 2024 22:55:44.891772032 CEST | 9000 | 42870 | 185.248.144.209 | 192.168.2.13 |
Oct 7, 2024 22:55:46.889069080 CEST | 37776 | 3724 | 192.168.2.13 | 5.230.229.83 |
Oct 7, 2024 22:55:46.894033909 CEST | 3724 | 37776 | 5.230.229.83 | 192.168.2.13 |
Oct 7, 2024 22:55:46.894165039 CEST | 37776 | 3724 | 192.168.2.13 | 5.230.229.83 |
Oct 7, 2024 22:55:46.894198895 CEST | 37776 | 3724 | 192.168.2.13 | 5.230.229.83 |
Oct 7, 2024 22:55:46.898957014 CEST | 3724 | 37776 | 5.230.229.83 | 192.168.2.13 |
Oct 7, 2024 22:55:48.602041960 CEST | 3724 | 37776 | 5.230.229.83 | 192.168.2.13 |
Oct 7, 2024 22:55:48.602358103 CEST | 37776 | 3724 | 192.168.2.13 | 5.230.229.83 |
Oct 7, 2024 22:55:48.607280970 CEST | 3724 | 37776 | 5.230.229.83 | 192.168.2.13 |
Oct 7, 2024 22:55:49.604971886 CEST | 42252 | 7000 | 192.168.2.13 | 5.230.228.23 |
Oct 7, 2024 22:55:49.610165119 CEST | 7000 | 42252 | 5.230.228.23 | 192.168.2.13 |
Oct 7, 2024 22:55:49.610263109 CEST | 42252 | 7000 | 192.168.2.13 | 5.230.228.23 |
Oct 7, 2024 22:55:49.610305071 CEST | 42252 | 7000 | 192.168.2.13 | 5.230.228.23 |
Oct 7, 2024 22:55:49.615623951 CEST | 7000 | 42252 | 5.230.228.23 | 192.168.2.13 |
Oct 7, 2024 22:55:51.245600939 CEST | 7000 | 42252 | 5.230.228.23 | 192.168.2.13 |
Oct 7, 2024 22:55:51.245904922 CEST | 42252 | 7000 | 192.168.2.13 | 5.230.228.23 |
Oct 7, 2024 22:55:51.251132011 CEST | 7000 | 42252 | 5.230.228.23 | 192.168.2.13 |
Oct 7, 2024 22:55:52.248400927 CEST | 47176 | 3389 | 192.168.2.13 | 185.248.144.209 |
Oct 7, 2024 22:55:52.253918886 CEST | 3389 | 47176 | 185.248.144.209 | 192.168.2.13 |
Oct 7, 2024 22:55:52.254008055 CEST | 47176 | 3389 | 192.168.2.13 | 185.248.144.209 |
Oct 7, 2024 22:55:52.254079103 CEST | 47176 | 3389 | 192.168.2.13 | 185.248.144.209 |
Oct 7, 2024 22:55:52.259036064 CEST | 3389 | 47176 | 185.248.144.209 | 192.168.2.13 |
Oct 7, 2024 22:55:53.928747892 CEST | 3389 | 47176 | 185.248.144.209 | 192.168.2.13 |
Oct 7, 2024 22:55:53.929575920 CEST | 47176 | 3389 | 192.168.2.13 | 185.248.144.209 |
Oct 7, 2024 22:55:53.934583902 CEST | 3389 | 47176 | 185.248.144.209 | 192.168.2.13 |
Oct 7, 2024 22:55:56.932729006 CEST | 56458 | 9000 | 192.168.2.13 | 5.230.228.42 |
Oct 7, 2024 22:55:56.938528061 CEST | 9000 | 56458 | 5.230.228.42 | 192.168.2.13 |
Oct 7, 2024 22:55:56.938678026 CEST | 56458 | 9000 | 192.168.2.13 | 5.230.228.42 |
Oct 7, 2024 22:55:56.938729048 CEST | 56458 | 9000 | 192.168.2.13 | 5.230.228.42 |
Oct 7, 2024 22:55:56.943773985 CEST | 9000 | 56458 | 5.230.228.42 | 192.168.2.13 |
Oct 7, 2024 22:55:58.605042934 CEST | 9000 | 56458 | 5.230.228.42 | 192.168.2.13 |
Oct 7, 2024 22:55:58.605783939 CEST | 56458 | 9000 | 192.168.2.13 | 5.230.228.42 |
Oct 7, 2024 22:55:58.610696077 CEST | 9000 | 56458 | 5.230.228.42 | 192.168.2.13 |
Oct 7, 2024 22:56:01.608119965 CEST | 52406 | 27014 | 192.168.2.13 | 5.230.228.47 |
Oct 7, 2024 22:56:01.613284111 CEST | 27014 | 52406 | 5.230.228.47 | 192.168.2.13 |
Oct 7, 2024 22:56:01.613368034 CEST | 52406 | 27014 | 192.168.2.13 | 5.230.228.47 |
Oct 7, 2024 22:56:01.613401890 CEST | 52406 | 27014 | 192.168.2.13 | 5.230.228.47 |
Oct 7, 2024 22:56:01.618467093 CEST | 27014 | 52406 | 5.230.228.47 | 192.168.2.13 |
Oct 7, 2024 22:56:03.319843054 CEST | 27014 | 52406 | 5.230.228.47 | 192.168.2.13 |
Oct 7, 2024 22:56:03.320230007 CEST | 52406 | 27014 | 192.168.2.13 | 5.230.228.47 |
Oct 7, 2024 22:56:03.325202942 CEST | 27014 | 52406 | 5.230.228.47 | 192.168.2.13 |
Oct 7, 2024 22:56:04.321850061 CEST | 34178 | 2022 | 192.168.2.13 | 5.230.122.82 |
Oct 7, 2024 22:56:04.328851938 CEST | 2022 | 34178 | 5.230.122.82 | 192.168.2.13 |
Oct 7, 2024 22:56:04.328959942 CEST | 34178 | 2022 | 192.168.2.13 | 5.230.122.82 |
Oct 7, 2024 22:56:04.329097986 CEST | 34178 | 2022 | 192.168.2.13 | 5.230.122.82 |
Oct 7, 2024 22:56:04.335936069 CEST | 2022 | 34178 | 5.230.122.82 | 192.168.2.13 |
Oct 7, 2024 22:56:06.492357016 CEST | 2022 | 34178 | 5.230.122.82 | 192.168.2.13 |
Oct 7, 2024 22:56:06.492794037 CEST | 34178 | 2022 | 192.168.2.13 | 5.230.122.82 |
Oct 7, 2024 22:56:06.498449087 CEST | 2022 | 34178 | 5.230.122.82 | 192.168.2.13 |
Oct 7, 2024 22:56:07.494342089 CEST | 48558 | 993 | 192.168.2.13 | 5.230.122.82 |
Oct 7, 2024 22:56:07.500159025 CEST | 993 | 48558 | 5.230.122.82 | 192.168.2.13 |
Oct 7, 2024 22:56:07.500258923 CEST | 48558 | 993 | 192.168.2.13 | 5.230.122.82 |
Oct 7, 2024 22:56:07.500267982 CEST | 48558 | 993 | 192.168.2.13 | 5.230.122.82 |
Oct 7, 2024 22:56:07.505193949 CEST | 993 | 48558 | 5.230.122.82 | 192.168.2.13 |
Oct 7, 2024 22:56:09.675542116 CEST | 993 | 48558 | 5.230.122.82 | 192.168.2.13 |
Oct 7, 2024 22:56:09.676078081 CEST | 48558 | 993 | 192.168.2.13 | 5.230.122.82 |
Oct 7, 2024 22:56:09.681242943 CEST | 993 | 48558 | 5.230.122.82 | 192.168.2.13 |
Oct 7, 2024 22:56:10.678400993 CEST | 56826 | 9001 | 192.168.2.13 | 5.230.228.47 |
Oct 7, 2024 22:56:10.683911085 CEST | 9001 | 56826 | 5.230.228.47 | 192.168.2.13 |
Oct 7, 2024 22:56:10.684012890 CEST | 56826 | 9001 | 192.168.2.13 | 5.230.228.47 |
Oct 7, 2024 22:56:10.684068918 CEST | 56826 | 9001 | 192.168.2.13 | 5.230.228.47 |
Oct 7, 2024 22:56:10.689142942 CEST | 9001 | 56826 | 5.230.228.47 | 192.168.2.13 |
Oct 7, 2024 22:56:12.395282030 CEST | 9001 | 56826 | 5.230.228.47 | 192.168.2.13 |
Oct 7, 2024 22:56:12.396018028 CEST | 56826 | 9001 | 192.168.2.13 | 5.230.228.47 |
Oct 7, 2024 22:56:12.401541948 CEST | 9001 | 56826 | 5.230.228.47 | 192.168.2.13 |
Oct 7, 2024 22:56:15.398511887 CEST | 50490 | 27014 | 192.168.2.13 | 5.230.122.80 |
Oct 7, 2024 22:56:15.403450966 CEST | 27014 | 50490 | 5.230.122.80 | 192.168.2.13 |
Oct 7, 2024 22:56:15.403542995 CEST | 50490 | 27014 | 192.168.2.13 | 5.230.122.80 |
Oct 7, 2024 22:56:15.403595924 CEST | 50490 | 27014 | 192.168.2.13 | 5.230.122.80 |
Oct 7, 2024 22:56:15.408595085 CEST | 27014 | 50490 | 5.230.122.80 | 192.168.2.13 |
Oct 7, 2024 22:56:17.572134972 CEST | 27014 | 50490 | 5.230.122.80 | 192.168.2.13 |
Oct 7, 2024 22:56:17.572810888 CEST | 50490 | 27014 | 192.168.2.13 | 5.230.122.80 |
Oct 7, 2024 22:56:17.577872038 CEST | 27014 | 50490 | 5.230.122.80 | 192.168.2.13 |
Oct 7, 2024 22:56:19.575160027 CEST | 55806 | 22022 | 192.168.2.13 | 5.230.171.9 |
Oct 7, 2024 22:56:19.580463886 CEST | 22022 | 55806 | 5.230.171.9 | 192.168.2.13 |
Oct 7, 2024 22:56:19.580590010 CEST | 55806 | 22022 | 192.168.2.13 | 5.230.171.9 |
Oct 7, 2024 22:56:19.580661058 CEST | 55806 | 22022 | 192.168.2.13 | 5.230.171.9 |
Oct 7, 2024 22:56:19.585884094 CEST | 22022 | 55806 | 5.230.171.9 | 192.168.2.13 |
Oct 7, 2024 22:56:21.483623028 CEST | 22022 | 55806 | 5.230.171.9 | 192.168.2.13 |
Oct 7, 2024 22:56:21.484132051 CEST | 55806 | 22022 | 192.168.2.13 | 5.230.171.9 |
Oct 7, 2024 22:56:21.489331007 CEST | 22022 | 55806 | 5.230.171.9 | 192.168.2.13 |
Oct 7, 2024 22:56:23.486749887 CEST | 37898 | 5222 | 192.168.2.13 | 5.230.229.83 |
Oct 7, 2024 22:56:23.539033890 CEST | 5222 | 37898 | 5.230.229.83 | 192.168.2.13 |
Oct 7, 2024 22:56:23.539139032 CEST | 37898 | 5222 | 192.168.2.13 | 5.230.229.83 |
Oct 7, 2024 22:56:23.539365053 CEST | 37898 | 5222 | 192.168.2.13 | 5.230.229.83 |
Oct 7, 2024 22:56:23.544591904 CEST | 5222 | 37898 | 5.230.229.83 | 192.168.2.13 |
Oct 7, 2024 22:56:25.227859020 CEST | 5222 | 37898 | 5.230.229.83 | 192.168.2.13 |
Oct 7, 2024 22:56:25.228245020 CEST | 37898 | 5222 | 192.168.2.13 | 5.230.229.83 |
Oct 7, 2024 22:56:25.233165026 CEST | 5222 | 37898 | 5.230.229.83 | 192.168.2.13 |
Oct 7, 2024 22:56:28.230684996 CEST | 45154 | 993 | 192.168.2.13 | 5.230.228.62 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 7, 2024 22:54:23.754475117 CEST | 1299 | 3478 | 192.168.2.13 | 172.217.192.127 |
Oct 7, 2024 22:54:24.312252998 CEST | 3478 | 1299 | 172.217.192.127 | 192.168.2.13 |
Oct 7, 2024 22:54:24.319767952 CEST | 59943 | 53 | 192.168.2.13 | 51.77.149.139 |
Oct 7, 2024 22:54:24.328875065 CEST | 53 | 59943 | 51.77.149.139 | 192.168.2.13 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 7, 2024 22:54:24.319767952 CEST | 192.168.2.13 | 51.77.149.139 | 0xd72d | Standard query (0) | 16 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 7, 2024 22:54:24.328875065 CEST | 51.77.149.139 | 192.168.2.13 | 0xd72d | No error (0) | TXT (Text strings) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 20:54:19 |
Start date (UTC): | 07/10/2024 |
Path: | /tmp/SecuriteInfo.com.ELF.Mirai-CVD.30330.5069.elf |
Arguments: | /tmp/SecuriteInfo.com.ELF.Mirai-CVD.30330.5069.elf |
File size: | 5388968 bytes |
MD5 hash: | ae65271c943d3451b7f026d1fadccea6 |
Start time (UTC): | 20:54:22 |
Start date (UTC): | 07/10/2024 |
Path: | /tmp/SecuriteInfo.com.ELF.Mirai-CVD.30330.5069.elf |
Arguments: | - |
File size: | 5388968 bytes |
MD5 hash: | ae65271c943d3451b7f026d1fadccea6 |
Start time (UTC): | 20:54:23 |
Start date (UTC): | 07/10/2024 |
Path: | /tmp/SecuriteInfo.com.ELF.Mirai-CVD.30330.5069.elf |
Arguments: | - |
File size: | 5388968 bytes |
MD5 hash: | ae65271c943d3451b7f026d1fadccea6 |