Edit tour
Linux
Analysis Report
na.elf
Overview
General Information
Sample name: | na.elf |
Analysis ID: | 1528788 |
MD5: | e92707c5b799b98cd9e09166d58930f3 |
SHA1: | bbd8ffef109cb8a1b800209825f4f2491347a507 |
SHA256: | 355a6f5e6e0357f3a6440ca408bc9c67899753e1662c0dd92ae6b6de892391f5 |
Tags: | elfMiraiuser-abuse_ch |
Infos: |
Detection
Score: | 60 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1528788 |
Start date and time: | 2024-10-08 10:56:01 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 36s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | na.elf |
Detection: | MAL |
Classification: | mal60.troj.linELF@0/0@31/0 |
Command: | /tmp/na.elf |
PID: | 5514 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | zenci |
Standard Error: |
⊘No yara matches
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Networking |
---|
Source: | TCP traffic: |
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: |
Source: | .symtab present: |
Source: | Classification label: |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | Direct Volume Access | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 2 Application Layer Protocol | Traffic Duplication | Data Destruction |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
50% | ReversingLabs | Linux.Trojan.Mirai | ||
58% | Virustotal | Browse | ||
100% | Avira | EXP/ELF.Mirai.W |
⊘No Antivirus matches
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
14% | Virustotal | Browse |
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
enemybotnet.com | 93.123.39.105 | true | true |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
93.123.39.105 | enemybotnet.com | Bulgaria | 43561 | NET1-ASBG | true | |
185.125.190.26 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
93.123.39.105 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
185.125.190.26 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
enemybotnet.com | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
NET1-ASBG | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
CANONICAL-ASGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 5.4733988468823425 |
TrID: |
|
File name: | na.elf |
File size: | 80'712 bytes |
MD5: | e92707c5b799b98cd9e09166d58930f3 |
SHA1: | bbd8ffef109cb8a1b800209825f4f2491347a507 |
SHA256: | 355a6f5e6e0357f3a6440ca408bc9c67899753e1662c0dd92ae6b6de892391f5 |
SHA512: | 587f553c7719bbea39ca7a9e596a756a9569455c0a8ce34fef23ad73cb60023c822e5445901d451491207ad264f9dd028d7417f31b3fac82630b4ff16c81c999 |
SSDEEP: | 1536:zvT16ORJA1M1rsYAuUAim9OrgT8YtKCe5dD/d:zvTYO01MilrgT8YtKpDl |
TLSH: | B673B81E2E618FADF7A8823547B78E21939C378527E1D685E29CD6001F7034E645FBB8 |
File Content Preview: | .ELF.....................@.`...4..9......4. ...(.............@...@..../0../0..............0..E0..E0.......:.........dt.Q............................<...'..L...!'.......................<...'..(...!... ....'9... ......................<...'......!........'9. |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 80152 |
Section Header Size: | 40 |
Number of Section Headers: | 14 |
Header String Table Index: | 13 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x400094 | 0x94 | 0x8c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x400120 | 0x120 | 0x117e0 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x411900 | 0x11900 | 0x5c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x411960 | 0x11960 | 0x15d0 | 0x0 | 0x2 | A | 0 | 0 | 16 |
.ctors | PROGBITS | 0x453000 | 0x13000 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x453008 | 0x13008 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data.rel.ro | PROGBITS | 0x453014 | 0x13014 | 0x34 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x453050 | 0x13050 | 0x3a0 | 0x0 | 0x3 | WA | 0 | 0 | 16 |
.got | PROGBITS | 0x4533f0 | 0x133f0 | 0x4c4 | 0x4 | 0x10000003 | WAp | 0 | 0 | 16 |
.sbss | NOBITS | 0x4538b4 | 0x138b4 | 0x14 | 0x0 | 0x10000003 | WAp | 0 | 0 | 4 |
.bss | NOBITS | 0x4538d0 | 0x138b4 | 0x31f8 | 0x0 | 0x3 | WA | 0 | 0 | 16 |
.mdebug.abi32 | PROGBITS | 0x9a2 | 0x138b4 | 0x0 | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0x138b4 | 0x64 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x400000 | 0x400000 | 0x12f30 | 0x12f30 | 5.5182 | 0x5 | R E | 0x10000 | .init .text .fini .rodata | |
LOAD | 0x13000 | 0x453000 | 0x453000 | 0x8b4 | 0x3ac8 | 3.6021 | 0x6 | RW | 0x10000 | .ctors .dtors .data.rel.ro .data .got .sbss .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 8, 2024 10:56:59.721365929 CEST | 34708 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:56:59.726317883 CEST | 38241 | 34708 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:56:59.726372957 CEST | 34708 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:56:59.727153063 CEST | 34708 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:56:59.731873035 CEST | 38241 | 34708 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:56:59.731978893 CEST | 34708 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:56:59.732012987 CEST | 38241 | 34708 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:56:59.736933947 CEST | 38241 | 34708 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:57:04.131253958 CEST | 46540 | 443 | 192.168.2.14 | 185.125.190.26 |
Oct 8, 2024 10:57:16.484287024 CEST | 34710 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:57:16.489489079 CEST | 38241 | 34710 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:57:16.489587069 CEST | 34710 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:57:16.490479946 CEST | 34710 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:57:16.494652987 CEST | 38241 | 34710 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:57:16.494810104 CEST | 34710 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:57:16.495321035 CEST | 38241 | 34710 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:57:16.499849081 CEST | 38241 | 34710 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:57:33.258282900 CEST | 34712 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:57:33.263269901 CEST | 38241 | 34712 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:57:33.263370037 CEST | 34712 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:57:33.264292002 CEST | 34712 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:57:33.269109011 CEST | 38241 | 34712 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:57:33.269190073 CEST | 34712 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:57:33.274007082 CEST | 38241 | 34712 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:57:33.870413065 CEST | 38241 | 34712 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:57:33.870577097 CEST | 34712 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:57:33.870816946 CEST | 34712 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:57:34.082175970 CEST | 46540 | 443 | 192.168.2.14 | 185.125.190.26 |
Oct 8, 2024 10:57:55.901874065 CEST | 34714 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:57:55.906892061 CEST | 38241 | 34714 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:57:55.906963110 CEST | 34714 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:57:55.908135891 CEST | 34714 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:57:55.913000107 CEST | 38241 | 34714 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:57:55.913073063 CEST | 34714 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:57:55.918045998 CEST | 38241 | 34714 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:57:56.504545927 CEST | 38241 | 34714 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:57:56.504704952 CEST | 34714 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:57:56.504745007 CEST | 34714 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:57:58.711716890 CEST | 34716 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:57:58.716636896 CEST | 38241 | 34716 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:57:58.716708899 CEST | 34716 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:57:58.717741013 CEST | 34716 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:57:58.722760916 CEST | 38241 | 34716 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:57:58.722841024 CEST | 34716 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:57:58.727591038 CEST | 38241 | 34716 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:57:59.319991112 CEST | 38241 | 34716 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:57:59.320250034 CEST | 34716 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:57:59.320353985 CEST | 34716 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:01.336810112 CEST | 34718 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:01.341557980 CEST | 38241 | 34718 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:01.341645002 CEST | 34718 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:01.342850924 CEST | 34718 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:01.347563028 CEST | 38241 | 34718 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:01.347640991 CEST | 34718 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:01.352380037 CEST | 38241 | 34718 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:02.173790932 CEST | 38241 | 34718 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:02.173942089 CEST | 34718 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:02.174181938 CEST | 34718 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:02.175961971 CEST | 38241 | 34718 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:02.176014900 CEST | 34718 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:02.176121950 CEST | 38241 | 34718 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:02.176155090 CEST | 34718 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:04.194147110 CEST | 34720 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:04.200052977 CEST | 38241 | 34720 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:04.200139999 CEST | 34720 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:04.201124907 CEST | 34720 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:04.206959009 CEST | 38241 | 34720 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:04.207026005 CEST | 34720 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:04.212970972 CEST | 38241 | 34720 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:04.798898935 CEST | 38241 | 34720 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:04.799056053 CEST | 34720 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:04.799149036 CEST | 34720 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:21.982064009 CEST | 34722 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:21.987112045 CEST | 38241 | 34722 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:21.987281084 CEST | 34722 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:21.988221884 CEST | 34722 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:21.995132923 CEST | 38241 | 34722 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:21.995212078 CEST | 34722 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:22.000710964 CEST | 38241 | 34722 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:22.594635963 CEST | 38241 | 34722 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:22.594847918 CEST | 34722 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:22.594847918 CEST | 34722 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:24.805130005 CEST | 34724 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:24.810246944 CEST | 38241 | 34724 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:24.810331106 CEST | 34724 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:24.811409950 CEST | 34724 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:24.816308975 CEST | 38241 | 34724 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:24.816423893 CEST | 34724 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:24.821387053 CEST | 38241 | 34724 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:25.423722029 CEST | 38241 | 34724 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:25.423934937 CEST | 34724 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:25.424030066 CEST | 34724 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:32.453397989 CEST | 34726 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:32.458616018 CEST | 38241 | 34726 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:32.458710909 CEST | 34726 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:32.459464073 CEST | 34726 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:32.464569092 CEST | 38241 | 34726 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:32.464623928 CEST | 34726 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:32.469609022 CEST | 38241 | 34726 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:33.058983088 CEST | 38241 | 34726 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:33.059324980 CEST | 34726 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:33.059392929 CEST | 34726 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:40.463481903 CEST | 34728 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:40.468300104 CEST | 38241 | 34728 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:40.468389034 CEST | 34728 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:40.469171047 CEST | 34728 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:40.473912001 CEST | 38241 | 34728 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:40.473990917 CEST | 34728 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:40.478800058 CEST | 38241 | 34728 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:41.090200901 CEST | 38241 | 34728 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:41.090364933 CEST | 34728 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:41.090609074 CEST | 34728 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:48.256979942 CEST | 34730 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:48.262145996 CEST | 38241 | 34730 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:48.262228012 CEST | 34730 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:48.263241053 CEST | 34730 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:48.267261028 CEST | 38241 | 34730 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:48.267349958 CEST | 34730 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:48.267968893 CEST | 38241 | 34730 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:48.272104979 CEST | 38241 | 34730 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:49.428849936 CEST | 34732 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:49.433830023 CEST | 38241 | 34732 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:49.433948040 CEST | 34732 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:49.435158968 CEST | 34732 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:49.439235926 CEST | 38241 | 34732 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:49.439361095 CEST | 34732 | 38241 | 192.168.2.14 | 93.123.39.105 |
Oct 8, 2024 10:58:49.439975023 CEST | 38241 | 34732 | 93.123.39.105 | 192.168.2.14 |
Oct 8, 2024 10:58:49.444283009 CEST | 38241 | 34732 | 93.123.39.105 | 192.168.2.14 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 8, 2024 10:56:54.698348045 CEST | 60095 | 53 | 192.168.2.14 | 70.34.254.19 |
Oct 8, 2024 10:56:59.704494953 CEST | 37348 | 53 | 192.168.2.14 | 51.158.108.203 |
Oct 8, 2024 10:56:59.720649958 CEST | 53 | 37348 | 51.158.108.203 | 192.168.2.14 |
Oct 8, 2024 10:57:00.733910084 CEST | 55157 | 53 | 192.168.2.14 | 178.254.22.166 |
Oct 8, 2024 10:57:05.739767075 CEST | 40282 | 53 | 192.168.2.14 | 70.34.254.19 |
Oct 8, 2024 10:57:10.742878914 CEST | 48725 | 53 | 192.168.2.14 | 178.254.22.166 |
Oct 8, 2024 10:57:15.750056982 CEST | 49581 | 53 | 192.168.2.14 | 168.235.111.72 |
Oct 8, 2024 10:57:16.483107090 CEST | 53 | 49581 | 168.235.111.72 | 192.168.2.14 |
Oct 8, 2024 10:57:17.497637987 CEST | 54113 | 53 | 192.168.2.14 | 178.254.22.166 |
Oct 8, 2024 10:57:22.504528046 CEST | 35143 | 53 | 192.168.2.14 | 178.254.22.166 |
Oct 8, 2024 10:57:27.510787964 CEST | 39679 | 53 | 192.168.2.14 | 64.176.6.48 |
Oct 8, 2024 10:57:32.517191887 CEST | 48741 | 53 | 192.168.2.14 | 80.152.203.134 |
Oct 8, 2024 10:57:33.256998062 CEST | 53 | 48741 | 80.152.203.134 | 192.168.2.14 |
Oct 8, 2024 10:57:35.876084089 CEST | 38650 | 53 | 192.168.2.14 | 137.220.52.23 |
Oct 8, 2024 10:57:40.882127047 CEST | 44154 | 53 | 192.168.2.14 | 139.84.165.176 |
Oct 8, 2024 10:57:45.889187098 CEST | 48019 | 53 | 192.168.2.14 | 70.34.254.19 |
Oct 8, 2024 10:57:50.895867109 CEST | 33822 | 53 | 192.168.2.14 | 139.84.165.176 |
Oct 8, 2024 10:57:58.509773970 CEST | 39996 | 53 | 192.168.2.14 | 185.181.61.24 |
Oct 8, 2024 10:57:58.710779905 CEST | 53 | 39996 | 185.181.61.24 | 192.168.2.14 |
Oct 8, 2024 10:58:01.325709105 CEST | 38812 | 53 | 192.168.2.14 | 152.53.15.127 |
Oct 8, 2024 10:58:01.335918903 CEST | 53 | 38812 | 152.53.15.127 | 192.168.2.14 |
Oct 8, 2024 10:58:04.177656889 CEST | 55160 | 53 | 192.168.2.14 | 51.158.108.203 |
Oct 8, 2024 10:58:04.193403006 CEST | 53 | 55160 | 51.158.108.203 | 192.168.2.14 |
Oct 8, 2024 10:58:06.803141117 CEST | 51659 | 53 | 192.168.2.14 | 178.254.22.166 |
Oct 8, 2024 10:58:11.806401968 CEST | 48413 | 53 | 192.168.2.14 | 70.34.254.19 |
Oct 8, 2024 10:58:16.812609911 CEST | 41705 | 53 | 192.168.2.14 | 64.176.6.48 |
Oct 8, 2024 10:58:21.818737984 CEST | 46535 | 53 | 192.168.2.14 | 202.61.197.122 |
Oct 8, 2024 10:58:21.980895042 CEST | 53 | 46535 | 202.61.197.122 | 192.168.2.14 |
Oct 8, 2024 10:58:24.598849058 CEST | 46213 | 53 | 192.168.2.14 | 185.181.61.24 |
Oct 8, 2024 10:58:24.804059029 CEST | 53 | 46213 | 185.181.61.24 | 192.168.2.14 |
Oct 8, 2024 10:58:27.429338932 CEST | 59331 | 53 | 192.168.2.14 | 139.84.165.176 |
Oct 8, 2024 10:58:32.436331034 CEST | 40975 | 53 | 192.168.2.14 | 51.158.108.203 |
Oct 8, 2024 10:58:32.452812910 CEST | 53 | 40975 | 51.158.108.203 | 192.168.2.14 |
Oct 8, 2024 10:58:35.079718113 CEST | 51196 | 53 | 192.168.2.14 | 139.84.165.176 |
Oct 8, 2024 10:58:40.086446047 CEST | 36850 | 53 | 192.168.2.14 | 185.181.61.24 |
Oct 8, 2024 10:58:40.461976051 CEST | 53 | 36850 | 185.181.61.24 | 192.168.2.14 |
Oct 8, 2024 10:58:43.094100952 CEST | 55845 | 53 | 192.168.2.14 | 139.84.165.176 |
Oct 8, 2024 10:58:48.100117922 CEST | 35796 | 53 | 192.168.2.14 | 168.235.111.72 |
Oct 8, 2024 10:58:48.255929947 CEST | 53 | 35796 | 168.235.111.72 | 192.168.2.14 |
Oct 8, 2024 10:58:49.269666910 CEST | 39756 | 53 | 192.168.2.14 | 168.235.111.72 |
Oct 8, 2024 10:58:49.427709103 CEST | 53 | 39756 | 168.235.111.72 | 192.168.2.14 |
Oct 8, 2024 10:58:50.442241907 CEST | 59550 | 53 | 192.168.2.14 | 139.84.165.176 |
Oct 8, 2024 10:58:55.448302031 CEST | 44682 | 53 | 192.168.2.14 | 64.176.6.48 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 8, 2024 10:56:54.698348045 CEST | 192.168.2.14 | 70.34.254.19 | 0xcff9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:56:59.704494953 CEST | 192.168.2.14 | 51.158.108.203 | 0x7ff4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:57:00.733910084 CEST | 192.168.2.14 | 178.254.22.166 | 0x9955 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:57:05.739767075 CEST | 192.168.2.14 | 70.34.254.19 | 0x8b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:57:10.742878914 CEST | 192.168.2.14 | 178.254.22.166 | 0xa08f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:57:15.750056982 CEST | 192.168.2.14 | 168.235.111.72 | 0x15ac | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:57:17.497637987 CEST | 192.168.2.14 | 178.254.22.166 | 0x4857 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:57:22.504528046 CEST | 192.168.2.14 | 178.254.22.166 | 0x91a5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:57:27.510787964 CEST | 192.168.2.14 | 64.176.6.48 | 0x2028 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:57:32.517191887 CEST | 192.168.2.14 | 80.152.203.134 | 0x2dd1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:57:35.876084089 CEST | 192.168.2.14 | 137.220.52.23 | 0x30e3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:57:40.882127047 CEST | 192.168.2.14 | 139.84.165.176 | 0x195 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:57:45.889187098 CEST | 192.168.2.14 | 70.34.254.19 | 0xf8c4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:57:50.895867109 CEST | 192.168.2.14 | 139.84.165.176 | 0x23eb | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:57:58.509773970 CEST | 192.168.2.14 | 185.181.61.24 | 0x8d86 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:58:01.325709105 CEST | 192.168.2.14 | 152.53.15.127 | 0x814b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:58:04.177656889 CEST | 192.168.2.14 | 51.158.108.203 | 0x1173 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:58:06.803141117 CEST | 192.168.2.14 | 178.254.22.166 | 0x63b1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:58:11.806401968 CEST | 192.168.2.14 | 70.34.254.19 | 0xec83 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:58:16.812609911 CEST | 192.168.2.14 | 64.176.6.48 | 0x19f0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:58:21.818737984 CEST | 192.168.2.14 | 202.61.197.122 | 0x301c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:58:24.598849058 CEST | 192.168.2.14 | 185.181.61.24 | 0xda40 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:58:27.429338932 CEST | 192.168.2.14 | 139.84.165.176 | 0x443c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:58:32.436331034 CEST | 192.168.2.14 | 51.158.108.203 | 0xb412 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:58:35.079718113 CEST | 192.168.2.14 | 139.84.165.176 | 0x4d0b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:58:40.086446047 CEST | 192.168.2.14 | 185.181.61.24 | 0x3bdf | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:58:43.094100952 CEST | 192.168.2.14 | 139.84.165.176 | 0x4a17 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:58:48.100117922 CEST | 192.168.2.14 | 168.235.111.72 | 0xe278 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:58:49.269666910 CEST | 192.168.2.14 | 168.235.111.72 | 0x7d24 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:58:50.442241907 CEST | 192.168.2.14 | 139.84.165.176 | 0xdd6c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 10:58:55.448302031 CEST | 192.168.2.14 | 64.176.6.48 | 0xfced | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 8, 2024 10:56:59.720649958 CEST | 51.158.108.203 | 192.168.2.14 | 0x7ff4 | No error (0) | 93.123.39.105 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 10:57:16.483107090 CEST | 168.235.111.72 | 192.168.2.14 | 0x15ac | No error (0) | 93.123.39.105 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 10:57:33.256998062 CEST | 80.152.203.134 | 192.168.2.14 | 0x2dd1 | No error (0) | 93.123.39.105 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 10:57:58.710779905 CEST | 185.181.61.24 | 192.168.2.14 | 0x8d86 | No error (0) | 93.123.39.105 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 10:58:01.335918903 CEST | 152.53.15.127 | 192.168.2.14 | 0x814b | No error (0) | 93.123.39.105 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 10:58:04.193403006 CEST | 51.158.108.203 | 192.168.2.14 | 0x1173 | No error (0) | 93.123.39.105 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 10:58:21.980895042 CEST | 202.61.197.122 | 192.168.2.14 | 0x301c | No error (0) | 93.123.39.105 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 10:58:24.804059029 CEST | 185.181.61.24 | 192.168.2.14 | 0xda40 | No error (0) | 93.123.39.105 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 10:58:32.452812910 CEST | 51.158.108.203 | 192.168.2.14 | 0xb412 | No error (0) | 93.123.39.105 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 10:58:40.461976051 CEST | 185.181.61.24 | 192.168.2.14 | 0x3bdf | No error (0) | 93.123.39.105 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 10:58:48.255929947 CEST | 168.235.111.72 | 192.168.2.14 | 0xe278 | No error (0) | 93.123.39.105 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 10:58:49.427709103 CEST | 168.235.111.72 | 192.168.2.14 | 0x7d24 | No error (0) | 93.123.39.105 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 08:56:52 |
Start date (UTC): | 08/10/2024 |
Path: | /tmp/na.elf |
Arguments: | /tmp/na.elf |
File size: | 5777432 bytes |
MD5 hash: | 0083f1f0e77be34ad27f849842bbb00c |
Start time (UTC): | 08:56:53 |
Start date (UTC): | 08/10/2024 |
Path: | /tmp/na.elf |
Arguments: | - |
File size: | 5777432 bytes |
MD5 hash: | 0083f1f0e77be34ad27f849842bbb00c |
Start time (UTC): | 08:56:53 |
Start date (UTC): | 08/10/2024 |
Path: | /tmp/na.elf |
Arguments: | - |
File size: | 5777432 bytes |
MD5 hash: | 0083f1f0e77be34ad27f849842bbb00c |
Start time (UTC): | 08:56:53 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/udisks2/udisksd |
Arguments: | - |
File size: | 483056 bytes |
MD5 hash: | 1d7ae439cc3d82fa6b127671ce037a24 |
Start time (UTC): | 08:56:53 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/sbin/dumpe2fs |
Arguments: | dumpe2fs -h /dev/dm-0 |
File size: | 31112 bytes |
MD5 hash: | 5c66f7d8f7681a40562cf049ad4b72b4 |
Start time (UTC): | 08:56:53 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/udisks2/udisksd |
Arguments: | - |
File size: | 483056 bytes |
MD5 hash: | 1d7ae439cc3d82fa6b127671ce037a24 |
Start time (UTC): | 08:56:53 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/sbin/dumpe2fs |
Arguments: | dumpe2fs -h /dev/dm-0 |
File size: | 31112 bytes |
MD5 hash: | 5c66f7d8f7681a40562cf049ad4b72b4 |
Start time (UTC): | 08:56:53 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/lib/udisks2/udisksd |
Arguments: | - |
File size: | 483056 bytes |
MD5 hash: | 1d7ae439cc3d82fa6b127671ce037a24 |
Start time (UTC): | 08:56:53 |
Start date (UTC): | 08/10/2024 |
Path: | /usr/sbin/dumpe2fs |
Arguments: | dumpe2fs -h /dev/dm-0 |
File size: | 31112 bytes |
MD5 hash: | 5c66f7d8f7681a40562cf049ad4b72b4 |