Linux
Analysis Report
arm6-20240814-0111.elf
Overview
General Information
Detection
Mirai
Score: | 72 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Yara detected Mirai
Detected TCP or UDP traffic on non-standard ports
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1492601 |
Start date and time: | 2024-08-14 03:16:44 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 28s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | arm6-20240814-0111.elf |
Detection: | MAL |
Classification: | mal72.troj.linELF@0/0@2/0 |
Command: | /tmp/arm6-20240814-0111.elf |
PID: | 5656 |
Exit Code: | 139 |
Exit Code Info: | SIGSEGV (11) Segmentation fault invalid memory reference |
Killed: | False |
Standard Output: | |
Standard Error: | qemu: uncaught target signal 11 (Segmentation fault) - core dumped |
- system is lnxubuntu20
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Mirai | Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Mirai_6 | Yara detected Mirai | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Mirai_6 | Yara detected Mirai | Joe Security | ||
JoeSecurity_Mirai_8 | Yara detected Mirai | Joe Security | ||
JoeSecurity_Mirai_6 | Yara detected Mirai | Joe Security |
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: |
Source: | .symtab present: |
Source: | Classification label: |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | Direct Volume Access | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Non-Standard Port | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
55% | ReversingLabs | Linux.Trojan.Mirai | ||
55% | Virustotal | Browse | ||
100% | Avira | EXP/ELF.Mirai.W |
⊘No Antivirus matches
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
daisy.ubuntu.com | 162.213.35.24 | true | false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
202.147.31.50 | unknown | Japan | 4637 | ASN-TELSTRA-GLOBALTelstraGlobalHK | false | |
111.118.138.64 | unknown | Cambodia | 38623 | VIETTELCAMBODIA-AS-APISPIXPINCAMBODIAWITHTHEBESTVERV | false | |
81.239.112.126 | unknown | Sweden | 3301 | TELIANET-SWEDENTeliaCompanySE | false | |
203.75.207.166 | unknown | Taiwan; Republic of China (ROC) | 3462 | HINETDataCommunicationBusinessGroupTW | false | |
122.151.81.184 | unknown | Australia | 38285 | VOCUS-RETAIL-AUVocusRetailAU | false | |
164.178.237.236 | unknown | Canada | 37717 | EL-KhawarizmiTN | false | |
80.76.196.80 | unknown | United Kingdom | 31641 | ATLAS-COMMUNICATIONS-ASGB | false | |
156.253.186.6 | unknown | Seychelles | 132839 | POWERLINE-AS-APPOWERLINEDATACENTERHK | false | |
122.228.112.179 | unknown | China | 134771 | CHINATELECOM-ZHEJIANG-WENZHOU-IDCWENZHOUZHEJIANGProvince | false | |
156.152.144.45 | unknown | United States | 71 | HP-INTERNET-ASUS | false | |
78.204.8.123 | unknown | France | 12322 | PROXADFR | false | |
189.146.43.33 | unknown | Mexico | 8151 | UninetSAdeCVMX | false | |
89.227.105.120 | unknown | France | 12670 | AS-COMPLETELFR | false | |
132.46.12.43 | unknown | United States | 385 | AFCONC-BLOCK1-ASUS | false | |
197.70.188.36 | unknown | South Africa | 16637 | MTNNS-ASZA | false | |
79.51.4.187 | unknown | Italy | 3269 | ASN-IBSNAZIT | false | |
103.193.219.145 | unknown | China | 24039 | ITC-GLOBAL-AS-APITCGlobalAustraliaAU | false | |
41.184.174.132 | unknown | Nigeria | 29091 | IPNXngNG | false | |
156.201.63.19 | unknown | Egypt | 8452 | TE-ASTE-ASEG | false | |
86.91.177.61 | unknown | Netherlands | 1136 | KPNKPNNationalEU | false | |
65.105.26.81 | unknown | United States | 2828 | XO-AS15US | false | |
23.138.37.212 | unknown | Reserved | 23033 | WOWUS | false | |
35.162.0.35 | unknown | United States | 16509 | AMAZON-02US | false | |
176.139.185.154 | unknown | France | 5410 | BOUYGTEL-ISPFR | false | |
179.5.146.47 | unknown | El Salvador | 14754 | TelguaGT | false | |
166.10.147.165 | unknown | United States | 11798 | ACEDATACENTERS-AS-1US | false | |
54.254.169.28 | unknown | United States | 16509 | AMAZON-02US | false | |
23.214.5.110 | unknown | United States | 16625 | AKAMAI-ASUS | false | |
186.118.234.169 | unknown | Colombia | 3816 | COLOMBIATELECOMUNICACIONESSAESPCO | false | |
27.55.180.178 | unknown | Thailand | 132061 | REALMOVE-AS-APRealmoveCompanyLimitedTH | false | |
197.68.180.70 | unknown | South Africa | 16637 | MTNNS-ASZA | false | |
62.72.181.10 | unknown | Ukraine | 24896 | INTELLECOM-ASUA | false | |
38.31.12.59 | unknown | United States | 174 | COGENT-174US | false | |
194.35.191.127 | unknown | United States | 395854 | SIMNA-64643US | false | |
197.1.172.116 | unknown | Tunisia | 37705 | TOPNETTN | false | |
54.133.78.197 | unknown | United States | 14618 | AMAZON-AESUS | false | |
20.96.255.164 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
41.1.23.33 | unknown | South Africa | 29975 | VODACOM-ZA | false | |
206.151.17.212 | unknown | United States | 3561 | CENTURYLINK-LEGACY-SAVVISUS | false | |
68.21.231.52 | unknown | United States | 7018 | ATT-INTERNET4US | false | |
156.91.176.142 | unknown | United States | 10695 | WAL-MARTUS | false | |
45.75.216.100 | unknown | United Kingdom | 49425 | DIGITAL-REALTY-UKGB | false | |
41.249.111.90 | unknown | Morocco | 36903 | MT-MPLSMA | false | |
41.224.191.129 | unknown | Tunisia | 37492 | ORANGE-TN | false | |
75.172.245.230 | unknown | United States | 209 | CENTURYLINK-US-LEGACY-QWESTUS | false | |
138.2.189.16 | unknown | United States | 264524 | CunhaeZanatotelecomLTDAMEBR | false | |
110.151.10.99 | unknown | Australia | 1221 | ASN-TELSTRATelstraCorporationLtdAU | false | |
75.7.232.29 | unknown | United States | 7018 | ATT-INTERNET4US | false | |
66.30.41.27 | unknown | United States | 7922 | COMCAST-7922US | false | |
1.138.141.144 | unknown | Australia | 1221 | ASN-TELSTRATelstraCorporationLtdAU | false | |
102.53.205.96 | unknown | Morocco | 36903 | MT-MPLSMA | false | |
118.193.56.101 | unknown | China | 133115 | HKKFGL-AS-APHKKwaifongGroupLimitedHK | false | |
221.35.249.104 | unknown | Japan | 17676 | GIGAINFRASoftbankBBCorpJP | false | |
79.186.204.198 | unknown | Poland | 5617 | TPNETPL | false | |
102.187.121.109 | unknown | Egypt | 24835 | RAYA-ASEG | false | |
128.222.189.130 | unknown | United States | 5723 | JHUUS | false | |
66.241.94.144 | unknown | United States | 14188 | ASHLANDFIBERNETWORKUS | false | |
151.188.66.157 | unknown | United States | 21984 | FCPSUS | false | |
130.10.112.131 | unknown | United States | 6908 | DATAHOPDatahop-SixDegreesGB | false | |
112.255.126.189 | unknown | China | 4837 | CHINA169-BACKBONECHINAUNICOMChina169BackboneCN | false | |
156.177.168.140 | unknown | Egypt | 36992 | ETISALAT-MISREG | false | |
69.201.61.0 | unknown | United States | 11351 | TWC-11351-NORTHEASTUS | false | |
105.96.32.89 | unknown | Algeria | 36947 | ALGTEL-ASDZ | false | |
197.33.2.140 | unknown | Egypt | 8452 | TE-ASTE-ASEG | false | |
106.61.114.91 | unknown | China | 4134 | CHINANET-BACKBONENo31Jin-rongStreetCN | false | |
41.59.217.130 | unknown | Tanzania United Republic of | 33765 | TTCLDATATZ | false | |
102.71.185.164 | unknown | Malawi | 37294 | TNMMW | false | |
197.102.58.17 | unknown | South Africa | 3741 | ISZA | false | |
216.64.179.158 | unknown | United States | 3549 | LVLT-3549US | false | |
154.134.56.130 | unknown | Egypt | 37069 | MOBINILEG | false | |
217.219.129.205 | unknown | Iran (ISLAMIC Republic Of) | 58224 | TCIIR | false | |
90.135.40.201 | unknown | Sweden | 1257 | TELE2EU | false | |
133.3.125.253 | unknown | Japan | 2504 | NCA5KyotoUniversityJP | false | |
73.162.244.200 | unknown | United States | 7922 | COMCAST-7922US | false | |
177.199.116.28 | unknown | Brazil | 26599 | TELEFONICABRASILSABR | false | |
183.230.169.148 | unknown | China | 9808 | CMNET-GDGuangdongMobileCommunicationCoLtdCN | false | |
87.219.95.216 | unknown | Spain | 12479 | UNI2-ASES | false | |
112.88.214.72 | unknown | China | 17816 | CHINA169-GZChinaUnicomIPnetworkChina169Guangdongprovi | false | |
156.11.126.81 | unknown | Canada | 15290 | ALLST-15290CA | false | |
133.73.176.36 | unknown | Japan | 2907 | SINET-ASResearchOrganizationofInformationandSystemsN | false | |
135.67.11.24 | unknown | United States | 18676 | AVAYAUS | false | |
106.87.100.40 | unknown | China | 4134 | CHINANET-BACKBONENo31Jin-rongStreetCN | false | |
181.108.39.1 | unknown | Argentina | 7303 | TelecomArgentinaSAAR | false | |
156.75.151.117 | unknown | United States | 8103 | STATE-OF-FLAUS | false | |
60.109.245.52 | unknown | Japan | 17676 | GIGAINFRASoftbankBBCorpJP | false | |
61.75.224.202 | unknown | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | false | |
197.49.50.215 | unknown | Egypt | 8452 | TE-ASTE-ASEG | false | |
99.255.61.162 | unknown | Canada | 812 | ROGERS-COMMUNICATIONSCA | false | |
102.134.216.116 | unknown | South Africa | 328114 | Comsol-Networks-ASZA | false | |
105.75.136.131 | unknown | Morocco | 36884 | MAROCCONNECTMA | false | |
121.69.94.197 | unknown | China | 4808 | CHINA169-BJChinaUnicomBeijingProvinceNetworkCN | false | |
122.151.52.158 | unknown | Australia | 38285 | VOCUS-RETAIL-AUVocusRetailAU | false | |
170.255.178.244 | unknown | Belgium | 5400 | BTGB | false | |
193.190.66.25 | unknown | Belgium | 2611 | BELNETBE | false | |
68.178.148.181 | unknown | United States | 26496 | AS-26496-GO-DADDY-COM-LLCUS | false | |
97.92.92.239 | unknown | United States | 20115 | CHARTER-20115US | false | |
40.123.60.209 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
41.124.232.32 | unknown | South Africa | 16637 | MTNNS-ASZA | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
156.91.176.142 | Get hash | malicious | Mirai | Browse | ||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
daisy.ubuntu.com | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
VIETTELCAMBODIA-AS-APISPIXPINCAMBODIAWITHTHEBESTVERV | Get hash | malicious | Mirai, Moobot | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
ASN-TELSTRA-GLOBALTelstraGlobalHK | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
TELIANET-SWEDENTeliaCompanySE | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
HINETDataCommunicationBusinessGroupTW | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 6.193672291384879 |
TrID: |
|
File name: | arm6-20240814-0111.elf |
File size: | 105'216 bytes |
MD5: | 8f7a0cefc0892057bfa63966bbf41e8f |
SHA1: | 1508bfbc24cd18e3ad218a8c431923783de4bd1e |
SHA256: | 776e55e4452e5f0a0a771a417a122c8f82b122b25270ca7fb2b70f04863cb548 |
SHA512: | 742a3c43ba6f95293ec0c724f0cd74b7eb345a1ecf114c35340587f4f9a9b551a1da07af6906315279719f7c74ab345412d0fb97e9b27fa284e6c2b339d7b420 |
SSDEEP: | 3072:NbMzyMG34aAzyWaBLb0y1L2jaCmfWoz4:R+qRAz5a9bAjazWj |
TLSH: | CDA31A56B8819B21C5D112BAFD1E118D332317FCD3EEB2129D205F74778A96B0E3BA16 |
File Content Preview: | .ELF..............(.....T...4... .......4. ...(.....................T...T...............X...X...T...X...............Q.td..................................-...L..................@-.,@...0....S..... 0....S.........../..0...0...@..../.........T.....-.@0....S |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 104736 |
Section Header Size: | 40 |
Number of Section Headers: | 12 |
Header String Table Index: | 11 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x8094 | 0x94 | 0x10 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x80b0 | 0xb0 | 0x16fc0 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x1f070 | 0x17070 | 0x10 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x1f080 | 0x17080 | 0x24d4 | 0x0 | 0x2 | A | 0 | 0 | 8 |
.init_array | INIT_ARRAY | 0x29558 | 0x1955c | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.fini_array | FINI_ARRAY | 0x2955c | 0x19560 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.got | PROGBITS | 0x29564 | 0x19568 | 0x74 | 0x4 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x295d8 | 0x195dc | 0x2d4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x298ac | 0x198b0 | 0x64ac | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.ARM.attributes | ARM_ATTRIBUTES | 0x0 | 0x198b0 | 0x10 | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0x198c0 | 0x5d | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8000 | 0x8000 | 0x19554 | 0x19554 | 6.2069 | 0x5 | R E | 0x8000 | .init .text .fini .rodata | |
LOAD | 0x19558 | 0x29558 | 0x29554 | 0x358 | 0xe800 | 4.3166 | 0x6 | RW | 0x8000 | .init_array .fini_array .got .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Aug 14, 2024 03:18:19.804857969 CEST | 37215 | 46752 | 41.1.23.33 | 192.168.2.13 |
Aug 14, 2024 03:18:19.804955006 CEST | 23 | 51546 | 121.69.94.197 | 192.168.2.13 |
Aug 14, 2024 03:18:19.805100918 CEST | 46752 | 37215 | 192.168.2.13 | 41.1.23.33 |
Aug 14, 2024 03:18:19.805107117 CEST | 51546 | 23 | 192.168.2.13 | 121.69.94.197 |
Aug 14, 2024 03:18:19.805296898 CEST | 23 | 43778 | 68.21.231.52 | 192.168.2.13 |
Aug 14, 2024 03:18:19.805346012 CEST | 43778 | 23 | 192.168.2.13 | 68.21.231.52 |
Aug 14, 2024 03:18:21.852565050 CEST | 37215 | 57020 | 197.49.50.215 | 192.168.2.13 |
Aug 14, 2024 03:18:21.852626085 CEST | 57020 | 37215 | 192.168.2.13 | 197.49.50.215 |
Aug 14, 2024 03:18:21.852688074 CEST | 23 | 52944 | 216.64.179.158 | 192.168.2.13 |
Aug 14, 2024 03:18:21.852792025 CEST | 52944 | 23 | 192.168.2.13 | 216.64.179.158 |
Aug 14, 2024 03:18:21.852844000 CEST | 37215 | 37840 | 102.134.216.116 | 192.168.2.13 |
Aug 14, 2024 03:18:21.852946997 CEST | 23 | 37520 | 151.188.66.157 | 192.168.2.13 |
Aug 14, 2024 03:18:21.852978945 CEST | 23 | 58598 | 118.193.56.101 | 192.168.2.13 |
Aug 14, 2024 03:18:21.853009939 CEST | 37520 | 23 | 192.168.2.13 | 151.188.66.157 |
Aug 14, 2024 03:18:21.853044033 CEST | 58598 | 23 | 192.168.2.13 | 118.193.56.101 |
Aug 14, 2024 03:18:21.853053093 CEST | 37840 | 37215 | 192.168.2.13 | 102.134.216.116 |
Aug 14, 2024 03:18:21.853111982 CEST | 23 | 42874 | 110.151.10.99 | 192.168.2.13 |
Aug 14, 2024 03:18:21.853161097 CEST | 23 | 49906 | 23.138.37.212 | 192.168.2.13 |
Aug 14, 2024 03:18:21.853172064 CEST | 42874 | 23 | 192.168.2.13 | 110.151.10.99 |
Aug 14, 2024 03:18:21.853209972 CEST | 23 | 44090 | 105.96.32.89 | 192.168.2.13 |
Aug 14, 2024 03:18:21.853266001 CEST | 23 | 58632 | 111.118.138.64 | 192.168.2.13 |
Aug 14, 2024 03:18:21.853344917 CEST | 49906 | 23 | 192.168.2.13 | 23.138.37.212 |
Aug 14, 2024 03:18:21.853344917 CEST | 44090 | 23 | 192.168.2.13 | 105.96.32.89 |
Aug 14, 2024 03:18:21.853363037 CEST | 23 | 52414 | 176.139.185.154 | 192.168.2.13 |
Aug 14, 2024 03:18:21.853385925 CEST | 58632 | 23 | 192.168.2.13 | 111.118.138.64 |
Aug 14, 2024 03:18:21.853593111 CEST | 52414 | 23 | 192.168.2.13 | 176.139.185.154 |
Aug 14, 2024 03:18:21.853984118 CEST | 23 | 50658 | 81.239.112.126 | 192.168.2.13 |
Aug 14, 2024 03:18:21.854046106 CEST | 50658 | 23 | 192.168.2.13 | 81.239.112.126 |
Aug 14, 2024 03:18:23.900877953 CEST | 37215 | 44836 | 156.75.151.117 | 192.168.2.13 |
Aug 14, 2024 03:18:23.900963068 CEST | 23 | 48198 | 202.147.31.50 | 192.168.2.13 |
Aug 14, 2024 03:18:23.901015043 CEST | 23 | 60244 | 1.138.141.144 | 192.168.2.13 |
Aug 14, 2024 03:18:23.901058912 CEST | 44836 | 37215 | 192.168.2.13 | 156.75.151.117 |
Aug 14, 2024 03:18:23.901063919 CEST | 48198 | 23 | 192.168.2.13 | 202.147.31.50 |
Aug 14, 2024 03:18:23.901066065 CEST | 37215 | 41808 | 41.249.111.90 | 192.168.2.13 |
Aug 14, 2024 03:18:23.901118040 CEST | 23 | 44244 | 87.219.95.216 | 192.168.2.13 |
Aug 14, 2024 03:18:23.901122093 CEST | 60244 | 23 | 192.168.2.13 | 1.138.141.144 |
Aug 14, 2024 03:18:23.901146889 CEST | 41808 | 37215 | 192.168.2.13 | 41.249.111.90 |
Aug 14, 2024 03:18:23.901197910 CEST | 44244 | 23 | 192.168.2.13 | 87.219.95.216 |
Aug 14, 2024 03:18:25.948841095 CEST | 37215 | 45278 | 41.59.217.130 | 192.168.2.13 |
Aug 14, 2024 03:18:25.949038029 CEST | 45278 | 37215 | 192.168.2.13 | 41.59.217.130 |
Aug 14, 2024 03:18:25.949196100 CEST | 23 | 40090 | 105.75.136.131 | 192.168.2.13 |
Aug 14, 2024 03:18:25.949239969 CEST | 2323 | 58646 | 154.134.56.130 | 192.168.2.13 |
Aug 14, 2024 03:18:25.949285984 CEST | 40090 | 23 | 192.168.2.13 | 105.75.136.131 |
Aug 14, 2024 03:18:25.949318886 CEST | 58646 | 2323 | 192.168.2.13 | 154.134.56.130 |
Aug 14, 2024 03:18:25.951694965 CEST | 37215 | 47008 | 102.187.121.109 | 192.168.2.13 |
Aug 14, 2024 03:18:25.951747894 CEST | 47008 | 37215 | 192.168.2.13 | 102.187.121.109 |
Aug 14, 2024 03:18:25.952004910 CEST | 23 | 60040 | 193.190.66.25 | 192.168.2.13 |
Aug 14, 2024 03:18:25.952037096 CEST | 37215 | 52956 | 156.11.126.81 | 192.168.2.13 |
Aug 14, 2024 03:18:25.952054024 CEST | 60040 | 23 | 192.168.2.13 | 193.190.66.25 |
Aug 14, 2024 03:18:25.952100992 CEST | 52956 | 37215 | 192.168.2.13 | 156.11.126.81 |
Aug 14, 2024 03:18:25.952111006 CEST | 37215 | 45950 | 156.177.168.140 | 192.168.2.13 |
Aug 14, 2024 03:18:25.952167988 CEST | 45950 | 37215 | 192.168.2.13 | 156.177.168.140 |
Aug 14, 2024 03:18:27.999700069 CEST | 23 | 36342 | 40.123.60.209 | 192.168.2.13 |
Aug 14, 2024 03:18:27.999768972 CEST | 23 | 49722 | 65.105.26.81 | 192.168.2.13 |
Aug 14, 2024 03:18:27.999917030 CEST | 49722 | 23 | 192.168.2.13 | 65.105.26.81 |
Aug 14, 2024 03:18:28.000086069 CEST | 36342 | 23 | 192.168.2.13 | 40.123.60.209 |
Aug 14, 2024 03:18:30.044891119 CEST | 23 | 43452 | 66.241.94.144 | 192.168.2.13 |
Aug 14, 2024 03:18:30.044967890 CEST | 37215 | 51036 | 41.224.191.129 | 192.168.2.13 |
Aug 14, 2024 03:18:30.045176983 CEST | 43452 | 23 | 192.168.2.13 | 66.241.94.144 |
Aug 14, 2024 03:18:30.045183897 CEST | 51036 | 37215 | 192.168.2.13 | 41.224.191.129 |
Aug 14, 2024 03:18:30.045811892 CEST | 23 | 33472 | 122.151.52.158 | 192.168.2.13 |
Aug 14, 2024 03:18:30.045849085 CEST | 23 | 43560 | 75.7.232.29 | 192.168.2.13 |
Aug 14, 2024 03:18:30.045953035 CEST | 43560 | 23 | 192.168.2.13 | 75.7.232.29 |
Aug 14, 2024 03:18:30.045979023 CEST | 33472 | 23 | 192.168.2.13 | 122.151.52.158 |
Aug 14, 2024 03:18:32.091500998 CEST | 23 | 52864 | 90.135.40.201 | 192.168.2.13 |
Aug 14, 2024 03:18:32.091711044 CEST | 52864 | 23 | 192.168.2.13 | 90.135.40.201 |
Aug 14, 2024 03:18:32.096748114 CEST | 37215 | 33128 | 156.253.186.6 | 192.168.2.13 |
Aug 14, 2024 03:18:32.096812010 CEST | 33128 | 37215 | 192.168.2.13 | 156.253.186.6 |
Aug 14, 2024 03:18:32.096911907 CEST | 23 | 34770 | 112.88.214.72 | 192.168.2.13 |
Aug 14, 2024 03:18:32.096949100 CEST | 23 | 48266 | 62.72.181.10 | 192.168.2.13 |
Aug 14, 2024 03:18:32.096968889 CEST | 23 | 45810 | 103.193.219.145 | 192.168.2.13 |
Aug 14, 2024 03:18:32.096983910 CEST | 23 | 49090 | 122.151.81.184 | 192.168.2.13 |
Aug 14, 2024 03:18:32.097019911 CEST | 34770 | 23 | 192.168.2.13 | 112.88.214.72 |
Aug 14, 2024 03:18:32.097028017 CEST | 48266 | 23 | 192.168.2.13 | 62.72.181.10 |
Aug 14, 2024 03:18:32.097109079 CEST | 45810 | 23 | 192.168.2.13 | 103.193.219.145 |
Aug 14, 2024 03:18:32.097109079 CEST | 49090 | 23 | 192.168.2.13 | 122.151.81.184 |
Aug 14, 2024 03:18:34.139462948 CEST | 23 | 35130 | 133.3.125.253 | 192.168.2.13 |
Aug 14, 2024 03:18:34.139509916 CEST | 23 | 42544 | 186.118.234.169 | 192.168.2.13 |
Aug 14, 2024 03:18:34.139522076 CEST | 23 | 47312 | 166.10.147.165 | 192.168.2.13 |
Aug 14, 2024 03:18:34.139539003 CEST | 23 | 46710 | 135.67.11.24 | 192.168.2.13 |
Aug 14, 2024 03:18:34.139560938 CEST | 2323 | 38504 | 156.91.176.142 | 192.168.2.13 |
Aug 14, 2024 03:18:34.139769077 CEST | 42544 | 23 | 192.168.2.13 | 186.118.234.169 |
Aug 14, 2024 03:18:34.139779091 CEST | 35130 | 23 | 192.168.2.13 | 133.3.125.253 |
Aug 14, 2024 03:18:34.139786959 CEST | 47312 | 23 | 192.168.2.13 | 166.10.147.165 |
Aug 14, 2024 03:18:34.139823914 CEST | 46710 | 23 | 192.168.2.13 | 135.67.11.24 |
Aug 14, 2024 03:18:34.139823914 CEST | 38504 | 2323 | 192.168.2.13 | 156.91.176.142 |
Aug 14, 2024 03:18:34.143662930 CEST | 37215 | 56724 | 41.184.174.132 | 192.168.2.13 |
Aug 14, 2024 03:18:34.143727064 CEST | 56724 | 37215 | 192.168.2.13 | 41.184.174.132 |
Aug 14, 2024 03:18:36.189961910 CEST | 23 | 37872 | 170.255.178.244 | 192.168.2.13 |
Aug 14, 2024 03:18:36.190272093 CEST | 37215 | 52428 | 156.152.144.45 | 192.168.2.13 |
Aug 14, 2024 03:18:36.190309048 CEST | 23 | 54312 | 221.35.249.104 | 192.168.2.13 |
Aug 14, 2024 03:18:36.190376043 CEST | 37872 | 23 | 192.168.2.13 | 170.255.178.244 |
Aug 14, 2024 03:18:36.190381050 CEST | 52428 | 37215 | 192.168.2.13 | 156.152.144.45 |
Aug 14, 2024 03:18:36.190509081 CEST | 54312 | 23 | 192.168.2.13 | 221.35.249.104 |
Aug 14, 2024 03:18:38.236918926 CEST | 23 | 49860 | 66.30.41.27 | 192.168.2.13 |
Aug 14, 2024 03:18:38.237121105 CEST | 23 | 44960 | 73.162.244.200 | 192.168.2.13 |
Aug 14, 2024 03:18:38.237174034 CEST | 49860 | 23 | 192.168.2.13 | 66.30.41.27 |
Aug 14, 2024 03:18:38.237246037 CEST | 44960 | 23 | 192.168.2.13 | 73.162.244.200 |
Aug 14, 2024 03:18:40.284425974 CEST | 23 | 36848 | 164.178.237.236 | 192.168.2.13 |
Aug 14, 2024 03:18:40.284521103 CEST | 23 | 38090 | 106.87.100.40 | 192.168.2.13 |
Aug 14, 2024 03:18:40.284629107 CEST | 23 | 49958 | 80.76.196.80 | 192.168.2.13 |
Aug 14, 2024 03:18:40.284674883 CEST | 36848 | 23 | 192.168.2.13 | 164.178.237.236 |
Aug 14, 2024 03:18:40.284683943 CEST | 38090 | 23 | 192.168.2.13 | 106.87.100.40 |
Aug 14, 2024 03:18:40.284692049 CEST | 49958 | 23 | 192.168.2.13 | 80.76.196.80 |
Aug 14, 2024 03:18:40.284723043 CEST | 23 | 43012 | 79.186.204.198 | 192.168.2.13 |
Aug 14, 2024 03:18:40.284792900 CEST | 23 | 37324 | 181.108.39.1 | 192.168.2.13 |
Aug 14, 2024 03:18:40.284941912 CEST | 43012 | 23 | 192.168.2.13 | 79.186.204.198 |
Aug 14, 2024 03:18:40.284977913 CEST | 37324 | 23 | 192.168.2.13 | 181.108.39.1 |
Aug 14, 2024 03:18:40.292953968 CEST | 23 | 52274 | 97.92.92.239 | 192.168.2.13 |
Aug 14, 2024 03:18:40.292999983 CEST | 23 | 40388 | 194.35.191.127 | 192.168.2.13 |
Aug 14, 2024 03:18:40.293028116 CEST | 52274 | 23 | 192.168.2.13 | 97.92.92.239 |
Aug 14, 2024 03:18:40.293046951 CEST | 23 | 53174 | 41.124.232.32 | 192.168.2.13 |
Aug 14, 2024 03:18:40.293111086 CEST | 40388 | 23 | 192.168.2.13 | 194.35.191.127 |
Aug 14, 2024 03:18:40.293111086 CEST | 53174 | 23 | 192.168.2.13 | 41.124.232.32 |
Aug 14, 2024 03:18:42.332715988 CEST | 23 | 57222 | 79.51.4.187 | 192.168.2.13 |
Aug 14, 2024 03:18:42.333118916 CEST | 57222 | 23 | 192.168.2.13 | 79.51.4.187 |
Aug 14, 2024 03:18:42.336159945 CEST | 37215 | 47230 | 102.53.205.96 | 192.168.2.13 |
Aug 14, 2024 03:18:42.336230993 CEST | 37215 | 58606 | 197.70.188.36 | 192.168.2.13 |
Aug 14, 2024 03:18:42.336307049 CEST | 58606 | 37215 | 192.168.2.13 | 197.70.188.36 |
Aug 14, 2024 03:18:42.336424112 CEST | 47230 | 37215 | 192.168.2.13 | 102.53.205.96 |
Aug 14, 2024 03:18:44.380603075 CEST | 23 | 36464 | 20.96.255.164 | 192.168.2.13 |
Aug 14, 2024 03:18:44.380686045 CEST | 36464 | 23 | 192.168.2.13 | 20.96.255.164 |
Aug 14, 2024 03:18:44.380721092 CEST | 23 | 44326 | 206.151.17.212 | 192.168.2.13 |
Aug 14, 2024 03:18:44.380914927 CEST | 44326 | 23 | 192.168.2.13 | 206.151.17.212 |
Aug 14, 2024 03:18:44.381402969 CEST | 23 | 39000 | 99.255.61.162 | 192.168.2.13 |
Aug 14, 2024 03:18:44.381463051 CEST | 23 | 38506 | 35.162.0.35 | 192.168.2.13 |
Aug 14, 2024 03:18:44.381467104 CEST | 39000 | 23 | 192.168.2.13 | 99.255.61.162 |
Aug 14, 2024 03:18:44.381498098 CEST | 23 | 57184 | 78.204.8.123 | 192.168.2.13 |
Aug 14, 2024 03:18:44.381520033 CEST | 38506 | 23 | 192.168.2.13 | 35.162.0.35 |
Aug 14, 2024 03:18:44.381551027 CEST | 57184 | 23 | 192.168.2.13 | 78.204.8.123 |
Aug 14, 2024 03:18:44.381740093 CEST | 23 | 38474 | 217.219.129.205 | 192.168.2.13 |
Aug 14, 2024 03:18:44.381805897 CEST | 38474 | 23 | 192.168.2.13 | 217.219.129.205 |
Aug 14, 2024 03:18:44.381829977 CEST | 23 | 46788 | 68.178.148.181 | 192.168.2.13 |
Aug 14, 2024 03:18:44.381890059 CEST | 46788 | 23 | 192.168.2.13 | 68.178.148.181 |
Aug 14, 2024 03:18:44.381932020 CEST | 23 | 58620 | 177.199.116.28 | 192.168.2.13 |
Aug 14, 2024 03:18:44.382107973 CEST | 58620 | 23 | 192.168.2.13 | 177.199.116.28 |
Aug 14, 2024 03:18:46.428457022 CEST | 23 | 48496 | 61.75.224.202 | 192.168.2.13 |
Aug 14, 2024 03:18:46.428518057 CEST | 23 | 40766 | 138.2.189.16 | 192.168.2.13 |
Aug 14, 2024 03:18:46.428575039 CEST | 2323 | 37122 | 130.10.112.131 | 192.168.2.13 |
Aug 14, 2024 03:18:46.428639889 CEST | 2323 | 57374 | 183.230.169.148 | 192.168.2.13 |
Aug 14, 2024 03:18:46.428704977 CEST | 37122 | 2323 | 192.168.2.13 | 130.10.112.131 |
Aug 14, 2024 03:18:46.428730011 CEST | 48496 | 23 | 192.168.2.13 | 61.75.224.202 |
Aug 14, 2024 03:18:46.428730965 CEST | 40766 | 23 | 192.168.2.13 | 138.2.189.16 |
Aug 14, 2024 03:18:46.428756952 CEST | 57374 | 2323 | 192.168.2.13 | 183.230.169.148 |
Aug 14, 2024 03:18:46.428819895 CEST | 37215 | 37356 | 156.201.63.19 | 192.168.2.13 |
Aug 14, 2024 03:18:46.428900003 CEST | 37356 | 37215 | 192.168.2.13 | 156.201.63.19 |
Aug 14, 2024 03:18:46.431792021 CEST | 23 | 38746 | 122.228.112.179 | 192.168.2.13 |
Aug 14, 2024 03:18:46.431854010 CEST | 38746 | 23 | 192.168.2.13 | 122.228.112.179 |
Aug 14, 2024 03:18:46.432002068 CEST | 23 | 50238 | 75.172.245.230 | 192.168.2.13 |
Aug 14, 2024 03:18:46.432094097 CEST | 50238 | 23 | 192.168.2.13 | 75.172.245.230 |
Aug 14, 2024 03:18:48.476159096 CEST | 23 | 42996 | 179.5.146.47 | 192.168.2.13 |
Aug 14, 2024 03:18:48.476206064 CEST | 23 | 49580 | 132.46.12.43 | 192.168.2.13 |
Aug 14, 2024 03:18:48.476259947 CEST | 23 | 50578 | 189.146.43.33 | 192.168.2.13 |
Aug 14, 2024 03:18:48.476458073 CEST | 42996 | 23 | 192.168.2.13 | 179.5.146.47 |
Aug 14, 2024 03:18:48.476458073 CEST | 49580 | 23 | 192.168.2.13 | 132.46.12.43 |
Aug 14, 2024 03:18:48.476464987 CEST | 50578 | 23 | 192.168.2.13 | 189.146.43.33 |
Aug 14, 2024 03:18:48.479546070 CEST | 23 | 59252 | 54.254.169.28 | 192.168.2.13 |
Aug 14, 2024 03:18:48.479581118 CEST | 23 | 42138 | 106.61.114.91 | 192.168.2.13 |
Aug 14, 2024 03:18:48.479640961 CEST | 42138 | 23 | 192.168.2.13 | 106.61.114.91 |
Aug 14, 2024 03:18:48.479649067 CEST | 23 | 59040 | 38.31.12.59 | 192.168.2.13 |
Aug 14, 2024 03:18:48.479674101 CEST | 59252 | 23 | 192.168.2.13 | 54.254.169.28 |
Aug 14, 2024 03:18:48.479697943 CEST | 59040 | 23 | 192.168.2.13 | 38.31.12.59 |
Aug 14, 2024 03:18:50.528665066 CEST | 23 | 41476 | 27.55.180.178 | 192.168.2.13 |
Aug 14, 2024 03:18:50.529129982 CEST | 23 | 47462 | 69.201.61.0 | 192.168.2.13 |
Aug 14, 2024 03:18:50.529171944 CEST | 41476 | 23 | 192.168.2.13 | 27.55.180.178 |
Aug 14, 2024 03:18:50.529226065 CEST | 47462 | 23 | 192.168.2.13 | 69.201.61.0 |
Aug 14, 2024 03:18:50.529447079 CEST | 23 | 45070 | 112.255.126.189 | 192.168.2.13 |
Aug 14, 2024 03:18:50.529572964 CEST | 45070 | 23 | 192.168.2.13 | 112.255.126.189 |
Aug 14, 2024 03:18:52.618892908 CEST | 23 | 58502 | 197.1.172.116 | 192.168.2.13 |
Aug 14, 2024 03:18:52.619478941 CEST | 23 | 38054 | 89.227.105.120 | 192.168.2.13 |
Aug 14, 2024 03:18:52.619637012 CEST | 58502 | 23 | 192.168.2.13 | 197.1.172.116 |
Aug 14, 2024 03:18:52.619672060 CEST | 23 | 49928 | 203.75.207.166 | 192.168.2.13 |
Aug 14, 2024 03:18:52.619693995 CEST | 23 | 36650 | 128.222.189.130 | 192.168.2.13 |
Aug 14, 2024 03:18:52.619700909 CEST | 38054 | 23 | 192.168.2.13 | 89.227.105.120 |
Aug 14, 2024 03:18:52.619853020 CEST | 49928 | 23 | 192.168.2.13 | 203.75.207.166 |
Aug 14, 2024 03:18:52.619853973 CEST | 36650 | 23 | 192.168.2.13 | 128.222.189.130 |
Aug 14, 2024 03:18:54.620568991 CEST | 23 | 45756 | 45.75.216.100 | 192.168.2.13 |
Aug 14, 2024 03:18:54.621037006 CEST | 45756 | 23 | 192.168.2.13 | 45.75.216.100 |
Aug 14, 2024 03:18:56.667915106 CEST | 23 | 54614 | 54.133.78.197 | 192.168.2.13 |
Aug 14, 2024 03:18:56.667959929 CEST | 23 | 58540 | 133.73.176.36 | 192.168.2.13 |
Aug 14, 2024 03:18:56.668265104 CEST | 54614 | 23 | 192.168.2.13 | 54.133.78.197 |
Aug 14, 2024 03:18:56.668265104 CEST | 58540 | 23 | 192.168.2.13 | 133.73.176.36 |
Aug 14, 2024 03:18:56.671988010 CEST | 23 | 49922 | 23.214.5.110 | 192.168.2.13 |
Aug 14, 2024 03:18:56.672221899 CEST | 49922 | 23 | 192.168.2.13 | 23.214.5.110 |
Aug 14, 2024 03:18:58.716557026 CEST | 37215 | 33826 | 197.68.180.70 | 192.168.2.13 |
Aug 14, 2024 03:18:58.716608047 CEST | 37215 | 35752 | 102.71.185.164 | 192.168.2.13 |
Aug 14, 2024 03:18:58.716944933 CEST | 35752 | 37215 | 192.168.2.13 | 102.71.185.164 |
Aug 14, 2024 03:18:58.717048883 CEST | 33826 | 37215 | 192.168.2.13 | 197.68.180.70 |
Aug 14, 2024 03:19:00.763444901 CEST | 23 | 42968 | 86.91.177.61 | 192.168.2.13 |
Aug 14, 2024 03:19:00.763499975 CEST | 2323 | 38506 | 60.109.245.52 | 192.168.2.13 |
Aug 14, 2024 03:19:00.763648987 CEST | 42968 | 23 | 192.168.2.13 | 86.91.177.61 |
Aug 14, 2024 03:19:00.763653040 CEST | 38506 | 2323 | 192.168.2.13 | 60.109.245.52 |
Aug 14, 2024 03:19:08.959589958 CEST | 37215 | 53874 | 197.102.58.17 | 192.168.2.13 |
Aug 14, 2024 03:19:08.959990978 CEST | 53874 | 37215 | 192.168.2.13 | 197.102.58.17 |
Aug 14, 2024 03:19:08.960232973 CEST | 37215 | 33478 | 197.33.2.140 | 192.168.2.13 |
Aug 14, 2024 03:19:08.960314035 CEST | 33478 | 37215 | 192.168.2.13 | 197.33.2.140 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Aug 14, 2024 03:18:21.276474953 CEST | 45843 | 53 | 192.168.2.13 | 8.8.8.8 |
Aug 14, 2024 03:18:21.276474953 CEST | 32769 | 53 | 192.168.2.13 | 8.8.8.8 |
Aug 14, 2024 03:18:21.288911104 CEST | 53 | 45843 | 8.8.8.8 | 192.168.2.13 |
Aug 14, 2024 03:18:21.288937092 CEST | 53 | 32769 | 8.8.8.8 | 192.168.2.13 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Aug 14, 2024 03:18:21.276474953 CEST | 192.168.2.13 | 8.8.8.8 | 0xa206 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 14, 2024 03:18:21.276474953 CEST | 192.168.2.13 | 8.8.8.8 | 0x8d45 | Standard query (0) | 28 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Aug 14, 2024 03:18:21.288911104 CEST | 8.8.8.8 | 192.168.2.13 | 0xa206 | No error (0) | 162.213.35.24 | A (IP address) | IN (0x0001) | false | ||
Aug 14, 2024 03:18:21.288911104 CEST | 8.8.8.8 | 192.168.2.13 | 0xa206 | No error (0) | 162.213.35.25 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 01:18:18 |
Start date (UTC): | 14/08/2024 |
Path: | /tmp/arm6-20240814-0111.elf |
Arguments: | /tmp/arm6-20240814-0111.elf |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |