Linux
Analysis Report
zersh4.elf
Overview
General Information
Sample name: | zersh4.elf |
Analysis ID: | 1604431 |
MD5: | 9b9094f3ae2242597704fc6599329737 |
SHA1: | af6b42528082d32ad418077b8697073bbf0ec937 |
SHA256: | ea8b27801b58bb631eb540cf59c7f0bd324c92994967bc0e45496f1ea6f95b68 |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Multi AV Scanner detection for submitted file
Sample deletes itself
Sends malformed DNS queries
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1604431 |
Start date and time: | 2025-02-01 14:45:21 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 41s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | zersh4.elf |
Detection: | MAL |
Classification: | mal56.troj.evad.linELF@0/0@27/0 |
Command: | /tmp/zersh4.elf |
PID: | 5443 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | gosh that chinese family at the other table sure ate a lot |
Standard Error: |
- system is lnxubuntu20
- zersh4.elf New Fork (PID: 5445, Parent: 5443)
- zersh4.elf New Fork (PID: 5447, Parent: 5445)
- cleanup
⊘No yara matches
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Networking |
---|
Source: | DNS traffic detected: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: |
Source: | .symtab present: |
Source: | Classification label: |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | 1 File Deletion | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 2 Application Layer Protocol | Traffic Duplication | Data Destruction |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
25% | Virustotal | Browse | ||
21% | ReversingLabs | Linux.Backdoor.Gafgyt |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
serisontop.dyn | 146.190.204.203 | true | false | high | |
serisbot.geek. [malformed] | unknown | unknown | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
64.225.86.206 | unknown | United States | 14061 | DIGITALOCEAN-ASNUS | false | |
146.190.204.203 | serisontop.dyn | United States | 702 | UUNETUS | false | |
185.125.190.26 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
209.38.56.135 | unknown | United States | 7018 | ATT-INTERNET4US | false | |
68.183.244.135 | unknown | United States | 14061 | DIGITALOCEAN-ASNUS | false | |
209.38.188.134 | unknown | United States | 7018 | ATT-INTERNET4US | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
185.125.190.26 | Get hash | malicious | Mirai | Browse | ||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Okiru | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
serisontop.dyn | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
UUNETUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | I2PRAT | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
CANONICAL-ASGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
DIGITALOCEAN-ASNUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 6.726121944941634 |
TrID: |
|
File name: | zersh4.elf |
File size: | 46'008 bytes |
MD5: | 9b9094f3ae2242597704fc6599329737 |
SHA1: | af6b42528082d32ad418077b8697073bbf0ec937 |
SHA256: | ea8b27801b58bb631eb540cf59c7f0bd324c92994967bc0e45496f1ea6f95b68 |
SHA512: | 9c03ee34d2aa53b03a3adefd6d771e9f86f74c44119195a832ada6452a7174fbfabec78f153af754038f554fa719f791b6cd7cba767458c77d534fb2899d3aed |
SSDEEP: | 768:7aVwt6Soxe5qyUTxJU7O4PaXtLkCIoqLX8nC+:7aVwt6Sns4Bok4gX8nC+ |
TLSH: | 41237E63C42AADD0C50946B4A6299F742B13E404C7A62FFB674E86728007EBCF61D3F5 |
File Content Preview: | .ELF..............*.......@.4...........4. ...(...............@...@...........................A...A.....$...........Q.td............................././"O.n........#.*@........#.*@l....o&O.n...l..............................././.../.a"O.!...n...a.b("...q. |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 45568 |
Section Header Size: | 40 |
Number of Section Headers: | 11 |
Header String Table Index: | 10 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x400094 | 0x94 | 0x30 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x4000e0 | 0xe0 | 0xa480 | 0x0 | 0x6 | AX | 0 | 0 | 32 |
.fini | PROGBITS | 0x40a560 | 0xa560 | 0x24 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x40a584 | 0xa584 | 0x76c | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ctors | PROGBITS | 0x41b000 | 0xb000 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x41b008 | 0xb008 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.jcr | PROGBITS | 0x41b010 | 0xb010 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x41b014 | 0xb014 | 0x1a8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x41b1bc | 0xb1bc | 0x268 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.shstrtab | STRTAB | 0x0 | 0xb1bc | 0x43 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x400000 | 0x400000 | 0xacf0 | 0xacf0 | 6.8453 | 0x5 | R E | 0x10000 | .init .text .fini .rodata | |
LOAD | 0xb000 | 0x41b000 | 0x41b000 | 0x1bc | 0x424 | 2.3407 | 0x6 | RW | 0x10000 | .ctors .dtors .jcr .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Feb 1, 2025 14:46:15.843554020 CET | 34002 | 1440 | 192.168.2.13 | 209.38.56.135 |
Feb 1, 2025 14:46:15.848423004 CET | 1440 | 34002 | 209.38.56.135 | 192.168.2.13 |
Feb 1, 2025 14:46:15.848500013 CET | 34002 | 1440 | 192.168.2.13 | 209.38.56.135 |
Feb 1, 2025 14:46:15.860229015 CET | 34002 | 1440 | 192.168.2.13 | 209.38.56.135 |
Feb 1, 2025 14:46:15.865147114 CET | 1440 | 34002 | 209.38.56.135 | 192.168.2.13 |
Feb 1, 2025 14:46:15.865211010 CET | 34002 | 1440 | 192.168.2.13 | 209.38.56.135 |
Feb 1, 2025 14:46:15.869976997 CET | 1440 | 34002 | 209.38.56.135 | 192.168.2.13 |
Feb 1, 2025 14:46:25.870538950 CET | 34002 | 1440 | 192.168.2.13 | 209.38.56.135 |
Feb 1, 2025 14:46:25.875427008 CET | 1440 | 34002 | 209.38.56.135 | 192.168.2.13 |
Feb 1, 2025 14:46:26.484986067 CET | 1440 | 34002 | 209.38.56.135 | 192.168.2.13 |
Feb 1, 2025 14:46:26.485675097 CET | 34002 | 1440 | 192.168.2.13 | 209.38.56.135 |
Feb 1, 2025 14:46:26.490477085 CET | 1440 | 34002 | 209.38.56.135 | 192.168.2.13 |
Feb 1, 2025 14:46:27.087383986 CET | 48202 | 443 | 192.168.2.13 | 185.125.190.26 |
Feb 1, 2025 14:46:27.507143974 CET | 33192 | 1440 | 192.168.2.13 | 146.190.204.203 |
Feb 1, 2025 14:46:27.511970043 CET | 1440 | 33192 | 146.190.204.203 | 192.168.2.13 |
Feb 1, 2025 14:46:27.512049913 CET | 33192 | 1440 | 192.168.2.13 | 146.190.204.203 |
Feb 1, 2025 14:46:27.513123989 CET | 33192 | 1440 | 192.168.2.13 | 146.190.204.203 |
Feb 1, 2025 14:46:27.517915964 CET | 1440 | 33192 | 146.190.204.203 | 192.168.2.13 |
Feb 1, 2025 14:46:27.517980099 CET | 33192 | 1440 | 192.168.2.13 | 146.190.204.203 |
Feb 1, 2025 14:46:27.522711039 CET | 1440 | 33192 | 146.190.204.203 | 192.168.2.13 |
Feb 1, 2025 14:46:38.152137041 CET | 1440 | 33192 | 146.190.204.203 | 192.168.2.13 |
Feb 1, 2025 14:46:38.152499914 CET | 33192 | 1440 | 192.168.2.13 | 146.190.204.203 |
Feb 1, 2025 14:46:38.157286882 CET | 1440 | 33192 | 146.190.204.203 | 192.168.2.13 |
Feb 1, 2025 14:46:39.334352016 CET | 33194 | 1440 | 192.168.2.13 | 146.190.204.203 |
Feb 1, 2025 14:46:39.339235067 CET | 1440 | 33194 | 146.190.204.203 | 192.168.2.13 |
Feb 1, 2025 14:46:39.339404106 CET | 33194 | 1440 | 192.168.2.13 | 146.190.204.203 |
Feb 1, 2025 14:46:39.340616941 CET | 33194 | 1440 | 192.168.2.13 | 146.190.204.203 |
Feb 1, 2025 14:46:39.345424891 CET | 1440 | 33194 | 146.190.204.203 | 192.168.2.13 |
Feb 1, 2025 14:46:39.345496893 CET | 33194 | 1440 | 192.168.2.13 | 146.190.204.203 |
Feb 1, 2025 14:46:39.350332022 CET | 1440 | 33194 | 146.190.204.203 | 192.168.2.13 |
Feb 1, 2025 14:46:50.026154041 CET | 1440 | 33194 | 146.190.204.203 | 192.168.2.13 |
Feb 1, 2025 14:46:50.026555061 CET | 33194 | 1440 | 192.168.2.13 | 146.190.204.203 |
Feb 1, 2025 14:46:50.031384945 CET | 1440 | 33194 | 146.190.204.203 | 192.168.2.13 |
Feb 1, 2025 14:46:51.114794016 CET | 33196 | 1440 | 192.168.2.13 | 146.190.204.203 |
Feb 1, 2025 14:46:51.119729996 CET | 1440 | 33196 | 146.190.204.203 | 192.168.2.13 |
Feb 1, 2025 14:46:51.119844913 CET | 33196 | 1440 | 192.168.2.13 | 146.190.204.203 |
Feb 1, 2025 14:46:51.120956898 CET | 33196 | 1440 | 192.168.2.13 | 146.190.204.203 |
Feb 1, 2025 14:46:51.128767967 CET | 1440 | 33196 | 146.190.204.203 | 192.168.2.13 |
Feb 1, 2025 14:46:51.128844976 CET | 33196 | 1440 | 192.168.2.13 | 146.190.204.203 |
Feb 1, 2025 14:46:51.133708000 CET | 1440 | 33196 | 146.190.204.203 | 192.168.2.13 |
Feb 1, 2025 14:46:59.343508959 CET | 48202 | 443 | 192.168.2.13 | 185.125.190.26 |
Feb 1, 2025 14:47:01.935077906 CET | 1440 | 33196 | 146.190.204.203 | 192.168.2.13 |
Feb 1, 2025 14:47:01.935369015 CET | 33196 | 1440 | 192.168.2.13 | 146.190.204.203 |
Feb 1, 2025 14:47:01.935416937 CET | 33196 | 1440 | 192.168.2.13 | 146.190.204.203 |
Feb 1, 2025 14:47:01.940298080 CET | 1440 | 33196 | 146.190.204.203 | 192.168.2.13 |
Feb 1, 2025 14:47:02.966658115 CET | 43994 | 1440 | 192.168.2.13 | 68.183.244.135 |
Feb 1, 2025 14:47:02.971594095 CET | 1440 | 43994 | 68.183.244.135 | 192.168.2.13 |
Feb 1, 2025 14:47:02.971700907 CET | 43994 | 1440 | 192.168.2.13 | 68.183.244.135 |
Feb 1, 2025 14:47:02.973395109 CET | 43994 | 1440 | 192.168.2.13 | 68.183.244.135 |
Feb 1, 2025 14:47:02.978252888 CET | 1440 | 43994 | 68.183.244.135 | 192.168.2.13 |
Feb 1, 2025 14:47:02.978336096 CET | 43994 | 1440 | 192.168.2.13 | 68.183.244.135 |
Feb 1, 2025 14:47:02.983127117 CET | 1440 | 43994 | 68.183.244.135 | 192.168.2.13 |
Feb 1, 2025 14:47:14.236999989 CET | 1440 | 43994 | 68.183.244.135 | 192.168.2.13 |
Feb 1, 2025 14:47:14.237303019 CET | 43994 | 1440 | 192.168.2.13 | 68.183.244.135 |
Feb 1, 2025 14:47:14.242109060 CET | 1440 | 43994 | 68.183.244.135 | 192.168.2.13 |
Feb 1, 2025 14:47:15.258985996 CET | 39168 | 1440 | 192.168.2.13 | 64.225.86.206 |
Feb 1, 2025 14:47:15.263772964 CET | 1440 | 39168 | 64.225.86.206 | 192.168.2.13 |
Feb 1, 2025 14:47:15.263875961 CET | 39168 | 1440 | 192.168.2.13 | 64.225.86.206 |
Feb 1, 2025 14:47:15.265115976 CET | 39168 | 1440 | 192.168.2.13 | 64.225.86.206 |
Feb 1, 2025 14:47:15.269871950 CET | 1440 | 39168 | 64.225.86.206 | 192.168.2.13 |
Feb 1, 2025 14:47:15.269944906 CET | 39168 | 1440 | 192.168.2.13 | 64.225.86.206 |
Feb 1, 2025 14:47:15.274775028 CET | 1440 | 39168 | 64.225.86.206 | 192.168.2.13 |
Feb 1, 2025 14:47:26.536187887 CET | 1440 | 39168 | 64.225.86.206 | 192.168.2.13 |
Feb 1, 2025 14:47:26.536760092 CET | 39168 | 1440 | 192.168.2.13 | 64.225.86.206 |
Feb 1, 2025 14:47:26.541577101 CET | 1440 | 39168 | 64.225.86.206 | 192.168.2.13 |
Feb 1, 2025 14:47:28.584572077 CET | 39170 | 1440 | 192.168.2.13 | 64.225.86.206 |
Feb 1, 2025 14:47:28.589493036 CET | 1440 | 39170 | 64.225.86.206 | 192.168.2.13 |
Feb 1, 2025 14:47:28.589564085 CET | 39170 | 1440 | 192.168.2.13 | 64.225.86.206 |
Feb 1, 2025 14:47:28.590332031 CET | 39170 | 1440 | 192.168.2.13 | 64.225.86.206 |
Feb 1, 2025 14:47:28.595200062 CET | 1440 | 39170 | 64.225.86.206 | 192.168.2.13 |
Feb 1, 2025 14:47:28.595268965 CET | 39170 | 1440 | 192.168.2.13 | 64.225.86.206 |
Feb 1, 2025 14:47:28.600095034 CET | 1440 | 39170 | 64.225.86.206 | 192.168.2.13 |
Feb 1, 2025 14:47:38.600521088 CET | 39170 | 1440 | 192.168.2.13 | 64.225.86.206 |
Feb 1, 2025 14:47:38.605371952 CET | 1440 | 39170 | 64.225.86.206 | 192.168.2.13 |
Feb 1, 2025 14:47:39.172329903 CET | 1440 | 39170 | 64.225.86.206 | 192.168.2.13 |
Feb 1, 2025 14:47:39.172580957 CET | 39170 | 1440 | 192.168.2.13 | 64.225.86.206 |
Feb 1, 2025 14:47:39.177484035 CET | 1440 | 39170 | 64.225.86.206 | 192.168.2.13 |
Feb 1, 2025 14:47:40.205038071 CET | 34016 | 1440 | 192.168.2.13 | 209.38.56.135 |
Feb 1, 2025 14:47:40.211524010 CET | 1440 | 34016 | 209.38.56.135 | 192.168.2.13 |
Feb 1, 2025 14:47:40.211632013 CET | 34016 | 1440 | 192.168.2.13 | 209.38.56.135 |
Feb 1, 2025 14:47:40.212735891 CET | 34016 | 1440 | 192.168.2.13 | 209.38.56.135 |
Feb 1, 2025 14:47:40.219284058 CET | 1440 | 34016 | 209.38.56.135 | 192.168.2.13 |
Feb 1, 2025 14:47:40.219366074 CET | 34016 | 1440 | 192.168.2.13 | 209.38.56.135 |
Feb 1, 2025 14:47:40.228065014 CET | 1440 | 34016 | 209.38.56.135 | 192.168.2.13 |
Feb 1, 2025 14:47:51.647108078 CET | 1440 | 34016 | 209.38.56.135 | 192.168.2.13 |
Feb 1, 2025 14:47:51.647452116 CET | 34016 | 1440 | 192.168.2.13 | 209.38.56.135 |
Feb 1, 2025 14:47:51.652332067 CET | 1440 | 34016 | 209.38.56.135 | 192.168.2.13 |
Feb 1, 2025 14:47:52.673433065 CET | 51684 | 1440 | 192.168.2.13 | 209.38.188.134 |
Feb 1, 2025 14:47:52.678184986 CET | 1440 | 51684 | 209.38.188.134 | 192.168.2.13 |
Feb 1, 2025 14:47:52.678287029 CET | 51684 | 1440 | 192.168.2.13 | 209.38.188.134 |
Feb 1, 2025 14:47:52.679263115 CET | 51684 | 1440 | 192.168.2.13 | 209.38.188.134 |
Feb 1, 2025 14:47:52.684031963 CET | 1440 | 51684 | 209.38.188.134 | 192.168.2.13 |
Feb 1, 2025 14:47:52.684098005 CET | 51684 | 1440 | 192.168.2.13 | 209.38.188.134 |
Feb 1, 2025 14:47:52.688826084 CET | 1440 | 51684 | 209.38.188.134 | 192.168.2.13 |
Feb 1, 2025 14:48:03.346148014 CET | 1440 | 51684 | 209.38.188.134 | 192.168.2.13 |
Feb 1, 2025 14:48:03.346422911 CET | 51684 | 1440 | 192.168.2.13 | 209.38.188.134 |
Feb 1, 2025 14:48:03.351202011 CET | 1440 | 51684 | 209.38.188.134 | 192.168.2.13 |
Feb 1, 2025 14:48:04.520903111 CET | 51686 | 1440 | 192.168.2.13 | 209.38.188.134 |
Feb 1, 2025 14:48:04.527439117 CET | 1440 | 51686 | 209.38.188.134 | 192.168.2.13 |
Feb 1, 2025 14:48:04.527493000 CET | 51686 | 1440 | 192.168.2.13 | 209.38.188.134 |
Feb 1, 2025 14:48:04.528213024 CET | 51686 | 1440 | 192.168.2.13 | 209.38.188.134 |
Feb 1, 2025 14:48:04.533313036 CET | 1440 | 51686 | 209.38.188.134 | 192.168.2.13 |
Feb 1, 2025 14:48:04.533471107 CET | 51686 | 1440 | 192.168.2.13 | 209.38.188.134 |
Feb 1, 2025 14:48:04.538249969 CET | 1440 | 51686 | 209.38.188.134 | 192.168.2.13 |
Feb 1, 2025 14:48:15.141297102 CET | 1440 | 51686 | 209.38.188.134 | 192.168.2.13 |
Feb 1, 2025 14:48:15.141958952 CET | 51686 | 1440 | 192.168.2.13 | 209.38.188.134 |
Feb 1, 2025 14:48:15.146800041 CET | 1440 | 51686 | 209.38.188.134 | 192.168.2.13 |
Feb 1, 2025 14:48:16.173015118 CET | 39178 | 1440 | 192.168.2.13 | 64.225.86.206 |
Feb 1, 2025 14:48:16.177845955 CET | 1440 | 39178 | 64.225.86.206 | 192.168.2.13 |
Feb 1, 2025 14:48:16.177984953 CET | 39178 | 1440 | 192.168.2.13 | 64.225.86.206 |
Feb 1, 2025 14:48:16.179117918 CET | 39178 | 1440 | 192.168.2.13 | 64.225.86.206 |
Feb 1, 2025 14:48:16.183960915 CET | 1440 | 39178 | 64.225.86.206 | 192.168.2.13 |
Feb 1, 2025 14:48:16.184036970 CET | 39178 | 1440 | 192.168.2.13 | 64.225.86.206 |
Feb 1, 2025 14:48:16.188863039 CET | 1440 | 39178 | 64.225.86.206 | 192.168.2.13 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Feb 1, 2025 14:46:15.824985981 CET | 34782 | 53 | 192.168.2.13 | 152.53.15.127 |
Feb 1, 2025 14:46:15.842504025 CET | 53 | 34782 | 152.53.15.127 | 192.168.2.13 |
Feb 1, 2025 14:46:27.489396095 CET | 59541 | 53 | 192.168.2.13 | 152.53.15.127 |
Feb 1, 2025 14:46:27.506470919 CET | 53 | 59541 | 152.53.15.127 | 192.168.2.13 |
Feb 1, 2025 14:46:39.156619072 CET | 34489 | 53 | 192.168.2.13 | 185.181.61.24 |
Feb 1, 2025 14:46:39.192287922 CET | 53 | 34489 | 185.181.61.24 | 192.168.2.13 |
Feb 1, 2025 14:46:39.194102049 CET | 33068 | 53 | 192.168.2.13 | 185.181.61.24 |
Feb 1, 2025 14:46:39.227159977 CET | 53 | 33068 | 185.181.61.24 | 192.168.2.13 |
Feb 1, 2025 14:46:39.229038000 CET | 41191 | 53 | 192.168.2.13 | 185.181.61.24 |
Feb 1, 2025 14:46:39.262092113 CET | 53 | 41191 | 185.181.61.24 | 192.168.2.13 |
Feb 1, 2025 14:46:39.263670921 CET | 54339 | 53 | 192.168.2.13 | 185.181.61.24 |
Feb 1, 2025 14:46:39.296788931 CET | 53 | 54339 | 185.181.61.24 | 192.168.2.13 |
Feb 1, 2025 14:46:39.298355103 CET | 49713 | 53 | 192.168.2.13 | 185.181.61.24 |
Feb 1, 2025 14:46:39.333163977 CET | 53 | 49713 | 185.181.61.24 | 192.168.2.13 |
Feb 1, 2025 14:46:51.030591965 CET | 60086 | 53 | 192.168.2.13 | 51.158.108.203 |
Feb 1, 2025 14:46:51.046251059 CET | 53 | 60086 | 51.158.108.203 | 192.168.2.13 |
Feb 1, 2025 14:46:51.047713041 CET | 35248 | 53 | 192.168.2.13 | 51.158.108.203 |
Feb 1, 2025 14:46:51.062825918 CET | 53 | 35248 | 51.158.108.203 | 192.168.2.13 |
Feb 1, 2025 14:46:51.064481974 CET | 41955 | 53 | 192.168.2.13 | 51.158.108.203 |
Feb 1, 2025 14:46:51.079622984 CET | 53 | 41955 | 51.158.108.203 | 192.168.2.13 |
Feb 1, 2025 14:46:51.081165075 CET | 42363 | 53 | 192.168.2.13 | 51.158.108.203 |
Feb 1, 2025 14:46:51.096352100 CET | 53 | 42363 | 51.158.108.203 | 192.168.2.13 |
Feb 1, 2025 14:46:51.097687006 CET | 52966 | 53 | 192.168.2.13 | 51.158.108.203 |
Feb 1, 2025 14:46:51.113920927 CET | 53 | 52966 | 51.158.108.203 | 192.168.2.13 |
Feb 1, 2025 14:47:02.939017057 CET | 36320 | 53 | 192.168.2.13 | 81.169.136.222 |
Feb 1, 2025 14:47:02.965975046 CET | 53 | 36320 | 81.169.136.222 | 192.168.2.13 |
Feb 1, 2025 14:47:15.240367889 CET | 55291 | 53 | 192.168.2.13 | 202.61.197.122 |
Feb 1, 2025 14:47:15.258027077 CET | 53 | 55291 | 202.61.197.122 | 192.168.2.13 |
Feb 1, 2025 14:47:27.539566994 CET | 48743 | 53 | 192.168.2.13 | 168.235.111.72 |
Feb 1, 2025 14:47:28.210582018 CET | 53 | 48743 | 168.235.111.72 | 192.168.2.13 |
Feb 1, 2025 14:47:28.212260962 CET | 35006 | 53 | 192.168.2.13 | 168.235.111.72 |
Feb 1, 2025 14:47:28.301014900 CET | 53 | 35006 | 168.235.111.72 | 192.168.2.13 |
Feb 1, 2025 14:47:28.302416086 CET | 33596 | 53 | 192.168.2.13 | 168.235.111.72 |
Feb 1, 2025 14:47:28.391989946 CET | 53 | 33596 | 168.235.111.72 | 192.168.2.13 |
Feb 1, 2025 14:47:28.393060923 CET | 48907 | 53 | 192.168.2.13 | 168.235.111.72 |
Feb 1, 2025 14:47:28.493273020 CET | 53 | 48907 | 168.235.111.72 | 192.168.2.13 |
Feb 1, 2025 14:47:28.494344950 CET | 35901 | 53 | 192.168.2.13 | 168.235.111.72 |
Feb 1, 2025 14:47:28.583995104 CET | 53 | 35901 | 168.235.111.72 | 192.168.2.13 |
Feb 1, 2025 14:47:40.175584078 CET | 38316 | 53 | 192.168.2.13 | 81.169.136.222 |
Feb 1, 2025 14:47:40.204039097 CET | 53 | 38316 | 81.169.136.222 | 192.168.2.13 |
Feb 1, 2025 14:47:52.649831057 CET | 46037 | 53 | 192.168.2.13 | 152.53.15.127 |
Feb 1, 2025 14:47:52.672976971 CET | 53 | 46037 | 152.53.15.127 | 192.168.2.13 |
Feb 1, 2025 14:48:04.349486113 CET | 45654 | 53 | 192.168.2.13 | 185.181.61.24 |
Feb 1, 2025 14:48:04.382642031 CET | 53 | 45654 | 185.181.61.24 | 192.168.2.13 |
Feb 1, 2025 14:48:04.383805990 CET | 51955 | 53 | 192.168.2.13 | 185.181.61.24 |
Feb 1, 2025 14:48:04.417031050 CET | 53 | 51955 | 185.181.61.24 | 192.168.2.13 |
Feb 1, 2025 14:48:04.418086052 CET | 50761 | 53 | 192.168.2.13 | 185.181.61.24 |
Feb 1, 2025 14:48:04.452168941 CET | 53 | 50761 | 185.181.61.24 | 192.168.2.13 |
Feb 1, 2025 14:48:04.453175068 CET | 60828 | 53 | 192.168.2.13 | 185.181.61.24 |
Feb 1, 2025 14:48:04.486351013 CET | 53 | 60828 | 185.181.61.24 | 192.168.2.13 |
Feb 1, 2025 14:48:04.487339020 CET | 56190 | 53 | 192.168.2.13 | 185.181.61.24 |
Feb 1, 2025 14:48:04.520458937 CET | 53 | 56190 | 185.181.61.24 | 192.168.2.13 |
Feb 1, 2025 14:48:16.145061016 CET | 48387 | 53 | 192.168.2.13 | 81.169.136.222 |
Feb 1, 2025 14:48:16.172167063 CET | 53 | 48387 | 81.169.136.222 | 192.168.2.13 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Feb 1, 2025 14:46:15.824985981 CET | 192.168.2.13 | 152.53.15.127 | 0xfde | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Feb 1, 2025 14:46:27.489396095 CET | 192.168.2.13 | 152.53.15.127 | 0x1d25 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Feb 1, 2025 14:46:39.156619072 CET | 192.168.2.13 | 185.181.61.24 | 0x13b3 | Standard query (0) | 256 | 447 | false | |
Feb 1, 2025 14:46:39.194102049 CET | 192.168.2.13 | 185.181.61.24 | 0x13b3 | Standard query (0) | 256 | 447 | false | |
Feb 1, 2025 14:46:39.229038000 CET | 192.168.2.13 | 185.181.61.24 | 0x13b3 | Standard query (0) | 256 | 447 | false | |
Feb 1, 2025 14:46:39.263670921 CET | 192.168.2.13 | 185.181.61.24 | 0x13b3 | Standard query (0) | 256 | 447 | false | |
Feb 1, 2025 14:46:39.298355103 CET | 192.168.2.13 | 185.181.61.24 | 0x13b3 | Standard query (0) | 256 | 447 | false | |
Feb 1, 2025 14:46:51.030591965 CET | 192.168.2.13 | 51.158.108.203 | 0x7ae7 | Standard query (0) | 256 | 459 | false | |
Feb 1, 2025 14:46:51.047713041 CET | 192.168.2.13 | 51.158.108.203 | 0x7ae7 | Standard query (0) | 256 | 459 | false | |
Feb 1, 2025 14:46:51.064481974 CET | 192.168.2.13 | 51.158.108.203 | 0x7ae7 | Standard query (0) | 256 | 459 | false | |
Feb 1, 2025 14:46:51.081165075 CET | 192.168.2.13 | 51.158.108.203 | 0x7ae7 | Standard query (0) | 256 | 459 | false | |
Feb 1, 2025 14:46:51.097687006 CET | 192.168.2.13 | 51.158.108.203 | 0x7ae7 | Standard query (0) | 256 | 459 | false | |
Feb 1, 2025 14:47:02.939017057 CET | 192.168.2.13 | 81.169.136.222 | 0x1049 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Feb 1, 2025 14:47:15.240367889 CET | 192.168.2.13 | 202.61.197.122 | 0x8909 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Feb 1, 2025 14:47:27.539566994 CET | 192.168.2.13 | 168.235.111.72 | 0xaaff | Standard query (0) | 256 | 496 | false | |
Feb 1, 2025 14:47:28.212260962 CET | 192.168.2.13 | 168.235.111.72 | 0xaaff | Standard query (0) | 256 | 496 | false | |
Feb 1, 2025 14:47:28.302416086 CET | 192.168.2.13 | 168.235.111.72 | 0xaaff | Standard query (0) | 256 | 496 | false | |
Feb 1, 2025 14:47:28.393060923 CET | 192.168.2.13 | 168.235.111.72 | 0xaaff | Standard query (0) | 256 | 496 | false | |
Feb 1, 2025 14:47:28.494344950 CET | 192.168.2.13 | 168.235.111.72 | 0xaaff | Standard query (0) | 256 | 496 | false | |
Feb 1, 2025 14:47:40.175584078 CET | 192.168.2.13 | 81.169.136.222 | 0x5e3d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Feb 1, 2025 14:47:52.649831057 CET | 192.168.2.13 | 152.53.15.127 | 0xa6da | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Feb 1, 2025 14:48:04.349486113 CET | 192.168.2.13 | 185.181.61.24 | 0x82cc | Standard query (0) | 256 | 276 | false | |
Feb 1, 2025 14:48:04.383805990 CET | 192.168.2.13 | 185.181.61.24 | 0x82cc | Standard query (0) | 256 | 276 | false | |
Feb 1, 2025 14:48:04.418086052 CET | 192.168.2.13 | 185.181.61.24 | 0x82cc | Standard query (0) | 256 | 276 | false | |
Feb 1, 2025 14:48:04.453175068 CET | 192.168.2.13 | 185.181.61.24 | 0x82cc | Standard query (0) | 256 | 276 | false | |
Feb 1, 2025 14:48:04.487339020 CET | 192.168.2.13 | 185.181.61.24 | 0x82cc | Standard query (0) | 256 | 276 | false | |
Feb 1, 2025 14:48:16.145061016 CET | 192.168.2.13 | 81.169.136.222 | 0xa5a4 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Feb 1, 2025 14:46:15.842504025 CET | 152.53.15.127 | 192.168.2.13 | 0xfde | No error (0) | 146.190.204.203 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:46:15.842504025 CET | 152.53.15.127 | 192.168.2.13 | 0xfde | No error (0) | 68.183.244.135 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:46:15.842504025 CET | 152.53.15.127 | 192.168.2.13 | 0xfde | No error (0) | 209.38.188.134 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:46:15.842504025 CET | 152.53.15.127 | 192.168.2.13 | 0xfde | No error (0) | 209.38.56.135 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:46:15.842504025 CET | 152.53.15.127 | 192.168.2.13 | 0xfde | No error (0) | 209.38.56.129 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:46:15.842504025 CET | 152.53.15.127 | 192.168.2.13 | 0xfde | No error (0) | 64.225.86.206 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:46:27.506470919 CET | 152.53.15.127 | 192.168.2.13 | 0x1d25 | No error (0) | 209.38.56.135 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:46:27.506470919 CET | 152.53.15.127 | 192.168.2.13 | 0x1d25 | No error (0) | 209.38.56.129 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:46:27.506470919 CET | 152.53.15.127 | 192.168.2.13 | 0x1d25 | No error (0) | 64.225.86.206 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:46:27.506470919 CET | 152.53.15.127 | 192.168.2.13 | 0x1d25 | No error (0) | 146.190.204.203 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:46:27.506470919 CET | 152.53.15.127 | 192.168.2.13 | 0x1d25 | No error (0) | 68.183.244.135 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:46:27.506470919 CET | 152.53.15.127 | 192.168.2.13 | 0x1d25 | No error (0) | 209.38.188.134 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:46:51.046251059 CET | 51.158.108.203 | 192.168.2.13 | 0x7ae7 | Format error (1) | none | none | 256 | 459 | false | |
Feb 1, 2025 14:46:51.062825918 CET | 51.158.108.203 | 192.168.2.13 | 0x7ae7 | Format error (1) | none | none | 256 | 459 | false | |
Feb 1, 2025 14:46:51.079622984 CET | 51.158.108.203 | 192.168.2.13 | 0x7ae7 | Format error (1) | none | none | 256 | 459 | false | |
Feb 1, 2025 14:46:51.096352100 CET | 51.158.108.203 | 192.168.2.13 | 0x7ae7 | Format error (1) | none | none | 256 | 459 | false | |
Feb 1, 2025 14:46:51.113920927 CET | 51.158.108.203 | 192.168.2.13 | 0x7ae7 | Format error (1) | none | none | 256 | 459 | false | |
Feb 1, 2025 14:47:02.965975046 CET | 81.169.136.222 | 192.168.2.13 | 0x1049 | No error (0) | 68.183.244.135 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:47:02.965975046 CET | 81.169.136.222 | 192.168.2.13 | 0x1049 | No error (0) | 209.38.188.134 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:47:02.965975046 CET | 81.169.136.222 | 192.168.2.13 | 0x1049 | No error (0) | 64.225.86.206 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:47:02.965975046 CET | 81.169.136.222 | 192.168.2.13 | 0x1049 | No error (0) | 209.38.56.135 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:47:02.965975046 CET | 81.169.136.222 | 192.168.2.13 | 0x1049 | No error (0) | 146.190.204.203 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:47:02.965975046 CET | 81.169.136.222 | 192.168.2.13 | 0x1049 | No error (0) | 209.38.56.129 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:47:15.258027077 CET | 202.61.197.122 | 192.168.2.13 | 0x8909 | No error (0) | 209.38.56.135 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:47:15.258027077 CET | 202.61.197.122 | 192.168.2.13 | 0x8909 | No error (0) | 64.225.86.206 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:47:15.258027077 CET | 202.61.197.122 | 192.168.2.13 | 0x8909 | No error (0) | 68.183.244.135 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:47:15.258027077 CET | 202.61.197.122 | 192.168.2.13 | 0x8909 | No error (0) | 146.190.204.203 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:47:15.258027077 CET | 202.61.197.122 | 192.168.2.13 | 0x8909 | No error (0) | 209.38.56.129 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:47:15.258027077 CET | 202.61.197.122 | 192.168.2.13 | 0x8909 | No error (0) | 209.38.188.134 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:47:40.204039097 CET | 81.169.136.222 | 192.168.2.13 | 0x5e3d | No error (0) | 209.38.188.134 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:47:40.204039097 CET | 81.169.136.222 | 192.168.2.13 | 0x5e3d | No error (0) | 64.225.86.206 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:47:40.204039097 CET | 81.169.136.222 | 192.168.2.13 | 0x5e3d | No error (0) | 68.183.244.135 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:47:40.204039097 CET | 81.169.136.222 | 192.168.2.13 | 0x5e3d | No error (0) | 146.190.204.203 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:47:40.204039097 CET | 81.169.136.222 | 192.168.2.13 | 0x5e3d | No error (0) | 209.38.56.129 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:47:40.204039097 CET | 81.169.136.222 | 192.168.2.13 | 0x5e3d | No error (0) | 209.38.56.135 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:47:52.672976971 CET | 152.53.15.127 | 192.168.2.13 | 0xa6da | No error (0) | 68.183.244.135 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:47:52.672976971 CET | 152.53.15.127 | 192.168.2.13 | 0xa6da | No error (0) | 209.38.188.134 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:47:52.672976971 CET | 152.53.15.127 | 192.168.2.13 | 0xa6da | No error (0) | 209.38.56.135 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:47:52.672976971 CET | 152.53.15.127 | 192.168.2.13 | 0xa6da | No error (0) | 209.38.56.129 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:47:52.672976971 CET | 152.53.15.127 | 192.168.2.13 | 0xa6da | No error (0) | 64.225.86.206 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:47:52.672976971 CET | 152.53.15.127 | 192.168.2.13 | 0xa6da | No error (0) | 146.190.204.203 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:48:16.172167063 CET | 81.169.136.222 | 192.168.2.13 | 0xa5a4 | No error (0) | 209.38.188.134 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:48:16.172167063 CET | 81.169.136.222 | 192.168.2.13 | 0xa5a4 | No error (0) | 64.225.86.206 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:48:16.172167063 CET | 81.169.136.222 | 192.168.2.13 | 0xa5a4 | No error (0) | 209.38.56.129 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:48:16.172167063 CET | 81.169.136.222 | 192.168.2.13 | 0xa5a4 | No error (0) | 68.183.244.135 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:48:16.172167063 CET | 81.169.136.222 | 192.168.2.13 | 0xa5a4 | No error (0) | 146.190.204.203 | A (IP address) | IN (0x0001) | false | ||
Feb 1, 2025 14:48:16.172167063 CET | 81.169.136.222 | 192.168.2.13 | 0xa5a4 | No error (0) | 209.38.56.135 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 13:46:15 |
Start date (UTC): | 01/02/2025 |
Path: | /tmp/zersh4.elf |
Arguments: | /tmp/zersh4.elf |
File size: | 4139976 bytes |
MD5 hash: | 8943e5f8f8c280467b4472c15ae93ba9 |
Start time (UTC): | 13:46:15 |
Start date (UTC): | 01/02/2025 |
Path: | /tmp/zersh4.elf |
Arguments: | - |
File size: | 4139976 bytes |
MD5 hash: | 8943e5f8f8c280467b4472c15ae93ba9 |
Start time (UTC): | 13:46:15 |
Start date (UTC): | 01/02/2025 |
Path: | /tmp/zersh4.elf |
Arguments: | - |
File size: | 4139976 bytes |
MD5 hash: | 8943e5f8f8c280467b4472c15ae93ba9 |