Linux
Analysis Report
logrotate
Overview
General Information
Sample name: | logrotate |
Analysis ID: | 1628361 |
MD5: | e70e9d3525f36a9ccbf2a37f8a773015 |
SHA1: | 815bc1a79440cdc4a7e1d876ff2dc7bc4f53d25e |
SHA256: | 3eb47033cd5399aee33048d6ded163105158882b2483884bc949697f3bfd0d95 |
Infos: |
Detection
Score: | 80 |
Range: | 0 - 100 |
Signatures
Classification
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1628361 |
Start date and time: | 2025-03-03 19:18:16 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 6m 12s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 16.04 x64 (Kernel 4.4.0-116, Firefox 88.0, Document Viewer 3.18.2, LibreOffice 5.1.6.2, OpenJDK 1.8.0_171) |
Analysis Mode: | default |
Sample name: | logrotate |
Detection: | MAL |
Classification: | mal80.mine.lin@0/1@0/0 |
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Command: | /tmp/logrotate |
PID: | 4710 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | |
Standard Error: |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
XMRIG | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Xmrig | Yara detected Xmrig cryptocurrency miner | Joe Security | ||
Linux_Trojan_Pornoasset_927f314f | unknown | unknown |
| |
miner_lin_xmrig_strings | Detects XMRig ELF | Sekoia.io |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Xmrig | Yara detected Xmrig cryptocurrency miner | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Linux_Trojan_Pornoasset_927f314f | unknown | unknown |
|
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-03-03T19:18:54.135750+0100 | 2826930 | 2 | Crypto Currency Mining Activity Detected | 192.168.2.20 | 41548 | 185.196.8.41 | 443 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Virustotal: | Perma Link |
Bitcoin Miner |
---|
Source: | File source: | ||
Source: | File source: |
Source: | TCP traffic: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Modprobe: | Jump to behavior |
Source: | MSR open for writing: | Jump to behavior |
Source: | Reads CPU info from proc file: | Jump to behavior |
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior |
Source: | Suricata IDS: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | .symtab present: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | Directory: | Jump to behavior |
Source: | Shell command executed: | Jump to behavior |
Source: | Reads from proc file: | Jump to behavior | ||
Source: | Reads from proc file: | Jump to behavior | ||
Source: | Reads from proc file: | Jump to behavior |
Source: | Modprobe: | Jump to behavior |
Source: | Reads CPU info from proc file: | Jump to behavior |
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | Windows Management Instrumentation | 1 Kernel Modules and Extensions | 1 Kernel Modules and Extensions | 1 Hidden Files and Directories | OS Credential Dumping | 1 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 Scripting | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | 23 System Information Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
45% | Virustotal | Browse |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
185.196.8.41 | unknown | Switzerland | 34888 | SIMPLECARRER2IT | true |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
185.196.8.41 | Get hash | malicious | Xmrig | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
SIMPLECARRER2IT | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Amadey | Browse |
| ||
Get hash | malicious | Amadey | Browse |
| ||
Get hash | malicious | Amadey | Browse |
| ||
Get hash | malicious | PureLog Stealer, RHADAMANTHYS, zgRAT | Browse |
| ||
Get hash | malicious | Quasar | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Process: | /tmp/logrotate |
File Type: | |
Category: | dropped |
Size (bytes): | 3 |
Entropy (8bit): | 1.584962500721156 |
Encrypted: | false |
SSDEEP: | 3:Odn:Od |
MD5: | 76DC611D6EBAAFC66CC0879C71B5DB5C |
SHA1: | B4182BFF4B3CF75F9E54F4990F9BD153C0C2973C |
SHA-256: | 2747B7C718564BA5F066F0523B03E17F6A496B06851333D2D59AB6D863225848 |
SHA-512: | E2BC8CA53E630757EF4A3E8F3D0FC48AAC10A66DBE6D14D759D00C21263F4C0623F6841DC3995081F97EFF9641EA9BE42C9219F66E6C5B9EA9EFFA1C8450C3FB |
Malicious: | false |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 6.351905474305259 |
TrID: |
|
File name: | logrotate |
File size: | 7'447'240 bytes |
MD5: | e70e9d3525f36a9ccbf2a37f8a773015 |
SHA1: | 815bc1a79440cdc4a7e1d876ff2dc7bc4f53d25e |
SHA256: | 3eb47033cd5399aee33048d6ded163105158882b2483884bc949697f3bfd0d95 |
SHA512: | 7ca6d1c0045292f4c50dc66bf62ffc111525cd36897c1448caea079e9b4922418f2dda30d42588868f7889fd69f11db1a8265d492626a1a6cc288fe93578bb02 |
SSDEEP: | 196608:uJy1VOJo4/kKCPvH4zzzzzzzzzzz/zzzzzzzzzzzwzz6/zzz3HLSW:OY4/khP/4zzzzzzzzzzz/zzzzzzzzzzF |
TLSH: | BB764B1AB6A358BDC1A6C430876FD663AD34B85542217D7B3184EA302F67E305B1EF72 |
File Content Preview: | .ELF..............>.....p.@.....@.......H.q.........@.8...@.......................@.......@.....P.......P.................................@.......@......?S......?S......................PS......P.......P.......Y.......Y........................j............ |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 64 |
Program Header Offset: | 64 |
Program Header Size: | 56 |
Number of Program Headers: | 8 |
Section Header Offset: | 7445320 |
Section Header Size: | 64 |
Number of Section Headers: | 30 |
Header String Table Index: | 29 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.note.gnu.build-id | NOTE | 0x400200 | 0x200 | 0x24 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.note.ABI-tag | NOTE | 0x400224 | 0x224 | 0x20 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.rela.plt | RELA | 0x400248 | 0x248 | 0x408 | 0x18 | 0x42 | AI | 0 | 20 | 8 |
.init | PROGBITS | 0x401000 | 0x1000 | 0x17 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.plt | PROGBITS | 0x401018 | 0x1018 | 0x158 | 0x0 | 0x6 | AX | 0 | 0 | 8 |
.text | PROGBITS | 0x401180 | 0x1180 | 0x533012 | 0x0 | 0x6 | AX | 0 | 0 | 64 |
__libc_freeres_fn | PROGBITS | 0x9341a0 | 0x5341a0 | 0xdf8 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x934f98 | 0x534f98 | 0x9 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x935000 | 0x535000 | 0xa0d3c | 0x0 | 0x2 | A | 0 | 0 | 64 |
.stapsdt.base | PROGBITS | 0x9d5d3c | 0x5d5d3c | 0x1 | 0x0 | 0x2 | A | 0 | 0 | 1 |
.eh_frame | PROGBITS | 0x9d5d40 | 0x5d5d40 | 0xcc0d0 | 0x0 | 0x2 | A | 0 | 0 | 8 |
.gcc_except_table | PROGBITS | 0xaa1e10 | 0x6a1e10 | 0x8bc4 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.tdata | PROGBITS | 0xaabff0 | 0x6aaff0 | 0x70 | 0x0 | 0x403 | WAT | 0 | 0 | 16 |
.tbss | NOBITS | 0xaac060 | 0x6ab060 | 0x70 | 0x0 | 0x403 | WAT | 0 | 0 | 16 |
.preinit_array | PREINIT_ARRAY | 0xaac060 | 0x6ab060 | 0x8 | 0x8 | 0x3 | WA | 0 | 0 | 8 |
.init_array | INIT_ARRAY | 0xaac068 | 0x6ab068 | 0x140 | 0x8 | 0x3 | WA | 0 | 0 | 8 |
.fini_array | FINI_ARRAY | 0xaac1a8 | 0x6ab1a8 | 0x18 | 0x8 | 0x3 | WA | 0 | 0 | 8 |
.data.rel.ro | PROGBITS | 0xaac1c0 | 0x6ab1c0 | 0x64c24 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.got | PROGBITS | 0xb10de8 | 0x70fde8 | 0x208 | 0x0 | 0x3 | WA | 0 | 0 | 8 |
.got.plt | PROGBITS | 0xb11000 | 0x710000 | 0x170 | 0x8 | 0x3 | WA | 0 | 0 | 8 |
.data | PROGBITS | 0xb11180 | 0x710180 | 0x8dcc | 0x0 | 0x3 | WA | 0 | 0 | 32 |
__libc_subfreeres | PROGBITS | 0xb19f50 | 0x718f50 | 0xa8 | 0x0 | 0x3 | WA | 0 | 0 | 8 |
__libc_IO_vtables | PROGBITS | 0xb1a000 | 0x719000 | 0x8e8 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
__libc_atexit | PROGBITS | 0xb1a8e8 | 0x7198e8 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 8 |
.bss | NOBITS | 0xb1a900 | 0x7198f0 | 0x9c280 | 0x0 | 0x3 | WA | 0 | 0 | 64 |
__libc_freeres_ptrs | NOBITS | 0xbb6b80 | 0x7198f0 | 0x48 | 0x0 | 0x3 | WA | 0 | 0 | 8 |
.comment | PROGBITS | 0x0 | 0x7198f0 | 0x27 | 0x1 | 0x30 | MS | 0 | 0 | 1 |
.note.stapsdt | NOTE | 0x0 | 0x719918 | 0xe8 | 0x0 | 0x0 | 0 | 0 | 4 | |
.shstrtab | STRTAB | 0x0 | 0x719a00 | 0x143 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x400000 | 0x400000 | 0x650 | 0x650 | 2.4488 | 0x4 | R | 0x1000 | .note.gnu.build-id .note.ABI-tag .rela.plt | |
LOAD | 0x1000 | 0x401000 | 0x401000 | 0x533fa1 | 0x533fa1 | 6.4018 | 0x5 | R E | 0x1000 | .init .plt .text __libc_freeres_fn .fini | |
LOAD | 0x535000 | 0x935000 | 0x935000 | 0x1759d4 | 0x1759d4 | 6.0948 | 0x4 | R | 0x1000 | .rodata .stapsdt.base .eh_frame .gcc_except_table | |
LOAD | 0x6aaff0 | 0xaabff0 | 0xaabff0 | 0x6e900 | 0x10abd8 | 2.4675 | 0x6 | RW | 0x1000 | .tdata .tbss .preinit_array .init_array .fini_array .data.rel.ro .got .got.plt .data __libc_subfreeres __libc_IO_vtables __libc_atexit .bss __libc_freeres_ptrs | |
NOTE | 0x200 | 0x400200 | 0x400200 | 0x44 | 0x44 | 3.3673 | 0x4 | R | 0x4 | .note.gnu.build-id .note.ABI-tag | |
TLS | 0x6aaff0 | 0xaabff0 | 0xaabff0 | 0x70 | 0xe0 | 2.1257 | 0x4 | R | 0x10 | .tdata .tbss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x10 | ||
GNU_RELRO | 0x6aaff0 | 0xaabff0 | 0xaabff0 | 0x65010 | 0x65010 | 2.4117 | 0x4 | R | 0x1 | .tdata .tbss .preinit_array .init_array .fini_array .data.rel.ro .got |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-03-03T19:18:54.135750+0100 | 2826930 | ETPRO COINMINER XMR CoinMiner Usage | 2 | 192.168.2.20 | 41548 | 185.196.8.41 | 443 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 3, 2025 19:18:53.434576035 CET | 41548 | 443 | 192.168.2.20 | 185.196.8.41 |
Mar 3, 2025 19:18:53.434623003 CET | 443 | 41548 | 185.196.8.41 | 192.168.2.20 |
Mar 3, 2025 19:18:53.434674025 CET | 41548 | 443 | 192.168.2.20 | 185.196.8.41 |
Mar 3, 2025 19:18:53.435019016 CET | 41548 | 443 | 192.168.2.20 | 185.196.8.41 |
Mar 3, 2025 19:18:53.435034990 CET | 443 | 41548 | 185.196.8.41 | 192.168.2.20 |
Mar 3, 2025 19:18:54.129514933 CET | 443 | 41548 | 185.196.8.41 | 192.168.2.20 |
Mar 3, 2025 19:18:54.129740000 CET | 41548 | 443 | 192.168.2.20 | 185.196.8.41 |
Mar 3, 2025 19:18:54.130919933 CET | 41548 | 443 | 192.168.2.20 | 185.196.8.41 |
Mar 3, 2025 19:18:54.130929947 CET | 443 | 41548 | 185.196.8.41 | 192.168.2.20 |
Mar 3, 2025 19:18:54.133104086 CET | 443 | 41548 | 185.196.8.41 | 192.168.2.20 |
Mar 3, 2025 19:18:54.135514021 CET | 41548 | 443 | 192.168.2.20 | 185.196.8.41 |
Mar 3, 2025 19:18:54.135623932 CET | 443 | 41548 | 185.196.8.41 | 192.168.2.20 |
Mar 3, 2025 19:18:54.174026012 CET | 41548 | 443 | 192.168.2.20 | 185.196.8.41 |
Mar 3, 2025 19:18:54.174040079 CET | 443 | 41548 | 185.196.8.41 | 192.168.2.20 |
Mar 3, 2025 19:18:54.174092054 CET | 41548 | 443 | 192.168.2.20 | 185.196.8.41 |
Mar 3, 2025 19:18:54.449481010 CET | 443 | 41548 | 185.196.8.41 | 192.168.2.20 |
Mar 3, 2025 19:18:54.449569941 CET | 41548 | 443 | 192.168.2.20 | 185.196.8.41 |
Mar 3, 2025 19:19:00.186218977 CET | 443 | 41548 | 185.196.8.41 | 192.168.2.20 |
Mar 3, 2025 19:19:00.186388016 CET | 41548 | 443 | 192.168.2.20 | 185.196.8.41 |
Mar 3, 2025 19:19:07.907812119 CET | 443 | 41548 | 185.196.8.41 | 192.168.2.20 |
Mar 3, 2025 19:19:07.907897949 CET | 41548 | 443 | 192.168.2.20 | 185.196.8.41 |
Mar 3, 2025 19:20:07.950009108 CET | 41548 | 443 | 192.168.2.20 | 185.196.8.41 |
Mar 3, 2025 19:20:07.950028896 CET | 443 | 41548 | 185.196.8.41 | 192.168.2.20 |
Mar 3, 2025 19:20:08.397638083 CET | 41548 | 443 | 192.168.2.20 | 185.196.8.41 |
Mar 3, 2025 19:20:08.439374924 CET | 443 | 41548 | 185.196.8.41 | 192.168.2.20 |
Mar 3, 2025 19:20:08.605133057 CET | 443 | 41548 | 185.196.8.41 | 192.168.2.20 |
Mar 3, 2025 19:20:08.605331898 CET | 41548 | 443 | 192.168.2.20 | 185.196.8.41 |
Mar 3, 2025 19:21:08.685856104 CET | 41548 | 443 | 192.168.2.20 | 185.196.8.41 |
Mar 3, 2025 19:21:08.685883999 CET | 443 | 41548 | 185.196.8.41 | 192.168.2.20 |
Mar 3, 2025 19:21:09.407331944 CET | 41548 | 443 | 192.168.2.20 | 185.196.8.41 |
Mar 3, 2025 19:21:09.407361984 CET | 443 | 41548 | 185.196.8.41 | 192.168.2.20 |
Mar 3, 2025 19:21:09.609901905 CET | 443 | 41548 | 185.196.8.41 | 192.168.2.20 |
Mar 3, 2025 19:21:09.609956026 CET | 41548 | 443 | 192.168.2.20 | 185.196.8.41 |
Mar 3, 2025 19:21:25.341289043 CET | 443 | 41548 | 185.196.8.41 | 192.168.2.20 |
Mar 3, 2025 19:21:25.341485977 CET | 41548 | 443 | 192.168.2.20 | 185.196.8.41 |
Mar 3, 2025 19:21:35.598195076 CET | 443 | 41548 | 185.196.8.41 | 192.168.2.20 |
Mar 3, 2025 19:21:35.598381996 CET | 41548 | 443 | 192.168.2.20 | 185.196.8.41 |
Mar 3, 2025 19:21:45.722121000 CET | 443 | 41548 | 185.196.8.41 | 192.168.2.20 |
Mar 3, 2025 19:21:45.722313881 CET | 41548 | 443 | 192.168.2.20 | 185.196.8.41 |
Mar 3, 2025 19:21:55.942827940 CET | 443 | 41548 | 185.196.8.41 | 192.168.2.20 |
Mar 3, 2025 19:21:55.943028927 CET | 41548 | 443 | 192.168.2.20 | 185.196.8.41 |
Mar 3, 2025 19:22:06.044003963 CET | 443 | 41548 | 185.196.8.41 | 192.168.2.20 |
Mar 3, 2025 19:22:06.044209003 CET | 41548 | 443 | 192.168.2.20 | 185.196.8.41 |
Mar 3, 2025 19:22:16.158124924 CET | 443 | 41548 | 185.196.8.41 | 192.168.2.20 |
Mar 3, 2025 19:22:16.158191919 CET | 41548 | 443 | 192.168.2.20 | 185.196.8.41 |
Mar 3, 2025 19:22:26.130011082 CET | 443 | 41548 | 185.196.8.41 | 192.168.2.20 |
Mar 3, 2025 19:22:26.130105019 CET | 41548 | 443 | 192.168.2.20 | 185.196.8.41 |
Mar 3, 2025 19:22:36.197283030 CET | 443 | 41548 | 185.196.8.41 | 192.168.2.20 |
Mar 3, 2025 19:22:36.197518110 CET | 41548 | 443 | 192.168.2.20 | 185.196.8.41 |
Mar 3, 2025 19:22:46.219875097 CET | 443 | 41548 | 185.196.8.41 | 192.168.2.20 |
Mar 3, 2025 19:22:46.220004082 CET | 41548 | 443 | 192.168.2.20 | 185.196.8.41 |
Mar 3, 2025 19:22:56.277545929 CET | 443 | 41548 | 185.196.8.41 | 192.168.2.20 |
Mar 3, 2025 19:22:56.277654886 CET | 41548 | 443 | 192.168.2.20 | 185.196.8.41 |
Mar 3, 2025 19:23:12.538456917 CET | 443 | 41548 | 185.196.8.41 | 192.168.2.20 |
Mar 3, 2025 19:23:12.538849115 CET | 41548 | 443 | 192.168.2.20 | 185.196.8.41 |
Mar 3, 2025 19:23:12.538880110 CET | 443 | 41548 | 185.196.8.41 | 192.168.2.20 |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.20 | 41548 | 185.196.8.41 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-03 18:18:54 UTC | 350 | OUT | |
2025-03-03 18:18:54 UTC | 491 | IN | |
2025-03-03 18:19:00 UTC | 378 | IN | |
2025-03-03 18:19:07 UTC | 378 | IN | |
2025-03-03 18:20:08 UTC | 83 | OUT | |
2025-03-03 18:20:08 UTC | 71 | IN | |
2025-03-03 18:21:09 UTC | 83 | OUT | |
2025-03-03 18:21:09 UTC | 71 | IN | |
2025-03-03 18:21:25 UTC | 376 | IN | |
2025-03-03 18:21:35 UTC | 376 | IN |
System Behavior
Start time (UTC): | 18:18:52 |
Start date (UTC): | 03/03/2025 |
Path: | /tmp/logrotate |
Arguments: | /tmp/logrotate |
File size: | 7447240 bytes |
MD5 hash: | e70e9d3525f36a9ccbf2a37f8a773015 |
Start time (UTC): | 18:18:52 |
Start date (UTC): | 03/03/2025 |
Path: | /tmp/logrotate |
Arguments: | - |
File size: | 7447240 bytes |
MD5 hash: | e70e9d3525f36a9ccbf2a37f8a773015 |
Start time (UTC): | 18:18:53 |
Start date (UTC): | 03/03/2025 |
Path: | /tmp/logrotate |
Arguments: | - |
File size: | 7447240 bytes |
MD5 hash: | e70e9d3525f36a9ccbf2a37f8a773015 |
Start time (UTC): | 18:18:53 |
Start date (UTC): | 03/03/2025 |
Path: | /bin/sh |
Arguments: | sh -c "/sbin/modprobe msr allow_writes=on > /dev/null 2>&1" |
File size: | 4 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
Start time (UTC): | 18:18:53 |
Start date (UTC): | 03/03/2025 |
Path: | /bin/sh |
Arguments: | - |
File size: | 4 bytes |
MD5 hash: | e02ea3c3450d44126c46d658fa9e654c |
Start time (UTC): | 18:18:53 |
Start date (UTC): | 03/03/2025 |
Path: | /sbin/modprobe |
Arguments: | /sbin/modprobe msr allow_writes=on |
File size: | 0 bytes |
MD5 hash: | unknown |