Edit tour
Linux
Analysis Report
harm4.elf
Overview
General Information
Sample name: | harm4.elf |
Analysis ID: | 1552992 |
MD5: | 648de4e8238d1565b3b40bf88f84ff12 |
SHA1: | c6ccc773cdff3e37e5466d0e7a0d7eb656d61cd3 |
SHA256: | 0cddf21d0971458dc4aa374b1345e8455ca213cb3bb6b3f541bb0acad1f884e4 |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Score: | 52 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1552992 |
Start date and time: | 2024-11-10 06:07:03 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 30s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | harm4.elf |
Detection: | MAL |
Classification: | mal52.troj.linELF@0/0@8/0 |
Command: | /tmp/harm4.elf |
PID: | 6225 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | you are now apart of hail cock botnet |
Standard Error: |
⊘No yara matches
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | ReversingLabs: |
Networking |
---|
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | .symtab present: |
Source: | Classification label: |
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | 1 File Deletion | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 2 Application Layer Protocol | Traffic Duplication | Data Destruction |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
13% | ReversingLabs | Linux.Backdoor.Mirai |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
kingstonwikkerink.dyn | 193.233.193.45 | true | false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
31.13.248.89 | unknown | Bulgaria | 34224 | NETERRA-ASBG | false | |
86.107.100.80 | unknown | Romania | 38995 | AMG-ASRO | false | |
54.171.230.55 | unknown | United States | 16509 | AMAZON-02US | false | |
91.149.238.18 | unknown | Poland | 41952 | MARTON-ASPL | true | |
91.189.91.43 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
54.171.230.55 | Get hash | malicious | Mirai, Okiru | Browse | ||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Chaos | Browse | |||
Get hash | malicious | Mirai | Browse | |||
109.202.202.202 | Get hash | malicious | Unknown | Browse |
| |
31.13.248.89 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
86.107.100.80 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
kingstonwikkerink.dyn | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
NETERRA-ASBG | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
AMAZON-02US | Get hash | malicious | PureCrypter, LummaC, Amadey, LummaC Stealer, Stealc, Vidar | Browse |
| |
Get hash | malicious | Amadey, Stealc, Vidar | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | HtmlDropper, HTMLPhisher | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | PureCrypter, LummaC, Amadey, LummaC Stealer, Stealc, Vidar | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
INIT7CH | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
AMG-ASRO | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 6.1256368507240735 |
TrID: |
|
File name: | harm4.elf |
File size: | 61'456 bytes |
MD5: | 648de4e8238d1565b3b40bf88f84ff12 |
SHA1: | c6ccc773cdff3e37e5466d0e7a0d7eb656d61cd3 |
SHA256: | 0cddf21d0971458dc4aa374b1345e8455ca213cb3bb6b3f541bb0acad1f884e4 |
SHA512: | 0186300389bc2b2441823bd85f2b6d93b466a2b628b9d19a616462554b35ba59e03ac7c2480d1ddadb31ebefd30d85c58e4578c709b110bdfacacc618a703175 |
SSDEEP: | 768:CeFqmcoUh1NDbyonPcl+1LHcfiERCmz1Nd96zV6mtMa/10VIIacHVJ8lvYy4mI:pF2vxL8f96hOaLIdYlvp |
TLSH: | 82534B80BD819A13C6D412BBFB6E418D372713A8D2EE7207DD259F21378696F0D7B641 |
File Content Preview: | .ELF...a..........(.........4...X.......4. ...(.........................................................l%..........Q.td..................................-...L."....5..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 61016 |
Section Header Size: | 40 |
Number of Section Headers: | 11 |
Header String Table Index: | 10 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x8094 | 0x94 | 0x18 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x80b0 | 0xb0 | 0xd690 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x15740 | 0xd740 | 0x14 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x15754 | 0xd754 | 0x132c | 0x0 | 0x2 | A | 0 | 0 | 4 |
.eh_frame | PROGBITS | 0x16a80 | 0xea80 | 0x4 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ctors | PROGBITS | 0x1ea84 | 0xea84 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x1ea8c | 0xea8c | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x1ea98 | 0xea98 | 0x378 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x1ee10 | 0xee10 | 0x21e0 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.shstrtab | STRTAB | 0x0 | 0xee10 | 0x48 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8000 | 0x8000 | 0xea84 | 0xea84 | 6.1641 | 0x5 | R E | 0x8000 | .init .text .fini .rodata .eh_frame | |
LOAD | 0xea84 | 0x1ea84 | 0x1ea84 | 0x38c | 0x256c | 2.8124 | 0x6 | RW | 0x8000 | .ctors .dtors .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 10, 2024 06:07:48.004532099 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Nov 10, 2024 06:07:50.398462057 CET | 57748 | 7299 | 192.168.2.23 | 31.13.248.89 |
Nov 10, 2024 06:07:50.403295040 CET | 7299 | 57748 | 31.13.248.89 | 192.168.2.23 |
Nov 10, 2024 06:07:50.403342962 CET | 57748 | 7299 | 192.168.2.23 | 31.13.248.89 |
Nov 10, 2024 06:07:50.403456926 CET | 57748 | 7299 | 192.168.2.23 | 31.13.248.89 |
Nov 10, 2024 06:07:50.408204079 CET | 7299 | 57748 | 31.13.248.89 | 192.168.2.23 |
Nov 10, 2024 06:07:50.408252001 CET | 57748 | 7299 | 192.168.2.23 | 31.13.248.89 |
Nov 10, 2024 06:07:50.412986994 CET | 7299 | 57748 | 31.13.248.89 | 192.168.2.23 |
Nov 10, 2024 06:07:51.413741112 CET | 7299 | 57748 | 31.13.248.89 | 192.168.2.23 |
Nov 10, 2024 06:07:51.414087057 CET | 57748 | 7299 | 192.168.2.23 | 31.13.248.89 |
Nov 10, 2024 06:07:51.414170980 CET | 57748 | 7299 | 192.168.2.23 | 31.13.248.89 |
Nov 10, 2024 06:07:53.379759073 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Nov 10, 2024 06:07:54.915605068 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Nov 10, 2024 06:08:08.481595039 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Nov 10, 2024 06:08:11.461867094 CET | 58554 | 6320 | 192.168.2.23 | 91.149.238.18 |
Nov 10, 2024 06:08:11.466691971 CET | 6320 | 58554 | 91.149.238.18 | 192.168.2.23 |
Nov 10, 2024 06:08:11.466754913 CET | 58554 | 6320 | 192.168.2.23 | 91.149.238.18 |
Nov 10, 2024 06:08:11.466799974 CET | 58554 | 6320 | 192.168.2.23 | 91.149.238.18 |
Nov 10, 2024 06:08:11.471625090 CET | 6320 | 58554 | 91.149.238.18 | 192.168.2.23 |
Nov 10, 2024 06:08:11.471673012 CET | 58554 | 6320 | 192.168.2.23 | 91.149.238.18 |
Nov 10, 2024 06:08:11.476519108 CET | 6320 | 58554 | 91.149.238.18 | 192.168.2.23 |
Nov 10, 2024 06:08:12.347404003 CET | 6320 | 58554 | 91.149.238.18 | 192.168.2.23 |
Nov 10, 2024 06:08:12.347539902 CET | 58554 | 6320 | 192.168.2.23 | 91.149.238.18 |
Nov 10, 2024 06:08:12.347585917 CET | 58554 | 6320 | 192.168.2.23 | 91.149.238.18 |
Nov 10, 2024 06:08:17.376641989 CET | 37756 | 14180 | 192.168.2.23 | 91.149.238.18 |
Nov 10, 2024 06:08:17.381534100 CET | 14180 | 37756 | 91.149.238.18 | 192.168.2.23 |
Nov 10, 2024 06:08:17.381652117 CET | 37756 | 14180 | 192.168.2.23 | 91.149.238.18 |
Nov 10, 2024 06:08:17.381671906 CET | 37756 | 14180 | 192.168.2.23 | 91.149.238.18 |
Nov 10, 2024 06:08:17.386610031 CET | 14180 | 37756 | 91.149.238.18 | 192.168.2.23 |
Nov 10, 2024 06:08:17.386691093 CET | 37756 | 14180 | 192.168.2.23 | 91.149.238.18 |
Nov 10, 2024 06:08:17.391529083 CET | 14180 | 37756 | 91.149.238.18 | 192.168.2.23 |
Nov 10, 2024 06:08:18.251246929 CET | 14180 | 37756 | 91.149.238.18 | 192.168.2.23 |
Nov 10, 2024 06:08:18.251463890 CET | 37756 | 14180 | 192.168.2.23 | 91.149.238.18 |
Nov 10, 2024 06:08:18.251548052 CET | 37756 | 14180 | 192.168.2.23 | 91.149.238.18 |
Nov 10, 2024 06:08:20.767817974 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Nov 10, 2024 06:08:23.287868977 CET | 37044 | 2982 | 192.168.2.23 | 86.107.100.80 |
Nov 10, 2024 06:08:23.292823076 CET | 2982 | 37044 | 86.107.100.80 | 192.168.2.23 |
Nov 10, 2024 06:08:23.292918921 CET | 37044 | 2982 | 192.168.2.23 | 86.107.100.80 |
Nov 10, 2024 06:08:23.292939901 CET | 37044 | 2982 | 192.168.2.23 | 86.107.100.80 |
Nov 10, 2024 06:08:23.297758102 CET | 2982 | 37044 | 86.107.100.80 | 192.168.2.23 |
Nov 10, 2024 06:08:23.297821045 CET | 37044 | 2982 | 192.168.2.23 | 86.107.100.80 |
Nov 10, 2024 06:08:23.302777052 CET | 2982 | 37044 | 86.107.100.80 | 192.168.2.23 |
Nov 10, 2024 06:08:24.708735943 CET | 33606 | 443 | 192.168.2.23 | 54.171.230.55 |
Nov 10, 2024 06:08:24.715873957 CET | 443 | 33606 | 54.171.230.55 | 192.168.2.23 |
Nov 10, 2024 06:08:24.716146946 CET | 33606 | 443 | 192.168.2.23 | 54.171.230.55 |
Nov 10, 2024 06:08:24.863101006 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Nov 10, 2024 06:08:33.301680088 CET | 37044 | 2982 | 192.168.2.23 | 86.107.100.80 |
Nov 10, 2024 06:08:33.306602001 CET | 2982 | 37044 | 86.107.100.80 | 192.168.2.23 |
Nov 10, 2024 06:08:33.866852999 CET | 2982 | 37044 | 86.107.100.80 | 192.168.2.23 |
Nov 10, 2024 06:08:33.867113113 CET | 37044 | 2982 | 192.168.2.23 | 86.107.100.80 |
Nov 10, 2024 06:08:49.435642004 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 10, 2024 06:07:45.376969099 CET | 43647 | 53 | 192.168.2.23 | 178.254.22.166 |
Nov 10, 2024 06:07:50.382458925 CET | 48557 | 53 | 192.168.2.23 | 51.158.108.203 |
Nov 10, 2024 06:07:50.397749901 CET | 53 | 48557 | 51.158.108.203 | 192.168.2.23 |
Nov 10, 2024 06:07:56.416402102 CET | 60472 | 53 | 192.168.2.23 | 5.161.109.23 |
Nov 10, 2024 06:08:01.422065973 CET | 57489 | 53 | 192.168.2.23 | 64.176.6.48 |
Nov 10, 2024 06:08:06.427800894 CET | 49839 | 53 | 192.168.2.23 | 178.254.22.166 |
Nov 10, 2024 06:08:11.434017897 CET | 40285 | 53 | 192.168.2.23 | 81.169.136.222 |
Nov 10, 2024 06:08:11.461129904 CET | 53 | 40285 | 81.169.136.222 | 192.168.2.23 |
Nov 10, 2024 06:08:17.349225998 CET | 33488 | 53 | 192.168.2.23 | 65.21.1.106 |
Nov 10, 2024 06:08:17.376144886 CET | 53 | 33488 | 65.21.1.106 | 192.168.2.23 |
Nov 10, 2024 06:08:23.253739119 CET | 57006 | 53 | 192.168.2.23 | 185.181.61.24 |
Nov 10, 2024 06:08:23.286825895 CET | 53 | 57006 | 185.181.61.24 | 192.168.2.23 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 10, 2024 06:07:45.376969099 CET | 192.168.2.23 | 178.254.22.166 | 0x3d99 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 10, 2024 06:07:50.382458925 CET | 192.168.2.23 | 51.158.108.203 | 0xc772 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 10, 2024 06:07:56.416402102 CET | 192.168.2.23 | 5.161.109.23 | 0x9f99 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 10, 2024 06:08:01.422065973 CET | 192.168.2.23 | 64.176.6.48 | 0xbae9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 10, 2024 06:08:06.427800894 CET | 192.168.2.23 | 178.254.22.166 | 0x8b5c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 10, 2024 06:08:11.434017897 CET | 192.168.2.23 | 81.169.136.222 | 0x3c4d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 10, 2024 06:08:17.349225998 CET | 192.168.2.23 | 65.21.1.106 | 0xfd4b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 10, 2024 06:08:23.253739119 CET | 192.168.2.23 | 185.181.61.24 | 0xd068 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 10, 2024 06:07:50.397749901 CET | 51.158.108.203 | 192.168.2.23 | 0xc772 | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:07:50.397749901 CET | 51.158.108.203 | 192.168.2.23 | 0xc772 | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:07:50.397749901 CET | 51.158.108.203 | 192.168.2.23 | 0xc772 | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:07:50.397749901 CET | 51.158.108.203 | 192.168.2.23 | 0xc772 | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:07:50.397749901 CET | 51.158.108.203 | 192.168.2.23 | 0xc772 | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:07:50.397749901 CET | 51.158.108.203 | 192.168.2.23 | 0xc772 | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:07:50.397749901 CET | 51.158.108.203 | 192.168.2.23 | 0xc772 | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:07:50.397749901 CET | 51.158.108.203 | 192.168.2.23 | 0xc772 | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:07:50.397749901 CET | 51.158.108.203 | 192.168.2.23 | 0xc772 | No error (0) | 217.28.130.41 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:08:11.461129904 CET | 81.169.136.222 | 192.168.2.23 | 0x3c4d | No error (0) | 217.28.130.41 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:08:11.461129904 CET | 81.169.136.222 | 192.168.2.23 | 0x3c4d | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:08:11.461129904 CET | 81.169.136.222 | 192.168.2.23 | 0x3c4d | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:08:11.461129904 CET | 81.169.136.222 | 192.168.2.23 | 0x3c4d | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:08:11.461129904 CET | 81.169.136.222 | 192.168.2.23 | 0x3c4d | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:08:11.461129904 CET | 81.169.136.222 | 192.168.2.23 | 0x3c4d | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:08:11.461129904 CET | 81.169.136.222 | 192.168.2.23 | 0x3c4d | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:08:11.461129904 CET | 81.169.136.222 | 192.168.2.23 | 0x3c4d | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:08:11.461129904 CET | 81.169.136.222 | 192.168.2.23 | 0x3c4d | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:08:17.376144886 CET | 65.21.1.106 | 192.168.2.23 | 0xfd4b | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:08:17.376144886 CET | 65.21.1.106 | 192.168.2.23 | 0xfd4b | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:08:17.376144886 CET | 65.21.1.106 | 192.168.2.23 | 0xfd4b | No error (0) | 217.28.130.41 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:08:17.376144886 CET | 65.21.1.106 | 192.168.2.23 | 0xfd4b | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:08:17.376144886 CET | 65.21.1.106 | 192.168.2.23 | 0xfd4b | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:08:17.376144886 CET | 65.21.1.106 | 192.168.2.23 | 0xfd4b | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:08:17.376144886 CET | 65.21.1.106 | 192.168.2.23 | 0xfd4b | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:08:17.376144886 CET | 65.21.1.106 | 192.168.2.23 | 0xfd4b | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:08:17.376144886 CET | 65.21.1.106 | 192.168.2.23 | 0xfd4b | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:08:23.286825895 CET | 185.181.61.24 | 192.168.2.23 | 0xd068 | No error (0) | 193.233.193.45 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:08:23.286825895 CET | 185.181.61.24 | 192.168.2.23 | 0xd068 | No error (0) | 91.149.218.232 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:08:23.286825895 CET | 185.181.61.24 | 192.168.2.23 | 0xd068 | No error (0) | 91.149.238.18 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:08:23.286825895 CET | 185.181.61.24 | 192.168.2.23 | 0xd068 | No error (0) | 31.13.248.89 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:08:23.286825895 CET | 185.181.61.24 | 192.168.2.23 | 0xd068 | No error (0) | 86.107.100.80 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:08:23.286825895 CET | 185.181.61.24 | 192.168.2.23 | 0xd068 | No error (0) | 217.28.130.41 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:08:23.286825895 CET | 185.181.61.24 | 192.168.2.23 | 0xd068 | No error (0) | 88.151.195.22 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:08:23.286825895 CET | 185.181.61.24 | 192.168.2.23 | 0xd068 | No error (0) | 81.29.149.178 | A (IP address) | IN (0x0001) | false | ||
Nov 10, 2024 06:08:23.286825895 CET | 185.181.61.24 | 192.168.2.23 | 0xd068 | No error (0) | 213.182.204.57 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 05:07:44 |
Start date (UTC): | 10/11/2024 |
Path: | /tmp/harm4.elf |
Arguments: | /tmp/harm4.elf |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 05:07:44 |
Start date (UTC): | 10/11/2024 |
Path: | /tmp/harm4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 05:08:23 |
Start date (UTC): | 10/11/2024 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 05:08:23 |
Start date (UTC): | 10/11/2024 |
Path: | /usr/bin/rm |
Arguments: | rm -f /tmp/tmp.Qfksf9HK6a /tmp/tmp.FvTNS7bE3S /tmp/tmp.VgzGYBwJ5D |
File size: | 72056 bytes |
MD5 hash: | aa2b5496fdbfd88e38791ab81f90b95b |
Start time (UTC): | 05:08:23 |
Start date (UTC): | 10/11/2024 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 05:08:23 |
Start date (UTC): | 10/11/2024 |
Path: | /usr/bin/rm |
Arguments: | rm -f /tmp/tmp.Qfksf9HK6a /tmp/tmp.FvTNS7bE3S /tmp/tmp.VgzGYBwJ5D |
File size: | 72056 bytes |
MD5 hash: | aa2b5496fdbfd88e38791ab81f90b95b |