Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
Linux4.7.elf

Overview

General Information

Sample name:Linux4.7.elf
Analysis ID:1584220
MD5:bea79d22552cac2f0ddeff8b33682b0d
SHA1:183cb250e3211af0ccc1960a6a241a6ea90a95da
SHA256:4efe185e41696351835356a55211aeb113994f87887cab3ffbbaacecb589e9f6
Tags:elfuser-abuse_ch
Infos:

Detection

Score:96
Range:0 - 100
Whitelisted:false

Signatures

Antivirus detection for dropped file
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Drops files in suspicious directories
Drops invisible ELF files
Executes the "iptables" command to insert, remove and/or manipulate rules
Machine Learning detection for dropped file
Machine Learning detection for sample
Sample deletes itself
Sample tries to persist itself using System V runlevels
Sample tries to persist itself using cron
Creates hidden files and/or directories
Executes commands using a shell command-line interpreter
Executes the "iptables" command used for managing IP filtering and manipulation
Executes the "rm" command used to delete files or directories
Executes the "systemctl" command used for controlling the systemd system and service manager
Executes the "touch" command used to create files or modify time stamps
Sample has stripped symbol table
Sleeps for long times indicative of sandbox evasion
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Writes ELF files to disk
Writes shell script file to disk with an unusual file extension
Writes shell script files to disk
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1584220
Start date and time:2025-01-04 21:32:05 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 33s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Linux4.7.elf
Detection:MAL
Classification:mal96.troj.evad.linELF@0/5@0/0
Command:/tmp/Linux4.7.elf
PID:6223
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • Linux4.7.elf (PID: 6223, Parent: 6140, MD5: bea79d22552cac2f0ddeff8b33682b0d) Arguments: /tmp/Linux4.7.elf
    • Linux4.7.elf New Fork (PID: 6224, Parent: 6223)
      • Linux4.7.elf New Fork (PID: 6225, Parent: 6224)
        • Linux4.7.elf New Fork (PID: 6228, Parent: 6225)
          • update-rc.d (PID: 6229, Parent: 1860, MD5: 16a21f464119ea7fad1d3660de963637) Arguments: update-rc.d Linux4.7.elf remove
            • systemctl (PID: 6236, Parent: 6229, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl daemon-reload
        • Linux4.7.elf New Fork (PID: 6232, Parent: 6225)
          • update-rc.d (PID: 6233, Parent: 1860, MD5: 16a21f464119ea7fad1d3660de963637) Arguments: update-rc.d .chinaz{1736022760 defaults
            • systemctl (PID: 6238, Parent: 6233, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl daemon-reload
        • sh (PID: 6234, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "sed -i '/\\/etc\\/cron.hourly\\/cron.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/cron.sh' >> /etc/crontab"
          • sh New Fork (PID: 6235, Parent: 6234)
          • sed (PID: 6235, Parent: 6234, MD5: 885062561f66aa1d4af4c54b9e7cc81a) Arguments: sed -i /\\/etc\\/cron.hourly\\/cron.sh/d /etc/crontab
        • sh (PID: 6237, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "rm -rf /etc/resolv.conf"
          • sh New Fork (PID: 6239, Parent: 6237)
          • rm (PID: 6239, Parent: 6237, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -rf /etc/resolv.conf
        • sh (PID: 6242, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c whoami
          • sh New Fork (PID: 6247, Parent: 6242)
          • whoami (PID: 6247, Parent: 6242, MD5: dbc1888ae50bb5d4d9a7a210d51be710) Arguments: whoami
        • sh (PID: 6243, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables --flush"
          • sh New Fork (PID: 6245, Parent: 6243)
          • iptables (PID: 6245, Parent: 6243, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables --flush
        • sh (PID: 6244, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c whoami
          • sh New Fork (PID: 6246, Parent: 6244)
          • whoami (PID: 6246, Parent: 6244, MD5: dbc1888ae50bb5d4d9a7a210d51be710) Arguments: whoami
        • sh (PID: 6264, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6270, Parent: 6264)
          • iptables (PID: 6270, Parent: 6264, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6269, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "touch /home/root/ConfigDatecz"
          • sh New Fork (PID: 6271, Parent: 6269)
          • touch (PID: 6271, Parent: 6269, MD5: 3859c173f5d3b37be3e531b7c84a9c68) Arguments: touch /home/root/ConfigDatecz
        • sh (PID: 6276, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6280, Parent: 6276)
          • iptables (PID: 6280, Parent: 6276, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6281, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6282, Parent: 6281)
          • iptables (PID: 6282, Parent: 6281, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6283, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6284, Parent: 6283)
          • iptables (PID: 6284, Parent: 6283, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6285, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6286, Parent: 6285)
          • iptables (PID: 6286, Parent: 6285, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6287, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6288, Parent: 6287)
          • iptables (PID: 6288, Parent: 6287, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6289, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6290, Parent: 6289)
          • iptables (PID: 6290, Parent: 6289, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6293, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6294, Parent: 6293)
          • iptables (PID: 6294, Parent: 6293, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6295, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6296, Parent: 6295)
          • iptables (PID: 6296, Parent: 6295, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6338, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6339, Parent: 6338)
          • iptables (PID: 6339, Parent: 6338, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6340, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6341, Parent: 6340)
          • iptables (PID: 6341, Parent: 6340, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6342, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6343, Parent: 6342)
          • iptables (PID: 6343, Parent: 6342, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6344, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6345, Parent: 6344)
          • iptables (PID: 6345, Parent: 6344, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6346, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6347, Parent: 6346)
          • iptables (PID: 6347, Parent: 6346, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6348, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6349, Parent: 6348)
          • iptables (PID: 6349, Parent: 6348, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6350, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6351, Parent: 6350)
          • iptables (PID: 6351, Parent: 6350, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6352, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6353, Parent: 6352)
          • iptables (PID: 6353, Parent: 6352, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6354, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6355, Parent: 6354)
          • iptables (PID: 6355, Parent: 6354, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6372, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6373, Parent: 6372)
          • iptables (PID: 6373, Parent: 6372, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6374, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6375, Parent: 6374)
          • iptables (PID: 6375, Parent: 6374, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6376, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6377, Parent: 6376)
          • iptables (PID: 6377, Parent: 6376, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6378, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6379, Parent: 6378)
          • iptables (PID: 6379, Parent: 6378, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6380, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6381, Parent: 6380)
          • iptables (PID: 6381, Parent: 6380, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6382, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6383, Parent: 6382)
          • iptables (PID: 6383, Parent: 6382, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6384, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6385, Parent: 6384)
          • iptables (PID: 6385, Parent: 6384, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6386, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6387, Parent: 6386)
          • iptables (PID: 6387, Parent: 6386, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6388, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6389, Parent: 6388)
          • iptables (PID: 6389, Parent: 6388, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6403, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6404, Parent: 6403)
          • iptables (PID: 6404, Parent: 6403, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6405, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6406, Parent: 6405)
          • iptables (PID: 6406, Parent: 6405, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6407, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6408, Parent: 6407)
          • iptables (PID: 6408, Parent: 6407, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6409, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6410, Parent: 6409)
          • iptables (PID: 6410, Parent: 6409, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6411, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6412, Parent: 6411)
          • iptables (PID: 6412, Parent: 6411, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6413, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6414, Parent: 6413)
          • iptables (PID: 6414, Parent: 6413, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6415, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6416, Parent: 6415)
          • iptables (PID: 6416, Parent: 6415, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6417, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6418, Parent: 6417)
          • iptables (PID: 6418, Parent: 6417, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
        • sh (PID: 6419, Parent: 6225, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
          • sh New Fork (PID: 6420, Parent: 6419)
          • iptables (PID: 6420, Parent: 6419, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A OUTPUT -p tcp --dport 0 -j DROP
  • systemd New Fork (PID: 6249, Parent: 6248)
  • snapd-env-generator (PID: 6249, Parent: 6248, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • systemd New Fork (PID: 6273, Parent: 6272)
  • snapd-env-generator (PID: 6273, Parent: 6272, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • cleanup
SourceRuleDescriptionAuthorStrings
Linux4.7.elfLinux_Trojan_Xorddos_a6572d63unknownunknown
  • 0xb80ad:$a: C8 0F B6 46 04 0F B6 56 05 C1 E0 08 09 D0 89 45 CC 0F B6 46 06 0F B6
Linux4.7.elfCN_disclosed_20180208_lslsDetects malware from disclosed CN malware setFlorian Roth
  • 0xf5ef0:$x1: User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
SourceRuleDescriptionAuthorStrings
/etc/init.d/.chinaz{1736022760Linux_Trojan_Xorddos_a6572d63unknownunknown
  • 0xb80ad:$a: C8 0F B6 46 04 0F B6 56 05 C1 E0 08 09 D0 89 45 CC 0F B6 46 06 0F B6
/etc/init.d/.chinaz{1736022760CN_disclosed_20180208_lslsDetects malware from disclosed CN malware setFlorian Roth
  • 0xf5ef0:$x1: User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
SourceRuleDescriptionAuthorStrings
6227.1.0000000008048000.0000000008188000.r-x.sdmpLinux_Trojan_Xorddos_a6572d63unknownunknown
  • 0xb80ad:$a: C8 0F B6 46 04 0F B6 56 05 C1 E0 08 09 D0 89 45 CC 0F B6 46 06 0F B6
6227.1.0000000008048000.0000000008188000.r-x.sdmpCN_disclosed_20180208_lslsDetects malware from disclosed CN malware setFlorian Roth
  • 0xf5ef0:$x1: User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
6232.1.0000000008048000.0000000008188000.r-x.sdmpLinux_Trojan_Xorddos_a6572d63unknownunknown
  • 0xb80ad:$a: C8 0F B6 46 04 0F B6 56 05 C1 E0 08 09 D0 89 45 CC 0F B6 46 06 0F B6
6232.1.0000000008048000.0000000008188000.r-x.sdmpCN_disclosed_20180208_lslsDetects malware from disclosed CN malware setFlorian Roth
  • 0xf5ef0:$x1: User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)
6230.1.0000000008048000.0000000008188000.r-x.sdmpLinux_Trojan_Xorddos_a6572d63unknownunknown
  • 0xb80ad:$a: C8 0F B6 46 04 0F B6 56 05 C1 E0 08 09 D0 89 45 CC 0F B6 46 06 0F B6
Click to see the 13 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: /etc/cron.hourly/cron.shAvira: detection malicious, Label: LINUX/Xorddos.ZY
Source: Linux4.7.elfReversingLabs: Detection: 73%
Source: /etc/init.d/.chinaz{1736022760Joe Sandbox ML: detected
Source: Linux4.7.elfJoe Sandbox ML: detected

Networking

barindex
Source: /bin/sh (PID: 6270)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6280)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6282)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6284)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6286)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6288)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6290)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6294)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6296)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6339)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6341)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6343)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6345)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6347)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6349)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6351)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6353)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6355)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6373)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6375)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6377)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6379)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6381)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6383)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6385)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6387)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6389)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6404)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6406)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6408)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6410)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6412)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6414)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6416)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6418)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6420)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6245)Iptables executable: /usr/sbin/iptables -> iptables --flushJump to behavior
Source: /bin/sh (PID: 6270)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6280)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6282)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6284)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6286)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6288)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6290)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6294)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6296)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6339)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6341)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6343)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6345)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6347)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6349)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6351)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6353)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6355)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6373)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6375)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6377)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6379)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6381)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6383)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6385)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6387)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6389)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6404)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6406)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6408)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6410)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6412)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6414)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6416)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6418)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6420)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: Linux4.7.elf, .chinaz{1736022760.14.drString found in binary or memory: http://www.gnu.org/software/libc/bugs.html
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: Linux4.7.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown
Source: Linux4.7.elf, type: SAMPLEMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: 6227.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown
Source: 6227.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: 6232.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown
Source: 6232.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: 6230.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown
Source: 6230.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: 6225.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown
Source: 6225.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: 6223.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown
Source: 6223.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: 6228.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown
Source: 6228.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: 6226.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown
Source: 6226.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: 6231.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown
Source: 6231.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: 6224.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown
Source: 6224.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: /etc/init.d/.chinaz{1736022760, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown
Source: /etc/init.d/.chinaz{1736022760, type: DROPPEDMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
Source: ELF static info symbol of initial sample.symtab present: no
Source: Linux4.7.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16
Source: Linux4.7.elf, type: SAMPLEMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
Source: 6227.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16
Source: 6227.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
Source: 6232.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16
Source: 6232.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
Source: 6230.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16
Source: 6230.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
Source: 6225.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16
Source: 6225.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
Source: 6223.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16
Source: 6223.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
Source: 6228.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16
Source: 6228.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
Source: 6226.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16
Source: 6226.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
Source: 6231.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16
Source: 6231.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
Source: 6224.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16
Source: 6224.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORYMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
Source: /etc/init.d/.chinaz{1736022760, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16
Source: /etc/init.d/.chinaz{1736022760, type: DROPPEDMatched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
Source: classification engineClassification label: mal96.troj.evad.linELF@0/5@0/0

Persistence and Installation Behavior

barindex
Source: /bin/sh (PID: 6270)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6280)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6282)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6284)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6286)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6288)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6290)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6294)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6296)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6339)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6341)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6343)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6345)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6347)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6349)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6351)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6353)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6355)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6373)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6375)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6377)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6379)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6381)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6383)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6385)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6387)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6389)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6404)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6406)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6408)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6410)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6412)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6414)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6416)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6418)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6420)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)File: /etc/rc1.d/S90.chinaz{1736022760 -> /etc/init.d/.chinaz{1736022760Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)File: /etc/rc2.d/S90.chinaz{1736022760 -> /etc/init.d/.chinaz{1736022760Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)File: /etc/rc3.d/S90.chinaz{1736022760 -> /etc/init.d/.chinaz{1736022760Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)File: /etc/rc4.d/S90.chinaz{1736022760 -> /etc/init.d/.chinaz{1736022760Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)File: /etc/rc5.d/S90.chinaz{1736022760 -> /etc/init.d/.chinaz{1736022760Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)File: /etc/rc.d/rc1.d/S90.chinaz{1736022760 -> /etc/init.d/.chinaz{1736022760Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)File: /etc/rc.d/rc2.d/S90.chinaz{1736022760 -> /etc/init.d/.chinaz{1736022760Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)File: /etc/rc.d/rc3.d/S90.chinaz{1736022760 -> /etc/init.d/.chinaz{1736022760Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)File: /etc/rc.d/rc4.d/S90.chinaz{1736022760 -> /etc/init.d/.chinaz{1736022760Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)File: /etc/rc.d/rc5.d/S90.chinaz{1736022760 -> /etc/init.d/.chinaz{1736022760Jump to behavior
Source: /usr/sbin/update-rc.d (PID: 6233)File: /etc/rc1.d/S01.chinaz{1736022760 -> ../init.d/.chinaz{1736022760Jump to behavior
Source: /usr/sbin/update-rc.d (PID: 6233)File: /etc/rc2.d/S01.chinaz{1736022760 -> ../init.d/.chinaz{1736022760Jump to behavior
Source: /usr/sbin/update-rc.d (PID: 6233)File: /etc/rc3.d/S01.chinaz{1736022760 -> ../init.d/.chinaz{1736022760Jump to behavior
Source: /usr/sbin/update-rc.d (PID: 6233)File: /etc/rc4.d/S01.chinaz{1736022760 -> ../init.d/.chinaz{1736022760Jump to behavior
Source: /usr/sbin/update-rc.d (PID: 6233)File: /etc/rc5.d/S01.chinaz{1736022760 -> ../init.d/.chinaz{1736022760Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)File: /etc/cron.hourly/cron.shJump to behavior
Source: /usr/bin/sed (PID: 6235)File: /etc/crontabJump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)File: /tmp/.chinaz{1736022760Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)File: /etc/init.d/.chinaz{1736022760Jump to behavior
Source: /usr/sbin/update-rc.d (PID: 6233)Directory: /etc/init.d/.chinaz{1736022760Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6234)Shell command executed: sh -c "sed -i '/\\/etc\\/cron.hourly\\/cron.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/cron.sh' >> /etc/crontab"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6237)Shell command executed: sh -c "rm -rf /etc/resolv.conf"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6242)Shell command executed: sh -c whoamiJump to behavior
Source: /tmp/Linux4.7.elf (PID: 6243)Shell command executed: sh -c "iptables --flush"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6244)Shell command executed: sh -c whoamiJump to behavior
Source: /tmp/Linux4.7.elf (PID: 6264)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6269)Shell command executed: sh -c "touch /home/root/ConfigDatecz"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6276)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6281)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6283)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6285)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6287)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6289)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6293)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6295)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6338)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6340)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6342)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6344)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6346)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6348)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6350)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6352)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6354)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6372)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6374)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6376)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6378)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6380)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6382)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6384)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6386)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6388)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6403)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6405)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6407)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6409)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6411)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6413)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6415)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6417)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6419)Shell command executed: sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"Jump to behavior
Source: /bin/sh (PID: 6245)Iptables executable: /usr/sbin/iptables -> iptables --flushJump to behavior
Source: /bin/sh (PID: 6270)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6280)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6282)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6284)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6286)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6288)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6290)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6294)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6296)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6339)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6341)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6343)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6345)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6347)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6349)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6351)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6353)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6355)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6373)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6375)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6377)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6379)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6381)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6383)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6385)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6387)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6389)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6404)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6406)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6408)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6410)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6412)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6414)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6416)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6418)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6420)Iptables executable: /usr/sbin/iptables -> iptables -A OUTPUT -p tcp --dport 0 -j DROPJump to behavior
Source: /bin/sh (PID: 6239)Rm executable: /usr/bin/rm -> rm -rf /etc/resolv.confJump to behavior
Source: /usr/sbin/update-rc.d (PID: 6236)Systemctl executable: /usr/bin/systemctl -> systemctl daemon-reloadJump to behavior
Source: /usr/sbin/update-rc.d (PID: 6238)Systemctl executable: /usr/bin/systemctl -> systemctl daemon-reloadJump to behavior
Source: /bin/sh (PID: 6271)Touch executable: /usr/bin/touch -> touch /home/root/ConfigDateczJump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)File written: /tmp/.chinaz{1736022760Jump to dropped file
Source: /tmp/Linux4.7.elf (PID: 6225)Writes shell script file to disk with an unusual file extension: /etc/init.d/.chinaz{1736022760Jump to dropped file
Source: /tmp/Linux4.7.elf (PID: 6225)Shell script file created: /etc/cron.hourly/cron.shJump to dropped file
Source: /bin/sh (PID: 6235)Sed executable: /usr/bin/sed -> sed -i /\\/etc\\/cron.hourly\\/cron.sh/d /etc/crontabJump to behavior

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/Linux4.7.elf (PID: 6225)File: /etc/init.d/.chinaz{1736022760Jump to dropped file
Source: /tmp/Linux4.7.elf (PID: 6225)ELF file: /tmp/.chinaz{1736022760Jump to dropped file
Source: /tmp/Linux4.7.elf (PID: 6225)File: /tmp/Linux4.7.elfJump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)Sleeps longer then 60s: 600.0sJump to behavior
Source: /tmp/Linux4.7.elf (PID: 6223)Queries kernel information via 'uname': Jump to behavior
Source: /tmp/Linux4.7.elf (PID: 6225)Queries kernel information via 'uname': Jump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information2
Scripting
Valid Accounts1
Command and Scripting Interpreter
1
Systemd Service
1
Systemd Service
1
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job2
Scripting
Boot or Logon Initialization Scripts1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)11
Hidden Files and Directories
Security Account Manager1
System Network Configuration Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Indicator Removal
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script11
File Deletion
LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1584220 Sample: Linux4.7.elf Startdate: 04/01/2025 Architecture: LINUX Score: 96 56 109.202.202.202, 80 INIT7CH Switzerland 2->56 58 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->58 60 91.189.91.43, 443 CANONICAL-ASGB United Kingdom 2->60 62 Malicious sample detected (through community Yara rule) 2->62 64 Antivirus detection for dropped file 2->64 66 Multi AV Scanner detection for submitted file 2->66 68 2 other signatures 2->68 11 Linux4.7.elf 2->11         started        13 systemd snapd-env-generator 2->13         started        15 systemd snapd-env-generator 2->15         started        signatures3 process4 process5 17 Linux4.7.elf 11->17         started        process6 19 Linux4.7.elf 17->19         started        file7 50 /tmp/.chinaz{1736022760, ELF 19->50 dropped 52 /etc/init.d/.chinaz{1736022760, POSIX 19->52 dropped 54 /etc/cron.hourly/cron.sh, POSIX 19->54 dropped 70 Drops invisible ELF files 19->70 72 Drops files in suspicious directories 19->72 74 Sample deletes itself 19->74 76 2 other signatures 19->76 23 Linux4.7.elf 19->23         started        25 Linux4.7.elf sh 19->25         started        27 Linux4.7.elf sh 19->27         started        29 43 other processes 19->29 signatures8 process9 process10 31 Linux4.7.elf update-rc.d 23->31         started        34 sh sed 25->34         started        36 sh iptables 27->36         started        38 sh iptables 29->38         started        40 sh iptables 29->40         started        42 sh iptables 29->42         started        44 40 other processes 29->44 signatures11 78 Sample tries to persist itself using System V runlevels 31->78 46 update-rc.d systemctl 31->46         started        80 Sample tries to persist itself using cron 34->80 82 Executes the "iptables" command to insert, remove and/or manipulate rules 36->82 48 update-rc.d systemctl 44->48         started        process12

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
Linux4.7.elf74%ReversingLabsLinux.Trojan.XorDDoS
Linux4.7.elf100%Joe Sandbox ML
SourceDetectionScannerLabelLink
/etc/cron.hourly/cron.sh100%AviraLINUX/Xorddos.ZY
/etc/init.d/.chinaz{1736022760100%Joe Sandbox ML
/etc/cron.hourly/cron.sh19%ReversingLabsLinux.Network.Xor
/etc/cron.hourly/cron.sh11%VirustotalBrowse
/tmp/.chinaz{173602276074%ReversingLabsLinux.Trojan.XorDDoS
/tmp/.chinaz{173602276065%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://www.gnu.org/software/libc/bugs.htmlLinux4.7.elf, .chinaz{1736022760.14.drfalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
    • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
    91.189.91.43Space.arm5.elfGet hashmaliciousUnknownBrowse
      Space.ppc.elfGet hashmaliciousMiraiBrowse
        fenty.arm4.elfGet hashmaliciousMiraiBrowse
          main_sh4.elfGet hashmaliciousMiraiBrowse
            arm7.elfGet hashmaliciousMiraiBrowse
              .i.elfGet hashmaliciousUnknownBrowse
                arm.elfGet hashmaliciousMiraiBrowse
                  main_sh4.elfGet hashmaliciousMiraiBrowse
                    .i.elfGet hashmaliciousUnknownBrowse
                      main_arm5.elfGet hashmaliciousMiraiBrowse
                        91.189.91.42Space.arm5.elfGet hashmaliciousUnknownBrowse
                          Space.ppc.elfGet hashmaliciousMiraiBrowse
                            fenty.arm4.elfGet hashmaliciousMiraiBrowse
                              main_sh4.elfGet hashmaliciousMiraiBrowse
                                arm7.elfGet hashmaliciousMiraiBrowse
                                  .i.elfGet hashmaliciousUnknownBrowse
                                    arm.elfGet hashmaliciousMiraiBrowse
                                      main_sh4.elfGet hashmaliciousMiraiBrowse
                                        .i.elfGet hashmaliciousUnknownBrowse
                                          main_arm5.elfGet hashmaliciousMiraiBrowse
                                            No context
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            CANONICAL-ASGBSpace.arm5.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            Space.ppc.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            fenty.arm4.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            main_sh4.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            arm7.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            .i.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            arm.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            main_sh4.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            .i.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            main_arm5.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            CANONICAL-ASGBSpace.arm5.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            Space.ppc.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            fenty.arm4.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            main_sh4.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            arm7.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            .i.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            arm.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            main_sh4.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            .i.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            main_arm5.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            INIT7CHSpace.arm5.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            Space.ppc.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            fenty.arm4.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            main_sh4.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            arm7.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            .i.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            arm.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            main_sh4.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            .i.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            main_arm5.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            No context
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            /etc/cron.hourly/cron.shLinux4.7.elfGet hashmaliciousUnknownBrowse
                                              testGet hashmaliciousXorDDoSBrowse
                                                chinazGet hashmaliciousUnknownBrowse
                                                  HuuyISbqrLGet hashmaliciousUnknownBrowse
                                                    Process:/tmp/Linux4.7.elf
                                                    File Type:POSIX shell script, ASCII text executable
                                                    Category:dropped
                                                    Size (bytes):223
                                                    Entropy (8bit):4.756432444291805
                                                    Encrypted:false
                                                    SSDEEP:6:htiy4Mrm9lVNy28XbCVP270gJdUiynrgns:RjwVNfGbWPirSR
                                                    MD5:B791B087B1795E3674A9AA765C76FC04
                                                    SHA1:B53F478234AE97F3CDBF2E7FE7EC68D687FEB7C1
                                                    SHA-256:1C1E9B69CF8021BF7CE1F60DCAA2D31C1E21ED4B6E474F3571DA81FFD5A9B69E
                                                    SHA-512:2DCC2E478C51CF8118306FD5C744AAD7147E368CBC4329DB1CC5FAC52088A7F3354079AE2B582B270495789E4FB4591538EC88BB5EA40EEC646F360BAC33BBB2
                                                    Malicious:true
                                                    Antivirus:
                                                    • Antivirus: Avira, Detection: 100%
                                                    • Antivirus: ReversingLabs, Detection: 19%
                                                    • Antivirus: Virustotal, Detection: 11%, Browse
                                                    Joe Sandbox View:
                                                    • Filename: Linux4.7.elf, Detection: malicious, Browse
                                                    • Filename: test, Detection: malicious, Browse
                                                    • Filename: chinaz, Detection: malicious, Browse
                                                    • Filename: HuuyISbqrL, Detection: malicious, Browse
                                                    Reputation:low
                                                    Preview:#!/bin/sh.PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:/usr/X11R6/bin.for i in `cat /proc/net/dev|grep :|awk -F: {'print $1'}`; do ifconfig $i up& done.cp /lib/udev/udev /lib/udev/debug./lib/udev/debug.
                                                    Process:/tmp/Linux4.7.elf
                                                    File Type:POSIX shell script, ASCII text executable
                                                    Category:dropped
                                                    Size (bytes):355
                                                    Entropy (8bit):5.361857554256731
                                                    Encrypted:false
                                                    SSDEEP:6:hUtoFdU9uMw21CnsKheJjU51wBE21YJvmNeMwh2L51Y1DzRIju1p6MzEu1d4:6tw21rjc1wBEMO12L51Czuju1pzEu1G
                                                    MD5:85D93963A0595FAC4C980BC82207840B
                                                    SHA1:4178C1F994B86FE5F24ECDE530D3E7ED81EDAFD9
                                                    SHA-256:63CC98FF708BF1C8A7E95FCA49B6209A603C5F79442CB385CEC355A7A520087E
                                                    SHA-512:3DE06A9FDB22904C6673209021249B949AA08E528907BD1EFEDE8C6177BB29414AC6C9B713CFE8751521C903D37EDA8CC1C8B457A1F8B9F231F21737346BB711
                                                    Malicious:true
                                                    Yara Hits:
                                                    • Rule: Linux_Trojan_Xorddos_a6572d63, Description: unknown, Source: /etc/init.d/.chinaz{1736022760, Author: unknown
                                                    • Rule: CN_disclosed_20180208_lsls, Description: Detects malware from disclosed CN malware set, Source: /etc/init.d/.chinaz{1736022760, Author: Florian Roth
                                                    Antivirus:
                                                    • Antivirus: Joe Sandbox ML, Detection: 100%
                                                    Reputation:low
                                                    Preview:#!/bin/sh.# chkconfig: 12345 90 90.# description: .chinaz{1736022760.### BEGIN INIT INFO.# Provides:...chinaz{1736022760.# Required-Start:..# Required-Stop:..# Default-Start:.1 2 3 4 5.# Default-Stop:...# Short-Description:..chinaz{1736022760.### END INIT INFO.case $1 in.start)../tmp/.chinaz{1736022760..;;.stop)..;;.*)../tmp/.chinaz{1736022760..;;.esac.
                                                    Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                    File Type:ASCII text
                                                    Category:dropped
                                                    Size (bytes):76
                                                    Entropy (8bit):3.7627880354948586
                                                    Encrypted:false
                                                    SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                                                    MD5:D86A1F5765F37989EB0EC3837AD13ECC
                                                    SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                                                    SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                                                    SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                                                    Malicious:false
                                                    Reputation:moderate, very likely benign file
                                                    Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                                                    Process:/tmp/Linux4.7.elf
                                                    File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, for GNU/Linux 2.6.18, BuildID[sha1]=307edfa923d9ff7e3793ec8771ab90f5343cb21e, stripped
                                                    Category:dropped
                                                    Size (bytes):1315556
                                                    Entropy (8bit):6.390073589605978
                                                    Encrypted:false
                                                    SSDEEP:24576:8kUpotcUSzgtPLdOEG0V0JRzFB3ywyUZ1N2AhNdhBjh+hnPlVVW0Mk7t69Kx/ti8:MoKXwZOK0TFBCwy8P2AhNdhBjh+hnPlP
                                                    MD5:BEA79D22552CAC2F0DDEFF8B33682B0D
                                                    SHA1:183CB250E3211AF0CCC1960A6A241A6EA90A95DA
                                                    SHA-256:4EFE185E41696351835356A55211AEB113994F87887CAB3FFBBAACECB589E9F6
                                                    SHA-512:AE59FD898E659F6E361EFD1755E16C64BB2C72198BBC18784DF6DAD2FD90B3B0D456D44B739547AAEADA60CC747111BE07CCC552EAB221D699AD284069D80B03
                                                    Malicious:true
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 74%
                                                    • Antivirus: Virustotal, Detection: 65%, Browse
                                                    Reputation:low
                                                    Preview:.ELF........................4...........4. ...(.................................................................................D...D.............................L...........Q.td........................................GNU.............................GNU.0~.#..~7..q...4<..p...*...t...*...x...*...|...*.......*.......*.......*...U..S........[........|.....t..~........D<..X[...%p...h..........%t...h..........%x...h..........%|...h..........%....h..........%....h..........%....h.........1.^....PTRh....h0...QVh......;.................U..S.d$.=`....uS......d...............9.s...t&.....d...........d...9.r.......t...$.....1....`.....d$.[]..t&.U.......d$......Z........t .T$..D$......D$.h.....$.....4..........t........t...$..............U..WVS....u..}...E...............1..E......E....)E.)E..7..&.......O..N.]............).k..)..a.....\.......t>.C.<.v.C.<.w:...O..N.]...........).k..)..A.....\.......u...[^_].f..................'....U1..1.V.u.S.]......t.f.................
                                                    File type:ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, for GNU/Linux 2.6.18, BuildID[sha1]=307edfa923d9ff7e3793ec8771ab90f5343cb21e, stripped
                                                    Entropy (8bit):6.390073589605978
                                                    TrID:
                                                    • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                    • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                    File name:Linux4.7.elf
                                                    File size:1'315'556 bytes
                                                    MD5:bea79d22552cac2f0ddeff8b33682b0d
                                                    SHA1:183cb250e3211af0ccc1960a6a241a6ea90a95da
                                                    SHA256:4efe185e41696351835356a55211aeb113994f87887cab3ffbbaacecb589e9f6
                                                    SHA512:ae59fd898e659f6e361efd1755e16c64bb2c72198bbc18784df6dad2fd90b3b0d456d44b739547aaeada60cc747111be07ccc552eab221d699ad284069d80b03
                                                    SSDEEP:24576:8kUpotcUSzgtPLdOEG0V0JRzFB3ywyUZ1N2AhNdhBjh+hnPlVVW0Mk7t69Kx/ti8:MoKXwZOK0TFBCwy8P2AhNdhBjh+hnPlP
                                                    TLSH:D7556D1DF64344B5C837D17002CFEB7F8D24AA398017CA97AD8DDD39BCAB9A1690D612
                                                    File Content Preview:.ELF........................4...........4. ...(.....................................................................................D...D...............................L...........Q.td........................................GNU............................

                                                    ELF header

                                                    Class:ELF32
                                                    Data:2's complement, little endian
                                                    Version:1 (current)
                                                    Machine:Intel 80386
                                                    Version Number:0x1
                                                    Type:EXEC (Executable file)
                                                    OS/ABI:UNIX - Linux
                                                    ABI Version:0
                                                    Entry Point Address:0x80481f0
                                                    Flags:0x0
                                                    ELF Header Size:52
                                                    Program Header Offset:52
                                                    Program Header Size:32
                                                    Number of Program Headers:5
                                                    Section Header Offset:1314316
                                                    Section Header Size:40
                                                    Number of Section Headers:31
                                                    Header String Table Index:30
                                                    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                    NULL0x00x00x00x00x0000
                                                    .note.ABI-tagNOTE0x80480d40xd40x200x00x2A004
                                                    .note.gnu.build-idNOTE0x80480f40xf40x240x00x2A004
                                                    .rel.pltREL0x80481180x1180x380x80x2A054
                                                    .initPROGBITS0x80481500x1500x300x00x6AX004
                                                    .pltPROGBITS0x80481800x1800x700x00x6AX004
                                                    .textPROGBITS0x80481f00x1f00xf3bfc0x00x6AX0016
                                                    __libc_freeres_fnPROGBITS0x813bdf00xf3df00x18380x00x6AX0016
                                                    __libc_thread_freeres_fnPROGBITS0x813d6300xf56300x1fa0x00x6AX0016
                                                    .finiPROGBITS0x813d82c0xf582c0x1c0x00x6AX004
                                                    .rodataPROGBITS0x813d8600xf58600x1d5e40x00x2A0032
                                                    __libc_subfreeresPROGBITS0x815ae440x112e440x340x00x2A004
                                                    __libc_atexitPROGBITS0x815ae780x112e780x40x00x2A004
                                                    __libc_thread_subfreeresPROGBITS0x815ae7c0x112e7c0x80x00x2A004
                                                    .stapsdt.basePROGBITS0x815ae840x112e840x10x00x2A001
                                                    .eh_framePROGBITS0x815ae880x112e880x2843c0x00x2A004
                                                    .gcc_except_tablePROGBITS0x81832c40x13b2c40x40100x00x2A004
                                                    .tdataPROGBITS0x81882d40x13f2d40x140x00x403WAT004
                                                    .tbssNOBITS0x81882e80x13f2e80x380x00x403WAT004
                                                    .ctorsPROGBITS0x81882e80x13f2e80x280x00x3WA004
                                                    .dtorsPROGBITS0x81883100x13f3100xc0x00x3WA004
                                                    .jcrPROGBITS0x818831c0x13f31c0x40x00x3WA004
                                                    .data.rel.roPROGBITS0x81883200x13f3200xca00x00x3WA0032
                                                    .gotPROGBITS0x8188fc00x13ffc00xa40x40x3WA004
                                                    .got.pltPROGBITS0x81890640x1400640x280x40x3WA004
                                                    .dataPROGBITS0x81890a00x1400a00x9b40x00x3WA0032
                                                    .bssNOBITS0x8189a600x140a540xbb1c0x00x3WA0032
                                                    __libc_freeres_ptrsNOBITS0x819557c0x140a540x180x00x3WA004
                                                    .note.stapsdtNOTE0x00x140a540x23c0x00x0004
                                                    .commentPROGBITS0x00x140c900x2d0x10x30MS001
                                                    .shstrtabSTRTAB0x00x140cbd0x14e0x00x0001
                                                    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                    LOAD0x00x80480000x80480000x13f2d40x13f2d46.39590x5R E0x1000.note.ABI-tag .note.gnu.build-id .rel.plt .init .plt .text __libc_freeres_fn __libc_thread_freeres_fn .fini .rodata __libc_subfreeres __libc_atexit __libc_thread_subfreeres .stapsdt.base .eh_frame .gcc_except_table
                                                    LOAD0x13f2d40x81882d40x81882d40x17800xd2c04.13440x6RW 0x1000.tdata .tbss .ctors .dtors .jcr .data.rel.ro .got .got.plt .data .bss __libc_freeres_ptrs
                                                    NOTE0xd40x80480d40x80480d40x440x443.49240x4R 0x4.note.ABI-tag .note.gnu.build-id
                                                    TLS0x13f2d40x81882d40x81882d40x140x4c2.70370x4R 0x4.tdata .tbss
                                                    GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                    TimestampSource PortDest PortSource IPDest IP
                                                    Jan 4, 2025 21:32:43.597560883 CET43928443192.168.2.2391.189.91.42
                                                    Jan 4, 2025 21:32:48.968856096 CET42836443192.168.2.2391.189.91.43
                                                    Jan 4, 2025 21:32:50.504650116 CET4251680192.168.2.23109.202.202.202
                                                    Jan 4, 2025 21:33:04.582663059 CET43928443192.168.2.2391.189.91.42
                                                    Jan 4, 2025 21:33:14.821449995 CET42836443192.168.2.2391.189.91.43
                                                    Jan 4, 2025 21:33:20.964456081 CET4251680192.168.2.23109.202.202.202
                                                    Jan 4, 2025 21:33:45.537080050 CET43928443192.168.2.2391.189.91.42
                                                    Jan 4, 2025 21:34:06.014214039 CET42836443192.168.2.2391.189.91.43

                                                    System Behavior

                                                    Start time (UTC):20:32:40
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:/tmp/Linux4.7.elf
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:32:40
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:32:40
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:32:41
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:32:41
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:32:41
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:32:41
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:32:41
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/update-rc.d
                                                    Arguments:update-rc.d Linux4.7.elf remove
                                                    File size:3478464 bytes
                                                    MD5 hash:16a21f464119ea7fad1d3660de963637

                                                    Start time (UTC):20:32:41
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/update-rc.d
                                                    Arguments:-
                                                    File size:3478464 bytes
                                                    MD5 hash:16a21f464119ea7fad1d3660de963637

                                                    Start time (UTC):20:32:41
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/bin/systemctl
                                                    Arguments:systemctl daemon-reload
                                                    File size:996584 bytes
                                                    MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                    Start time (UTC):20:32:41
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:32:41
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:32:41
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:32:41
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:32:41
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/update-rc.d
                                                    Arguments:update-rc.d .chinaz{1736022760 defaults
                                                    File size:3478464 bytes
                                                    MD5 hash:16a21f464119ea7fad1d3660de963637

                                                    Start time (UTC):20:32:42
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/update-rc.d
                                                    Arguments:-
                                                    File size:3478464 bytes
                                                    MD5 hash:16a21f464119ea7fad1d3660de963637

                                                    Start time (UTC):20:32:42
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/bin/systemctl
                                                    Arguments:systemctl daemon-reload
                                                    File size:996584 bytes
                                                    MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                    Start time (UTC):20:32:41
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:32:41
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "sed -i '/\\/etc\\/cron.hourly\\/cron.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/cron.sh' >> /etc/crontab"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:41
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:41
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/bin/sed
                                                    Arguments:sed -i /\\/etc\\/cron.hourly\\/cron.sh/d /etc/crontab
                                                    File size:121288 bytes
                                                    MD5 hash:885062561f66aa1d4af4c54b9e7cc81a

                                                    Start time (UTC):20:32:41
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:32:41
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "rm -rf /etc/resolv.conf"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:42
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:42
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/bin/rm
                                                    Arguments:rm -rf /etc/resolv.conf
                                                    File size:72056 bytes
                                                    MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                    Start time (UTC):20:32:42
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:32:42
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c whoami
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:42
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:42
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/bin/whoami
                                                    Arguments:whoami
                                                    File size:39256 bytes
                                                    MD5 hash:dbc1888ae50bb5d4d9a7a210d51be710

                                                    Start time (UTC):20:32:42
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:32:42
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables --flush"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:42
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:42
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables --flush
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:32:42
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:32:42
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c whoami
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:42
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:42
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/bin/whoami
                                                    Arguments:whoami
                                                    File size:39256 bytes
                                                    MD5 hash:dbc1888ae50bb5d4d9a7a210d51be710

                                                    Start time (UTC):20:32:42
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:32:42
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:42
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:42
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:32:42
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:32:42
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "touch /home/root/ConfigDatecz"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:42
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:42
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/bin/touch
                                                    Arguments:touch /home/root/ConfigDatecz
                                                    File size:100728 bytes
                                                    MD5 hash:3859c173f5d3b37be3e531b7c84a9c68

                                                    Start time (UTC):20:32:43
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:32:43
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:43
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:43
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:32:43
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:32:43
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:43
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:43
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:32:43
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:32:43
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:43
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:43
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:32:43
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:32:43
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:43
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:43
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:32:43
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:32:43
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:43
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:43
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:32:44
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:32:44
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:44
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:44
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:32:44
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:32:44
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:44
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:44
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:32:44
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:32:44
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:44
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:32:44
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:33:14
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:33:14
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:14
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:14
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:33:14
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:33:14
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:14
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:14
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:33:14
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:33:14
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:14
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:14
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:33:14
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:33:14
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:14
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:14
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:33:15
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:33:15
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:15
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:15
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:33:15
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:33:15
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:15
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:15
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:33:15
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:33:15
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:15
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:15
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:33:15
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:33:15
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:15
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:15
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:33:15
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:33:15
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:15
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:15
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:33:45
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:33:45
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:45
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:45
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:33:45
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:33:45
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:45
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:45
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:33:45
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:33:45
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:45
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:45
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:33:45
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:33:45
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:45
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:45
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:33:45
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:33:45
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:45
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:45
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:33:46
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:33:46
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:46
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:46
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:33:46
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:33:46
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:46
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:46
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:33:46
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:33:46
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:46
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:46
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:33:46
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:33:46
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:46
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:33:46
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:34:16
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:34:16
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:34:16
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:34:16
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:34:16
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:34:16
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:34:16
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:34:16
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:34:16
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:34:16
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:34:16
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:34:16
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:34:16
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:34:16
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:34:16
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:34:16
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:34:17
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:34:17
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:34:17
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:34:17
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:34:17
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:34:17
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:34:17
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:34:17
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:34:17
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:34:17
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:34:17
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:34:17
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:34:17
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:34:17
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:34:17
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:34:17
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:34:17
                                                    Start date (UTC):04/01/2025
                                                    Path:/tmp/Linux4.7.elf
                                                    Arguments:-
                                                    File size:1315556 bytes
                                                    MD5 hash:bea79d22552cac2f0ddeff8b33682b0d

                                                    Start time (UTC):20:34:17
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP"
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:34:17
                                                    Start date (UTC):04/01/2025
                                                    Path:/bin/sh
                                                    Arguments:-
                                                    File size:129816 bytes
                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                    Start time (UTC):20:34:17
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/sbin/iptables
                                                    Arguments:iptables -A OUTPUT -p tcp --dport 0 -j DROP
                                                    File size:99296 bytes
                                                    MD5 hash:1ab05fef765b6342cdfadaa5275b33af

                                                    Start time (UTC):20:32:42
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/lib/systemd/systemd
                                                    Arguments:-
                                                    File size:1620224 bytes
                                                    MD5 hash:9b2bec7092a40488108543f9334aab75

                                                    Start time (UTC):20:32:42
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                    Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                    File size:22760 bytes
                                                    MD5 hash:3633b075f40283ec938a2a6a89671b0e

                                                    Start time (UTC):20:32:42
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/lib/systemd/systemd
                                                    Arguments:-
                                                    File size:1620224 bytes
                                                    MD5 hash:9b2bec7092a40488108543f9334aab75

                                                    Start time (UTC):20:32:42
                                                    Start date (UTC):04/01/2025
                                                    Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                    Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                    File size:22760 bytes
                                                    MD5 hash:3633b075f40283ec938a2a6a89671b0e