Linux Analysis Report HuuyISbqrL
Overview
General Information
Sample Name: | HuuyISbqrL |
Analysis ID: | 519576 |
MD5: | f29045435920698fbbe67b121e7bfe79 |
SHA1: | 22b027d1bef58216b0d73ddb755aac259711aa33 |
SHA256: | a07cd4589f01b49d0c349d73a6da0eec0e8c28c82b31bd637b2ee7ff612ad39b |
Tags: | 32elfintel |
Infos: |
Detection
Score: | 84 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Classification
Analysis Advice |
---|
All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work |
General Information |
---|
Joe Sandbox Version: | 34.0.0 Boulder Opal |
Analysis ID: | 519576 |
Start date: | 10.11.2021 |
Start time: | 22:29:12 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 5m 15s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | HuuyISbqrL |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Detection: | MAL |
Classification: | mal84.troj.evad.lin@0/5@0/0 |
Warnings: | Show All
|
Process Tree |
---|
|
Yara Overview |
---|
Initial Sample |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
CN_disclosed_20180208_lsls | Detects malware from disclosed CN malware set | Florian Roth |
|
Dropped Files |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
CN_disclosed_20180208_lsls | Detects malware from disclosed CN malware set | Florian Roth |
|
Memory Dumps |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
CN_disclosed_20180208_lsls | Detects malware from disclosed CN malware set | Florian Roth |
| |
CN_disclosed_20180208_lsls | Detects malware from disclosed CN malware set | Florian Roth |
| |
CN_disclosed_20180208_lsls | Detects malware from disclosed CN malware set | Florian Roth |
| |
CN_disclosed_20180208_lsls | Detects malware from disclosed CN malware set | Florian Roth |
| |
CN_disclosed_20180208_lsls | Detects malware from disclosed CN malware set | Florian Roth |
| |
Click to see the 4 entries |
Jbx Signature Overview |
---|
Click to jump to signature section
AV Detection: |
---|
Multi AV Scanner detection for submitted file | Show sources |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Machine Learning detection for dropped file | Show sources |
Source: | Joe Sandbox ML: |
Machine Learning detection for sample | Show sources |
Source: | Joe Sandbox ML: |
Source: | Reads CPU info from /sys: | Jump to behavior |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | String found in binary or memory: |
System Summary: |
---|
Malicious sample detected (through community Yara rule) | Show sources |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | .symtab present: |
Source: | Joe Sandbox Cloud Basic: | Perma Link |
Source: | Classification label: |
Persistence and Installation Behavior: |
---|
Sample tries to persist itself using System V runlevels | Show sources |
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior |
Sample tries to persist itself using cron | Show sources |
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior |
Source: | File written: | Jump to dropped file |
Source: | Shell script file created: | Jump to dropped file |
Source: | Reads from proc file: | Jump to behavior |
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior |
Source: | Rm executable: | Jump to behavior |
Source: | Touch executable: | Jump to behavior |
Source: | Writes shell script file to disk with an unusual file extension: | Jump to dropped file |
Source: | Sed executable: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection: |
---|
Drops files in suspicious directories | Show sources |
Source: | File: | Jump to dropped file |
Sample deletes itself | Show sources |
Source: | File: | Jump to behavior |
Drops invisible ELF files | Show sources |
Source: | ELF file: | Jump to dropped file |
Source: | Reads CPU info from /sys: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior |
Mitre Att&ck Matrix |
---|
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Command and Scripting Interpreter1 | At (Linux)2 | At (Linux)2 | Masquerading1 | OS Credential Dumping | Security Software Discovery1 | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | Encrypted Channel1 | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scripting2 | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Scripting2 | LSASS Memory | System Information Discovery2 | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | Application Layer Protocol1 | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux)2 | Logon Script (Windows) | Logon Script (Windows) | Hidden Files and Directories1 | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | Steganography | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | Indicator Removal on Host1 | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Scheduled Transfer | Protocol Impersonation | SIM Card Swap | Carrier Billing Fraud | |
Cloud Accounts | Cron | Network Logon Script | Network Logon Script | File Deletion11 | LSA Secrets | Remote System Discovery | SSH | Keylogging | Data Transfer Size Limits | Fallback Channels | Manipulate Device Communication | Manipulate App Store Rankings or Ratings |
Malware Configuration |
---|
No configs have been found |
---|
Behavior Graph |
---|
Antivirus, Machine Learning and Genetic Malware Detection |
---|
Initial Sample |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
54% | Virustotal | Browse | ||
73% | ReversingLabs | Linux.Trojan.XorDDoS | ||
100% | Joe Sandbox ML |
Dropped Files |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Joe Sandbox ML | |||
5% | Virustotal | Browse | ||
11% | Metadefender | Browse | ||
18% | ReversingLabs | Linux.Trojan.XorDDoS | ||
73% | ReversingLabs | Linux.Trojan.XorDDoS |
Domains |
---|
No Antivirus matches |
---|
URLs |
---|
No Antivirus matches |
---|
Domains and IPs |
---|
Contacted Domains |
---|
No contacted domains info |
---|
URLs from Memory and Binaries |
---|
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high |
Contacted IPs |
---|
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
Public |
---|
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
91.189.91.43 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false |
Runtime Messages |
---|
Command: | /tmp/HuuyISbqrL |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | |
Standard Error: |
Joe Sandbox View / Context |
---|
IPs |
---|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
109.202.202.202 | Get hash | malicious | Browse | ||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
91.189.91.43 | Get hash | malicious | Browse | ||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
91.189.91.42 | Get hash | malicious | Browse | ||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse |
Domains |
---|
No context |
---|
ASN |
---|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
CANONICAL-ASGB | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
CANONICAL-ASGB | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
INIT7CH | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
JA3 Fingerprints |
---|
No context |
---|
Dropped Files |
---|
Created / dropped Files |
---|
Process: | /tmp/HuuyISbqrL |
File Type: | |
Category: | dropped |
Size (bytes): | 223 |
Entropy (8bit): | 4.756432444291805 |
Encrypted: | false |
SSDEEP: | 6:htiy4Mrm9lVNy28XbCVP270gJdUiynrgns:RjwVNfGbWPirSR |
MD5: | B791B087B1795E3674A9AA765C76FC04 |
SHA1: | B53F478234AE97F3CDBF2E7FE7EC68D687FEB7C1 |
SHA-256: | 1C1E9B69CF8021BF7CE1F60DCAA2D31C1E21ED4B6E474F3571DA81FFD5A9B69E |
SHA-512: | 2DCC2E478C51CF8118306FD5C744AAD7147E368CBC4329DB1CC5FAC52088A7F3354079AE2B582B270495789E4FB4591538EC88BB5EA40EEC646F360BAC33BBB2 |
Malicious: | true |
Antivirus: | |
Joe Sandbox View: |
|
Reputation: | low |
Preview: |
|
Process: | /tmp/HuuyISbqrL |
File Type: | |
Category: | dropped |
Size (bytes): | 355 |
Entropy (8bit): | 5.348173954768942 |
Encrypted: | false |
SSDEEP: | 6:hUtoFdU9uMw2tBjnsKheJjU5tBNZBE21YJvmNeMwh2L5tBjR1DzRIjutrBk6MzEm:6tw2tpmjctbZBEMO12L5tp7zujutrazL |
MD5: | 6C162FA00872C8BCEB4331DCF0DFCCF8 |
SHA1: | 3AA328DA28C1D329E0A9696B06134B5B00D33D87 |
SHA-256: | 4B3729255911269128643140F4D971296C34D7B3EDE437CD2AB356E8A72CE62A |
SHA-512: | F669E609F5164FFA8D6D51F4C8EAA85384823060CB5265B0D213E3CEB02257445152ED517B0D7A8DFF9A1D5CF6DFC0E5DBC8CE87A2E60A0547F5ABF9EDE7D52B |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Reputation: | low |
Preview: |
|
Process: | /usr/lib/systemd/system-environment-generators/snapd-env-generator |
File Type: | |
Category: | dropped |
Size (bytes): | 76 |
Entropy (8bit): | 3.7627880354948586 |
Encrypted: | false |
SSDEEP: | 3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb |
MD5: | D86A1F5765F37989EB0EC3837AD13ECC |
SHA1: | D749672A734D9DEAFD61DCA501C6929EC431B83E |
SHA-256: | 85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45 |
SHA-512: | 338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
|
Process: | /tmp/HuuyISbqrL |
File Type: | |
Category: | dropped |
Size (bytes): | 1315556 |
Entropy (8bit): | 6.3900726950490805 |
Encrypted: | false |
SSDEEP: | 24576:8kUpotcUSzgtPLdOEG0V0JRzFB3ywyUZ1N2AhNdhBjh+hnPlVVW0Mk7t69Kx/ti8:MoKXwZOK0TFBCwy8P2AhNdhBjh+hnPlP |
MD5: | F29045435920698FBBE67B121E7BFE79 |
SHA1: | 22B027D1BEF58216B0D73DDB755AAC259711AA33 |
SHA-256: | A07CD4589F01B49D0C349D73A6DA0EEC0E8C28C82B31BD637B2EE7FF612AD39B |
SHA-512: | F225DA6D66D4A46B91E6A56EFF35699C31D0E0789D70D31DF4E6CE93E1E5B3FDBC1D43C5F5C5EC1B099477F24750BD2E189BD9DA998174E6D9AD498D5131D3B8 |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
|
Static File Info |
---|
General | |
---|---|
File type: | |
Entropy (8bit): | 6.3900726950490805 |
TrID: |
|
File name: | HuuyISbqrL |
File size: | 1315556 |
MD5: | f29045435920698fbbe67b121e7bfe79 |
SHA1: | 22b027d1bef58216b0d73ddb755aac259711aa33 |
SHA256: | a07cd4589f01b49d0c349d73a6da0eec0e8c28c82b31bd637b2ee7ff612ad39b |
SHA512: | f225da6d66d4a46b91e6a56eff35699c31d0e0789d70d31df4e6ce93e1e5b3fdbc1d43c5f5c5ec1b099477f24750bd2e189bd9da998174e6d9ad498d5131d3b8 |
SSDEEP: | 24576:8kUpotcUSzgtPLdOEG0V0JRzFB3ywyUZ1N2AhNdhBjh+hnPlVVW0Mk7t69Kx/ti8:MoKXwZOK0TFBCwy8P2AhNdhBjh+hnPlP |
File Content Preview: | .ELF........................4...........4. ...(.....................................................................................D...D...............................L...........Q.td........................................GNU............................ |
Static ELF Info |
---|
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | |
Entry Point Address: | |
Flags: | |
ELF Header Size: | |
Program Header Offset: | |
Program Header Size: | |
Number of Program Headers: | |
Section Header Offset: | |
Section Header Size: | |
Number of Section Headers: | |
Header String Table Index: |
Sections |
---|
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.note.ABI-tag | NOTE | 0x80480d4 | 0xd4 | 0x20 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.note.gnu.build-id | NOTE | 0x80480f4 | 0xf4 | 0x24 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.rel.plt | REL | 0x8048118 | 0x118 | 0x38 | 0x8 | 0x2 | A | 0 | 5 | 4 |
.init | PROGBITS | 0x8048150 | 0x150 | 0x30 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.plt | PROGBITS | 0x8048180 | 0x180 | 0x70 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x80481f0 | 0x1f0 | 0xf3bfc | 0x0 | 0x6 | AX | 0 | 0 | 16 |
__libc_freeres_fn | PROGBITS | 0x813bdf0 | 0xf3df0 | 0x1838 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
__libc_thread_freeres_fn | PROGBITS | 0x813d630 | 0xf5630 | 0x1fa | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x813d82c | 0xf582c | 0x1c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x813d860 | 0xf5860 | 0x1d5e4 | 0x0 | 0x2 | A | 0 | 0 | 32 |
__libc_subfreeres | PROGBITS | 0x815ae44 | 0x112e44 | 0x34 | 0x0 | 0x2 | A | 0 | 0 | 4 |
__libc_atexit | PROGBITS | 0x815ae78 | 0x112e78 | 0x4 | 0x0 | 0x2 | A | 0 | 0 | 4 |
__libc_thread_subfreeres | PROGBITS | 0x815ae7c | 0x112e7c | 0x8 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.stapsdt.base | PROGBITS | 0x815ae84 | 0x112e84 | 0x1 | 0x0 | 0x2 | A | 0 | 0 | 1 |
.eh_frame | PROGBITS | 0x815ae88 | 0x112e88 | 0x2843c | 0x0 | 0x2 | A | 0 | 0 | 4 |
.gcc_except_table | PROGBITS | 0x81832c4 | 0x13b2c4 | 0x4010 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.tdata | PROGBITS | 0x81882d4 | 0x13f2d4 | 0x14 | 0x0 | 0x403 | WAT | 0 | 0 | 4 |
.tbss | NOBITS | 0x81882e8 | 0x13f2e8 | 0x38 | 0x0 | 0x403 | WAT | 0 | 0 | 4 |
.ctors | PROGBITS | 0x81882e8 | 0x13f2e8 | 0x28 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x8188310 | 0x13f310 | 0xc | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.jcr | PROGBITS | 0x818831c | 0x13f31c | 0x4 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data.rel.ro | PROGBITS | 0x8188320 | 0x13f320 | 0xca0 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.got | PROGBITS | 0x8188fc0 | 0x13ffc0 | 0xa4 | 0x4 | 0x3 | WA | 0 | 0 | 4 |
.got.plt | PROGBITS | 0x8189064 | 0x140064 | 0x28 | 0x4 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x81890a0 | 0x1400a0 | 0x9b4 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.bss | NOBITS | 0x8189a60 | 0x140a54 | 0xbb1c | 0x0 | 0x3 | WA | 0 | 0 | 32 |
__libc_freeres_ptrs | NOBITS | 0x819557c | 0x140a54 | 0x18 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.note.stapsdt | NOTE | 0x0 | 0x140a54 | 0x23c | 0x0 | 0x0 | 0 | 0 | 4 | |
.comment | PROGBITS | 0x0 | 0x140c90 | 0x2d | 0x1 | 0x30 | MS | 0 | 0 | 1 |
.shstrtab | STRTAB | 0x0 | 0x140cbd | 0x14e | 0x0 | 0x0 | 0 | 0 | 1 |
Program Segments |
---|
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8048000 | 0x8048000 | 0x13f2d4 | 0x13f2d4 | 3.5669 | 0x5 | R E | 0x1000 | .note.ABI-tag .note.gnu.build-id .rel.plt .init .plt .text __libc_freeres_fn __libc_thread_freeres_fn .fini .rodata __libc_subfreeres __libc_atexit __libc_thread_subfreeres .stapsdt.base .eh_frame .gcc_except_table | |
LOAD | 0x13f2d4 | 0x81882d4 | 0x81882d4 | 0x1780 | 0xd2c0 | 2.9020 | 0x6 | RW | 0x1000 | .ctors .dtors .jcr .data.rel.ro .got .got.plt .data .bss __libc_freeres_ptrs | |
NOTE | 0xd4 | 0x80480d4 | 0x80480d4 | 0x44 | 0x44 | 2.5077 | 0x4 | R | 0x4 | .note.ABI-tag .note.gnu.build-id | |
TLS | 0x13f2d4 | 0x81882d4 | 0x81882d4 | 0x14 | 0x4c | 1.3966 | 0x4 | R | 0x4 | ||
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x4 |
Network Behavior |
---|
Network Port Distribution |
---|
TCP Packets |
---|
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 10, 2021 22:29:57.330091000 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Nov 10, 2021 22:29:58.098119020 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Nov 10, 2021 22:30:12.178035021 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Nov 10, 2021 22:30:24.465898991 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Nov 10, 2021 22:30:28.561901093 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Nov 10, 2021 22:30:53.137700081 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
System Behavior |
---|
General |
---|
Start time: | 22:29:55 |
Start date: | 10/11/2021 |
Path: | /tmp/HuuyISbqrL |
Arguments: | /tmp/HuuyISbqrL |
File size: | 1315556 bytes |
MD5 hash: | f29045435920698fbbe67b121e7bfe79 |
General |
---|
Start time: | 22:29:55 |
Start date: | 10/11/2021 |
Path: | /tmp/HuuyISbqrL |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | f29045435920698fbbe67b121e7bfe79 |
General |
---|
Start time: | 22:29:55 |
Start date: | 10/11/2021 |
Path: | /tmp/HuuyISbqrL |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | f29045435920698fbbe67b121e7bfe79 |
General |
---|
Start time: | 22:29:57 |
Start date: | 10/11/2021 |
Path: | /tmp/HuuyISbqrL |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | f29045435920698fbbe67b121e7bfe79 |
General |
---|
Start time: | 22:29:57 |
Start date: | 10/11/2021 |
Path: | /tmp/HuuyISbqrL |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | f29045435920698fbbe67b121e7bfe79 |
General |
---|
Start time: | 22:29:57 |
Start date: | 10/11/2021 |
Path: | /tmp/HuuyISbqrL |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | f29045435920698fbbe67b121e7bfe79 |
General |
---|
Start time: | 22:29:57 |
Start date: | 10/11/2021 |
Path: | /tmp/HuuyISbqrL |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | f29045435920698fbbe67b121e7bfe79 |
General |
---|
Start time: | 22:29:57 |
Start date: | 10/11/2021 |
Path: | /usr/sbin/update-rc.d |
Arguments: | update-rc.d HuuyISbqrL remove |
File size: | 3478464 bytes |
MD5 hash: | 16a21f464119ea7fad1d3660de963637 |
General |
---|
Start time: | 22:29:58 |
Start date: | 10/11/2021 |
Path: | /usr/sbin/update-rc.d |
Arguments: | n/a |
File size: | 3478464 bytes |
MD5 hash: | 16a21f464119ea7fad1d3660de963637 |
General |
---|
Start time: | 22:29:58 |
Start date: | 10/11/2021 |
Path: | /usr/bin/systemctl |
Arguments: | systemctl daemon-reload |
File size: | 996584 bytes |
MD5 hash: | 4deddfb6741481f68aeac522cc26ff4b |
General |
---|
Start time: | 22:29:57 |
Start date: | 10/11/2021 |
Path: | /tmp/HuuyISbqrL |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | f29045435920698fbbe67b121e7bfe79 |
General |
---|
Start time: | 22:29:57 |
Start date: | 10/11/2021 |
Path: | /tmp/HuuyISbqrL |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | f29045435920698fbbe67b121e7bfe79 |
General |
---|
Start time: | 22:29:57 |
Start date: | 10/11/2021 |
Path: | /tmp/HuuyISbqrL |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | f29045435920698fbbe67b121e7bfe79 |
General |
---|
Start time: | 22:29:57 |
Start date: | 10/11/2021 |
Path: | /tmp/HuuyISbqrL |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | f29045435920698fbbe67b121e7bfe79 |
General |
---|
Start time: | 22:29:57 |
Start date: | 10/11/2021 |
Path: | /usr/sbin/update-rc.d |
Arguments: | update-rc.d .chinaz{1636583395 defaults |
File size: | 3478464 bytes |
MD5 hash: | 16a21f464119ea7fad1d3660de963637 |
General |
---|
Start time: | 22:29:58 |
Start date: | 10/11/2021 |
Path: | /usr/sbin/update-rc.d |
Arguments: | n/a |
File size: | 3478464 bytes |
MD5 hash: | 16a21f464119ea7fad1d3660de963637 |
General |
---|
Start time: | 22:29:59 |
Start date: | 10/11/2021 |
Path: | /usr/bin/systemctl |
Arguments: | systemctl daemon-reload |
File size: | 996584 bytes |
MD5 hash: | 4deddfb6741481f68aeac522cc26ff4b |
General |
---|
Start time: | 22:29:57 |
Start date: | 10/11/2021 |
Path: | /tmp/HuuyISbqrL |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | f29045435920698fbbe67b121e7bfe79 |
General |
---|
Start time: | 22:29:57 |
Start date: | 10/11/2021 |
Path: | /bin/sh |
Arguments: | sh -c "sed -i '/\\/etc\\/cron.hourly\\/cron.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/cron.sh' >> /etc/crontab" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
General |
---|
Start time: | 22:29:57 |
Start date: | 10/11/2021 |
Path: | /bin/sh |
Arguments: | n/a |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
General |
---|
Start time: | 22:29:57 |
Start date: | 10/11/2021 |
Path: | /usr/bin/sed |
Arguments: | sed -i /\\/etc\\/cron.hourly\\/cron.sh/d /etc/crontab |
File size: | 121288 bytes |
MD5 hash: | 885062561f66aa1d4af4c54b9e7cc81a |
General |
---|
Start time: | 22:29:58 |
Start date: | 10/11/2021 |
Path: | /tmp/HuuyISbqrL |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | f29045435920698fbbe67b121e7bfe79 |
General |
---|
Start time: | 22:29:58 |
Start date: | 10/11/2021 |
Path: | /bin/sh |
Arguments: | sh -c "rm -rf /etc/resolv.conf" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
General |
---|
Start time: | 22:29:58 |
Start date: | 10/11/2021 |
Path: | /bin/sh |
Arguments: | n/a |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
General |
---|
Start time: | 22:29:58 |
Start date: | 10/11/2021 |
Path: | /usr/bin/rm |
Arguments: | rm -rf /etc/resolv.conf |
File size: | 72056 bytes |
MD5 hash: | aa2b5496fdbfd88e38791ab81f90b95b |
General |
---|
Start time: | 22:29:59 |
Start date: | 10/11/2021 |
Path: | /tmp/HuuyISbqrL |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | f29045435920698fbbe67b121e7bfe79 |
General |
---|
Start time: | 22:29:59 |
Start date: | 10/11/2021 |
Path: | /bin/sh |
Arguments: | sh -c whoami |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
General |
---|
Start time: | 22:29:59 |
Start date: | 10/11/2021 |
Path: | /bin/sh |
Arguments: | n/a |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
General |
---|
Start time: | 22:29:59 |
Start date: | 10/11/2021 |
Path: | /usr/bin/whoami |
Arguments: | whoami |
File size: | 39256 bytes |
MD5 hash: | dbc1888ae50bb5d4d9a7a210d51be710 |
General |
---|
Start time: | 22:29:59 |
Start date: | 10/11/2021 |
Path: | /tmp/HuuyISbqrL |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | f29045435920698fbbe67b121e7bfe79 |
General |
---|
Start time: | 22:29:59 |
Start date: | 10/11/2021 |
Path: | /bin/sh |
Arguments: | sh -c "iptables --flush" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
General |
---|
Start time: | 22:29:59 |
Start date: | 10/11/2021 |
Path: | /bin/sh |
Arguments: | n/a |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
General |
---|
Start time: | 22:29:59 |
Start date: | 10/11/2021 |
Path: | /usr/sbin/iptables |
Arguments: | iptables --flush |
File size: | 99296 bytes |
MD5 hash: | 1ab05fef765b6342cdfadaa5275b33af |
General |
---|
Start time: | 22:29:59 |
Start date: | 10/11/2021 |
Path: | /tmp/HuuyISbqrL |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | f29045435920698fbbe67b121e7bfe79 |
General |
---|
Start time: | 22:29:59 |
Start date: | 10/11/2021 |
Path: | /bin/sh |
Arguments: | sh -c whoami |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
General |
---|
Start time: | 22:29:59 |
Start date: | 10/11/2021 |
Path: | /bin/sh |
Arguments: | n/a |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
General |
---|
Start time: | 22:29:59 |
Start date: | 10/11/2021 |
Path: | /usr/bin/whoami |
Arguments: | whoami |
File size: | 39256 bytes |
MD5 hash: | dbc1888ae50bb5d4d9a7a210d51be710 |
General |
---|
Start time: | 22:29:59 |
Start date: | 10/11/2021 |
Path: | /tmp/HuuyISbqrL |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | f29045435920698fbbe67b121e7bfe79 |
General |
---|
Start time: | 22:29:59 |
Start date: | 10/11/2021 |
Path: | /bin/sh |
Arguments: | sh -c "touch /home/root/ConfigDatecz" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
General |
---|
Start time: | 22:29:59 |
Start date: | 10/11/2021 |
Path: | /bin/sh |
Arguments: | n/a |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
General |
---|
Start time: | 22:29:59 |
Start date: | 10/11/2021 |
Path: | /usr/bin/touch |
Arguments: | touch /home/root/ConfigDatecz |
File size: | 100728 bytes |
MD5 hash: | 3859c173f5d3b37be3e531b7c84a9c68 |
General |
---|
Start time: | 22:29:59 |
Start date: | 10/11/2021 |
Path: | /tmp/HuuyISbqrL |
Arguments: | n/a |
File size: | 1315556 bytes |
MD5 hash: | f29045435920698fbbe67b121e7bfe79 |
General |
---|
Start time: | 22:29:59 |
Start date: | 10/11/2021 |
Path: | /bin/sh |
Arguments: | sh -c "iptables -A OUTPUT -p tcp --dport 0 -j DROP" |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
General |
---|
Start time: | 22:29:59 |
Start date: | 10/11/2021 |
Path: | /bin/sh |
Arguments: | n/a |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
General |
---|
Start time: | 22:29:59 |
Start date: | 10/11/2021 |
Path: | /usr/sbin/iptables |
Arguments: | iptables -A OUTPUT -p tcp --dport 0 -j DROP |
File size: | 99296 bytes |
MD5 hash: | 1ab05fef765b6342cdfadaa5275b33af |
General |
---|
Start time: | 22:29:59 |
Start date: | 10/11/2021 |
Path: | /usr/lib/systemd/systemd |
Arguments: | n/a |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
General |
---|
Start time: | 22:29:59 |
Start date: | 10/11/2021 |
Path: | /usr/lib/systemd/system-environment-generators/snapd-env-generator |
Arguments: | /usr/lib/systemd/system-environment-generators/snapd-env-generator |
File size: | 22760 bytes |
MD5 hash: | 3633b075f40283ec938a2a6a89671b0e |
General |
---|
Start time: | 22:29:59 |
Start date: | 10/11/2021 |
Path: | /usr/lib/systemd/systemd |
Arguments: | n/a |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
General |
---|
Start time: | 22:29:59 |
Start date: | 10/11/2021 |
Path: | /usr/lib/systemd/system-environment-generators/snapd-env-generator |
Arguments: | /usr/lib/systemd/system-environment-generators/snapd-env-generator |
File size: | 22760 bytes |
MD5 hash: | 3633b075f40283ec938a2a6a89671b0e |